Essay

The Technology Framing of Cyber Risk: Why the Most Important Cyber Decisions Are Not Technical Ones

01 July 2026 · Digital Risk · No.03

Cyber risk is treated as a technology problem. That single classification is the first thing most institutions get wrong about it, and a surprising amount of what goes wrong later follows from it.

The framing feels obviously correct. A cyber incident arrives through technology. It is detected by technology, contained by technology, and explained afterwards in the language of systems, patches, and controls. So the problem is handed to the people who own the technology. The security team builds the defences. The board receives a quarterly update it is not equipped to interrogate. Cyber risk becomes a specialist function, walled off from the governance machinery that handles every other consequential exposure the institution carries.

What this framing hides is that the decisions that actually determine cyber exposure are not technical decisions at all.

The decisions underneath the breach

Consider what is really being decided when an institution sets its cyber posture. How much residual risk to accept. Which systems are worth protecting to what standard, and which are quietly left thinner because the budget ran out. Whether speed to market is allowed to outrun the controls that should travel with it. Who, by name, owns the consequence when a system the institution depends on is compromised.

None of these are engineering questions. They are governance questions. They are decisions about risk appetite, resource allocation, and accountability, which are the same decisions a board makes about credit, liquidity, or conduct. The difference is that for those exposures the institution has a governance structure that forces the decision into the open. For cyber, the decision is usually made implicitly, several levels below the board, by people optimising for a technical outcome rather than weighing an institutional one.

The breach is technical. The exposure was authorised, long before the breach, by a chain of decisions nobody recognised as governance.

How the framing creates the gap

Once cyber is filed as technology, a specific gap opens, and it is the same gap that produces most governance failures. The people with the authority to set the institution's true risk appetite do not understand the domain well enough to set it deliberately. The people who understand the domain do not have the authority to commit the institution. So the appetite is never actually set. It emerges, as the residue of a hundred operational choices made by technical staff who were never asked to make a strategic judgment and were never positioned to refuse one.

This is why an institution can be surprised by its own exposure. Asked beforehand, the board would have said cyber risk was well governed. The reports were current. The function was staffed. The framework existed. What the board never saw was that the framework described technical activity, not the institutional decisions that activity was quietly making on its behalf. The map covered the controls. It did not cover the appetite.

Cyber as a governance discipline

Treating cyber risk as a governance problem does not mean the board learns to read a vulnerability scan. The point is not to push technical judgment upward. It is to pull the genuinely institutional decisions back into the structure built to make them.

That means naming the residual risk in terms a board can actually weigh: not "we have patched the critical vulnerabilities," but "here is the exposure we are choosing to carry, here is what it would cost to reduce it, and here is the part of the business that depends on the system most at risk." It means deciding cyber appetite the way the institution decides every other appetite, deliberately and on the record, rather than letting it accumulate from below. And it means locating accountability for the consequence in someone senior enough to have weighed the trade-off, not in the technical team that inherited it by default.

The technology still matters. The defences still have to be built and run by people who understand them deeply. But the work of deciding how much risk the institution is willing to live with, and who answers for it, is governance work. Leaving it inside the technology function is not delegation. It is an abdication that looks like delegation, because the function receiving it was never asked to make the decision and has no authority to make it stick.

An institution that understands this does not have a better security team than its peers. It has the same security team, connected to a governance structure that makes the real decision visible before an incident makes it visible instead. The exposure is the same on a normal day. The difference shows only when something fails, and the institution discovers whether the risk it was carrying had ever actually been chosen.

The question worth sitting with is not whether an institution's cyber defences are strong. It is whether anyone with the authority to set its risk appetite has ever knowingly decided how much cyber exposure the institution is choosing to carry, or whether that decision is still being made, unseen, by people who were only ever asked a technical question.

I write about governance, risk, and the decisions institutions find hardest to make. If this is relevant to a problem you are working through, reach me at aan@asifahmednoor.com.

← Back to writing