Who Do You Trust When Your Cyber Advisors Are Paid to Sell?

Posted on February 23, 2026

0



Following my blog 2 weeks ago on ‘Cyber Tail risk‘, an interesting comment in response to the LinkedIn post for the blog spun off a side thread I felt worth tugging.

To rebase the parallel theme I used in that earlier piece, before 2008, financial leaders were not short of warnings of what we now know was a seismic event in the financial markets globally. Domain experts flagged leverage and systemic risk. The problem was not a lack of insight, it was that uncomfortable truths were structurally easy to ignore. Cyber security is in the same place.

We have no shortage of threat reports, maturity models and tooling dashboards warning of systemic cyber risk be that supply-chain compromise, identity collapse, control-plane failure … and the list could go on. We are optimising for good days and exercising wilful blindness in the headlight glare and distraction of yet another tool (to rule them all!), another control (because the assurance report says so), another audit, automation and now AI as we diligently response incrementally to the drumbeat of the market.

The issue is not expertise. It is who the board hears from and why. Most organisations receive cyber advice from three sources (yes oversimplified perhaps, but it helps consolidate the point):

  1. In-house Security/OT/Risk teams – They know the estate best but are judged on delivery and compliance. Over time, risk is framed as technical debt, not strategic exposure. The hardest truths get softened to remain actionable.
  1. Vendor and supplier professional services – Often excellent but structurally incentivised to frame risk in ways that map to what they sell. Systemic risk that requires architectural or organisational change rarely fits a product roadmap.
  1. Independent advisors and consultancies – In theory, the place for uncomfortable truth. In practice, independence is fragile. Market narratives, partner ecosystems and commercial pressure soften messages that would challenge operating models, supplier concentration or trust architecture. Rarely do the not caveat out any carried accountability and avoid standing behind an organisations decision making when things go wrong, as they do.

This mirrors pre-2008 finance as I wrote about recently. Internal risk teams warned, product-aligned advisors optimised within constraints and independent voices were marginalised until failure made them undeniable. The result is expertise without authority.

Avoiding a cyber ‘2008 moment’ requires more than better tools. Boards need independent, system-level judgement with authority to challenge architecture, operating model and concentration risk not just control gaps.

Until then, organisations will keep doing what humans do best; recognise the pattern, repeat the mistake and act only after failure makes denial impossible.