All insights
Cyber resilience6 min read

Security is a boardroom question long before it is a technical one

By the time a risk reaches the security team, the expensive decisions have usually already been made. Where resilience is actually won or lost.


When something goes wrong, the security team gets the call. They are the ones on the incident bridge at 2am, tracing the intrusion, containing the damage, writing the report. So it is natural to think of security as their problem, and their budget, and their failure when it fails.

It almost never is. By the time a risk lands on the security team's desk, the decisions that created it were made months or years earlier, in rooms security was never in.

The decisions that set the exposure

Consider where real incidents actually begin.

None of these are technical failures. They are ordinary business choices about data, suppliers, speed and cost, whose security consequences were simply not on the table when they were made.

Why "leave it to the experts" quietly fails

Handing security wholly to a specialist function feels responsible. It is also how the function ends up accountable for risks it has no power to prevent.

A security team can patch, monitor, segment and respond. It cannot un-collect the data the business decided to hoard, un-sign the vendor contract, or slow the release the board promised the market. It inherits the consequences of decisions made above it and is then measured on the outcome. That is not a strategy. It is a way to have someone to blame.

Resilience improves only when the questions move upstream, into the rooms where the consequential choices are actually made.

The questions a board should be asking

None of these are technical. All of them shape exposure more than any control ever will.

What data are we collecting, and what would it cost us if it leaked? Which of our suppliers could hurt us most, and what have we actually done about that? When we choose speed over caution, who decided, and did they know that is what they were choosing? And if the worst happened tomorrow, how would we find out, how long would we be down, and what would we tell our customers?

A leadership team that can answer those is in a stronger position than one with a larger security budget and no answers. Controls reduce the likelihood of an incident. These decisions determine how much an incident costs. Cost is the number the board will ultimately own.

Resilience is a property of the design, not a layer on top

The most secure systems are not the ones with the most security added at the end. They are the ones designed, from the first decision, to hold less, expose less and fail smaller. Security bolted on late is expensive and brittle. Security treated as a design constraint, a question asked in the room where data, vendors and timelines are decided, barely looks like security at all. It just looks like good decisions.

The cheapest security decision your organisation will ever make is the one taken before anything is built. The most expensive is the one discovered on the incident bridge.


Argentum helps leaders build security into technology decisions from the start, so resilience is a property of the design rather than a control added at the end. If security still lives only in the server room, let's change that.

Let’s discuss your next technology decision.

Schedule a consultation