Cyber problems have a particular kind of persistence. They don’t just recur; they resurface with different names, different systems, sometimes different teams – and yet the underlying pattern feels familiar.
At events and in board meetings, we tend to frame cyber security in two directions: We talk about the people dimension, usually through culture and awareness and we talk about the technology dimension, usually through controls, tooling and budgets.
Both are essential. In many organisations, strengthening these basics is exactly what reduces everyday risk, and it’s often the fastest way to prevent common incidents. But there is another factor that determines whether those people and controls hold up under real pressure. How does the organisation run cyber day-to-day?
That includes things like: who owns what, how decisions are made, what gets checked and when, what gets documented, how exceptions are handled, and what learning looks like after something goes wrong.
When those routines are unclear or inconsistent, cyber incidents are not random. They become predictable.
Asking “why?” is the shortest route to the root cause
Asking “why?” repeatedly can feel uncomfortable, partly because it pushes us away from tidy explanations. “Someone clicked a link” is easy to understand. “Our processes make it normal for people to rush, improvise and approve things informally” is harder, because it implicates the system.
But asking “why?” is also one of the simplest ways to stop treating cyber as a series of surprises.
Take a familiar scenario. Someone enters credentials into a convincing login page. We can stop at “They fell for a phishing email,” or we can keep going.
Why did they fall for it? Perhaps because it looked legitimate and they were rushed.
Why were they rushed? Perhaps because approvals happen late, often through email, and delays cause real pain.
Why is that approval process so time-sensitive? Perhaps because it isn’t documented well, ownership is unclear, and workarounds have become normal.
At that point, the incident is no longer a story about one person’s judgement. It becomes a story about process workflow design, responsibility and oversight, the things that determine whether training and technology actually hold under pressure.
This is also why many post-incident actions don’t reduce repeat incidents. They address the last step in the chain rather than the chain itself.
When a problem looks technical, check how it is managed over time
Cyber often sounds technical, and many incidents genuinely are technical in nature: vulnerabilities, misconfigurations, unpatched systems, failed backups, compromised admin accounts. Strong baseline controls and good technical practice reduce these risks significantly.
But when these issues persist, it’s worth asking an operational question: how did this remain normal for long enough to become a problem?
Take patching. On the surface, patching is a technical task. In practice, it’s an organisational agreement about disruption and risk. It raises questions about who decides when downtime is acceptable, who owns assets that sit between teams, how dependencies are tracked, and what happens when exceptions become routine.
A technical failure often sits on top of familiar operational gaps: responsibilities that aren’t clear between teams, documentation that isn’t kept current, training that doesn’t match real workflows, and checks that happen inconsistently because everyone is stretched.
The cycle organisations get stuck in
There is a recognisable loop that many organisations fall into, even when they care and invest.
An incident happens, urgency takes over, and the organisation learns just enough to restore service. A few visible actions follow, and then operational pressure returns and pulls attention elsewhere.
Months later, another incident happens. Sometimes it’s the same category. Sometimes it’s a different category with the same underlying weakness.
This is how organisations become reactive by default. Understanding root causes breaks the loop by turning response into prevention.
Leaders don’t need deep technical knowledge — they need the confidence to question
One persistent myth in cyber is that resilience is primarily a technical achievement. Technical expertise matters, and so do baseline controls that reduce common risks, but many of the decisions that reduce risk are leadership decisions.
Leaders do not need deep technical knowledge to improve cyber resilience. They need the confidence to challenge, question and understand risks.
In practice, that confidence looks like asking who owns a risk, how controls are maintained and tested over time, whether the incident response plan has been practised under pressure, and what changed since the last incident.
These are governance questions, and governance is where consistent cyber practice is made real.
Resilience is alignment, not size
Whether an organisation is large or small, cyber resilience depends on aligning people, routines and technology.
Small organisations can be resilient when responsibilities are clear, controls are realistic and response is practised. Large organisations can be fragile when ownership is blurred and lessons learned don’t translate into day-to-day improvements.
Controls and tools matter, but they work best when they are supported by clear ownership, repeatable routines and leadership oversight.
So why do cyber problems keep coming back?
Because the system that produced them hasn’t changed.
Incidents repeat when we treat them as isolated events instead of signals, focus on immediate recovery rather than strengthening what happens before the incident, allow exceptions to become normal, and fail to turn learning into sustained improvement.
Create assurance and build confidence
The organisations that improve fastest tend to build one habit: asking “why?” consistently, and then being disciplined enough to change what the answer reveals, even when inconvenient.
IASME Cyber Assurance (ICA) supports this approach by helping organisations build cyber confidence through good governance, alongside effective controls that make good practice repeatable.
IASME Cyber Assurance is a flexible, risk-based cyber security standard and certification scheme designed to help organisations of all sizes strengthen their risk governance and achieve cyber resilience. The full IASME Cyber Assurance Standard aligns with the UK Government’s DSIT Cyber Governance Code of Practice.
Learn more about IASME Cyber Assurance here, or contact [email protected]
