top of page

ARVIND CLEMENTE

Reflection
1

The Risk Nobody Takes Seriously Until It Hurts

One of the things I have learned over the years is that organisations rarely ignore risk because they are careless. Most of the people I have worked with were serious, capable and genuinely trying to do the right thing. They set aside certain risks because they were busy attending to everything else.


Projects have deadlines. Customers are waiting. Budgets are spoken for long before the year begins.


Cybersecurity has to compete inside that room, and it is not an easy competition to win. What has always interested me is not that these risks are unknown. It is that they are known, named, sometimes even written down, and still allowed to wait.


I have sat in many budget conversations where cybersecurity was the line everyone agreed was important and no one wanted to fund. It rarely happens with any drama. There is no real argument. Someone simply observes that the investment can wait until next year, and because nothing has gone wrong, no one in the room can quite explain why it shouldn't.


That is the peculiar difficulty of this work. When systems are running normally, and month after month passes without an incident, it becomes very easy to believe that everything is fine. Quietly, without anyone deciding it, confidence takes the place of caution. Last year's renewal gets questioned because last year nothing happened. The absence of a problem is treated as proof that the spending was unnecessary, rather than as the result of it.


Success in security is almost impossible to see. When production rises, everyone notices. When sales improve, the numbers say so. But when an attack is prevented, nothing happens at all. The day looks exactly like every other day, which is precisely what everyone expected.


Doing the work well is what makes the work look unnecessary.


There is usually one person in the organisation who keeps raising the same risk. For a long time they are easy to overlook. Nothing they warned about has happened, and after a while their warnings begin to sound like habit rather than judgement. It is only afterwards, when the thing they described finally arrives, that everyone remembers they had been saying it all along.


And occasionally, something does arrive. I have watched organisations that spent years treating security as a cost approve, within a single week, the very investment they had deferred for three. The technology had not changed. The threats had not changed. What changed was how the risk suddenly felt.


That pattern taught me something I have come to believe quite firmly. One of the hardest responsibilities of leadership is preparing for events that may never happen. It means spending money, attention and political capital on a problem that has not yet appeared, and being willing to keep spending it precisely because it hasn't.


This is genuinely difficult. Budgets are finite. Every amount spent on resilience is an amount not spent on something with a visible, immediate return. Cybersecurity almost never produces growth you can point to. Its value shows up as the disruption that never occurred, the week that stayed ordinary, the incident nobody had to manage. Perhaps that is why it is so easily underestimated. We are not very good at valuing the things that quietly did not happen.


Increasingly, customers, regulators and business partners expect organisations to demonstrate that cyber risk is being managed properly. Frameworks such as ISO 27001 have become one way of showing that security is built on governance and discipline, rather than relying on the diligence of a few individuals who happen to care.


But the deeper lesson, for me, has less to do with frameworks. It is that cybersecurity was never really an IT problem. Technology teams can recommend controls, implement them and respond when something goes wrong. What they cannot do is decide how much risk the organisation is prepared to live with. That decision belongs to leadership, and it cannot be delegated to the people who merely operate the systems.


The most resilient organisations I have seen were rarely the ones with the largest security budgets. More often, they were the ones whose leaders understood, quietly and early, that resilience is built long before anyone discovers whether it works.

Closing Reflection

The greatest risks are rarely the ones that surprise us. More often, they are the ones we knew existed but believed could wait.


Leadership is not about preparing for the crisis we can see. It is about having the courage to prepare for the one we hope never comes.

— Arvind Clemente

Reflections on Leadership, Technology & Risk
About

These reflections draw on more than 28 years of experience leading technology, cybersecurity and business transformation. Their purpose is not to document events, but to preserve the leadership lessons those experiences revealed.

The views expressed are personal reflections and do not represent the views of any employer, client or organization.

Written from experience. Not from a template.

bottom of page