top of page

ARVIND CLEMENTE

Reflection
7

The Slow Return of Complacency

Why Organizations Forget the Lessons They Once Promised Never to Repeat

One of the things I did not anticipate after the ransomware attack was how differently people would remember it. For me, that weekend permanently changed the way I thought about leadership, governance and organisational risk. For many others, it gradually became a memory.


That difference taught me another lesson. Organisations rarely abandon good security all at once. They do it one small compromise at a time.


Immediately after a major cyber incident, security becomes everyone's priority. Restrictions are accepted without resistance. Budgets are approved more quickly. Users understand why stronger controls are necessary, because the consequences are still fresh in everyone's mind. Fear creates clarity.


Unfortunately, time has a way of weakening memory. As months pass without another major incident, the urgency slowly begins to fade. Conversations change. Controls that once felt essential begin to feel restrictive. Security reviews are seen as delays. Requests for exceptions become more frequent. Convenience quietly starts competing with discipline. Nothing dramatic happens. The organisation simply begins to drift back toward the same habits that existed before the crisis. That is how complacency returns.


What makes cybersecurity particularly unforgiving is that attackers and defenders live by completely different rules. An attacker can fail hundreds of times and still succeed if just one opportunity remains. One compromised account. One overlooked vulnerability. One unnecessary exception. That is all it takes. Defenders face the opposite reality. They may prevent thousands of attacks without anyone noticing, yet one successful attack can undo years of careful planning, investment and hard work. That imbalance is why security can never become a one-time project. It must become a discipline.


Looking back, I realised that the greatest challenge after a major incident was not rebuilding systems. It was protecting the lessons we had learned. Every request for an exception became a quiet test. Every attempt to bypass a control asked the same question.


Have we already forgotten why this exists?


The longer an organisation operates without experiencing another major incident, the easier it becomes to believe the controls are no longer necessary. Ironically, that confidence is often created by the very controls people are questioning. This is the quiet trap of security done well: the longer it succeeds, the more invisible it becomes, until the calm it produces is mistaken for the absence of danger. The risk has not disappeared. It has simply been managed.


In the end, I no longer believe that resilience is created by technology alone. Technology supports resilience. Processes strengthen it. But what sustains it over time is culture. Culture is what reminds an organisation why difficult decisions were made, long after the crisis has faded from memory.


Because the slow return of complacency rarely announces itself. It simply waits until people begin to believe that yesterday's lessons no longer apply today.

Closing Reflection

Organizations rarely fail because they forget how to recover. More often, they fail because they forget why they prepared.


Complacency does not arrive with a warning. It returns quietly, one small compromise at a time.

— Arvind Clemente

Reflections on Leadership, Technology & Risk
About

These reflections draw on more than 28 years of experience leading technology, cybersecurity and business transformation. Their purpose is not to document events, but to preserve the leadership lessons those experiences revealed.

The views expressed are personal reflections and do not represent the views of any employer, client or organization.

Written from experience. Not from a template.

bottom of page