DECISION ARCHITECTURE

The Uncertainty Is Not an Accident 2

Cyber risk decisions rest on information shaped by every actor who passes it along. This piece maps the incentive architecture that produces that distortion, and what it takes to see through it.

AUTHOR

Karol Chwastowski

PUBLISHED

22.09.2026

Cybersecurity as a decision problem

Investing in cybersecurity is a sharp case of a problem the decision sciences have studied for decades under the name deep uncertainty. It holds when the parties to a decision do not know, or cannot agree on, the model of the system they are dealing with, the probability distributions over its inputs, or how outcomes should be valued. What distinguishes this case from climate policy or infrastructure planning, the fields where these methods matured, is that the uncertainty here is not a residue of ignorance. Someone produces it, deliberately, and has reasons to.

Weaknesses in decision architecture in this domain do not announce themselves openly. They compound. Early on they read as ordinary process inefficiency, or they produce false optimism, because the same limited visibility that conceals the risk also makes the report more flattering to the organisation being assessed. Gradually operational efficiency slows enough to be noticed, and the optimism of reports begins to be questioned. The manifestation, when it comes, tends to be violent and triggers a cascade of problems. By the point the pattern is legible, there is no inexpensive way to stop it.

The pattern is not hypothetical. Two of the most consequential compromises of the last decade reached their victims through a supplier’s routine software update rather than through anything those victims controlled, and both were visible only after the cascade had run. Closer to home, a recent breach of medical records in Poland moved from a single point of access to a matter of public record faster than the affected parties could establish what had actually been taken.

How information asymmetry is formed

Three dimensions shape information about risk before it reaches a decision-maker. They map onto the three conditions of deep uncertainty, which is why the domain satisfies all of them at once.

The incentive dimension. Information about risk is actively shaped by stakeholders before it reaches decision-makers. This is not pathology. It is the rational consequence of an incentive structure known as the principal-agent problem, and it is the dimension in which parties cannot agree on how to value outcomes, because their outcomes are not the same.

The regulatory dimension. Standards and certifications formalize a minimum compliance threshold, not an actual level of resilience. A requirement written to be verifiable across an entire sector cannot describe the exposure of any single member of it, and a control installed to pass an audit is built for the audit rather than for the threat. It still appears on the list of things protecting you. So the organisation does not simply end up with a weak defence. It ends up with a wrong picture of the defence it has.

The operational dimension. Cybersecurity events — the serious ones above all — are disclosed selectively, late, or never. Data on real incidents, attack vectors, and losses sustained does not circulate freely. Every organization decides under a fundamentally constrained view of what happens to everyone else, which is the dimension of straightforward not knowing: no distribution can be defended because the underlying population is unobservable.

All three may coexist and compound over each other. Consider how that works in practice. A consulting company engaged as an expert in the design of a legal act bases its insights on threat reports supplied by a security software vendor that adjusted its research methodology to lend credibility to a particular offering. Working from that reference, the consulting company shapes regulatory requirements in a direction that will let it standardize the delivery model of its own future services — simplifying sales, easing scale, widening the recruitment pool. All of which any B2B service provider needs if its business model is to survive customer price expectations. Stakeholders inside the legal authority shape the scope further, in line with their own plans and constraints. The finished act, once in force, is implemented in a given company by a CISO who competes with the legal department for resources, so each side interprets the requirements in a way that minimizes its own obligations, sometimes without noticing that this damages the holistic resilience of the organisation. And it continues up the chain, until a board member has to draw a precise line where acceptable risk ends and, under European law, take personal responsibility for getting it wrong.

Different actors inside the same system hold fundamentally different fragments of reality. The board, the CISO, the vendor, the regulator, and the investor each see a different piece, each face different incentives, and each communicate risk selectively. At no point in that chain did anyone lie or act maliciously. Everyone attended first to what mattered to them. As a result, strategic decisions rest not on facts but on optimized narratives.

The architecture of incentives

The behaviour described above fits a useful analytical frame: every actor holds private information unavailable to the others and makes decisions by optimizing their own payoff function, not the collective outcome. Table 1 sets out the incentives of the principal participants in the cybersecurity ecosystem.

Table 1. The architecture of incentives in the cybersecurity ecosystem

Actor

Access to information

Optimizes

Communicates

Vendor

Own product

Sales and contract retention

Effectiveness and uniqueness of the solution

Integrator

Project scope and schedule

Project margin, avoidance of liability

Conformance to requirements and timeliness

CISO / CIO

Posture of the entire organization

Budget, organizational calm, own professional risk

A manageable picture of risk, without raising alarm

Regulator

Sector compliance

Enforcement of the adopted standard

The minimum threshold of conformance as sufficient

Board

The narrative received from the CISO

Stability and continuity of reporting

Confirmation that the strategy is correct

Investor

Board reports and benchmarks

Portfolio financial performance

Sector risk as the point of reference

Each actor behaves rationally within the system that shaped them. A vendor selling the effectiveness of a product rather than risk reduction is doing what its business model requires. A CISO filtering the message to meet organizational expectations is acting in accordance with institutional rationality. A regulator communicating a minimum standard is not exceeding its mandate. The system rewards conformance and reportability, not operational truth.

The mechanism known from agency theory — where the agent holds a greater store of information than the principal and optimizes their own interests — operates here in a multiplied version, which the literature describes as the multi-layer principal-agent problem. Every layer in the information chain is simultaneously an agent toward the layer above and a principal toward the layer below. The decision-maker at the top of the structure receives information that has passed through successive stages of selection and adaptation.

A consequence of this structure is that the problem is not solved by adding another expert node. Expertise is not what is missing. An advisor brought in from outside arrives with a payoff function of their own, and unless that function is built differently from every other one in the chain, they become one more layer of selection — a better-informed layer, which makes the distortion harder to see rather than smaller. The outside position does not buy accuracy. It buys the possibility of accuracy, and only if the terms are right.

Technical assurance is worth separating out, because it is regularly mistaken for the answer. A red team with broad reach does reduce asymmetry, but only in the operational dimension: it establishes what the controls actually do. It says nothing about the incentives that shaped the report, and nothing about which of its findings should change a decision. Translating operational fact into strategic choice is a separate function, and not an interchangeable one.

What would have to be true instead

If you do not understand how the risk narrative reaching you was produced, you are not managing risk. You are consuming it. Reducing the asymmetry requires an independent interpretive layer able to translate operational signals — including those from the lower tiers of the organization, where visibility into detail is greatest — into the language of strategic decisions. Three conditions have to hold at once for that layer to be anything other than one more filter.

Parallel command of cybersecurity logic and business logic. A technical finding does not come with a price tag attached. The same misconfiguration can sit on the system that prices your product or on the one that books meeting rooms, and the finding reads identically in both cases. Sorting them takes someone who knows what the business does with each system. Questioning them takes someone who knows what the finding means. Most people have one of those and not the other. With only the business side, an advisor escalates everything, because they cannot tell which items matter. With only the technical side, they accept whatever order they are given, because they have no grounds to argue. Both look like thoroughness from the outside.

A position whose long-term success depends on the quality of its risk judgments — and not on implementation cost, project scope, or the division of responsibilities chosen. The negative half of that condition carries as much weight as the positive one, because both common arrangements fail it, in opposite directions. An advisor responsible for implementation has an incentive to escalate every deviation, because this increases his workload and compensation. An integrator on a fixed fee has the opposite incentive to overlook the findings that would widen the work at their own cost. One inflates the risk picture, the other deflates it, and neither distortion requires dishonesty — both are what the contract pays for. So what the advisor finds cannot be allowed to change what the advisor earns. That leaves only one thing to be judged on, and it takes years to show: whether the calls were right. An advisor paid that way has to answer the same question the CEO answers — where does acceptable exposure end.

An institutional position outside the organization’s hierarchy, at the level of its leadership. Without it, the role steadily reverts to being one more filter of perception. Anyone inside the structure depends on it — for budget, for standing, for what happens after they deliver bad news to the person who signs off their work. It shapes what gets raised, how sharply, and to whom, long before anyone decides to soften anything. The position has to sit outside that dependence, and high enough that going around it is not an option.

In an environment where all actors tell the truth, but not the whole truth, the advantage goes to those who understand the architecture of that selection. Decoding incentivized risk narratives takes experience, but the deconstruction above should be enough to change how you select and reward the advisors you rely on. That gives you an information feed you can reason from, without mistaking it for a complete one. The next problem is how to codify cyber risk decisions — to keep their quality consistent, allow for incremental improvements, and make delegation possible.

This might interest you as well

This might interest you as well

DECISION ARCHITECTURE

DORA and NIS2 now put personal liability for cyber risk oversight on management bodies. This piece sets out why compliance is not a substitute for a real decision framework, and what such a framework has to contain.

Article cover image

DECISION ARCHITECTURE

Cyber risk decisions rest on information shaped by every actor who passes it along. This piece maps the incentive architecture that produces that distortion, and what it takes to see through it.

Article cover image

DECISION ARCHITECTURE

DORA and NIS2 now put personal liability for cyber risk oversight on management bodies. This piece sets out why compliance is not a substitute for a real decision framework, and what such a framework has to contain.

Article cover image

/

NEWSLETTER

Get email notifications about new publications, 

case studies and open source frameworks

Follow us on other platforms:

© 2026 Metastrategy. All rights reserved.

/

NEWSLETTER

Get email notifications about new publications, case studies and open source frameworks

Follow us on other platforms:

© 2026 Metastrategy. All rights reserved.

/

NEWSLETTER

Get email notifications about new publications, 

case studies and open source frameworks

Follow us on other platforms:

© 2026 Metastrategy. All rights reserved.