Why We Ignore Cyber Risks We Already Know About
2026-07-01 · by SECURITYSQUAD

Standing at the edge of a cliff makes you freeze before you can even think – in 40 milliseconds, your pulse spikes, your muscles tense, the reflex takes over. Hand the same person a sheet of paper describing a cyber risk that could ruin their company, and nothing happens. No pulse spike, no reflex – even though the danger is objectively bigger. SECURITYSQUAD managing director René Karcher opened his talk at an IT security conference hosted by a regional chamber of commerce on 1 July 2026 with exactly that contrast.
Excellent risk managers – until it comes to cyber
The business owners in the room vet suppliers before they sign a contract. They insure machinery long before anything catches fire. They plan liquidity for scenarios that never happen. Knowing, assessing and managing risk is their trade, and has been for decades. Yet the same group reliably overlooks one particular kind of danger: the digital one.
A 200,000-year-old brain is still casting the vote
The reason is not a lack of knowledge but the architecture of the decision itself. Harvard psychologist Daniel Gilbert describes four traits that our danger-detection system responds to: Personal, Abrupt, Immoral, Now – PAIN, for short. Something with a face, sudden, outrageous, happening right now. A cyberattack ticks none of these boxes. No attacker to point to, silent for years, no moral outrage, and always "not today". Four empty boxes, so the alarm stays quiet – even though the damage is the same as from a fire. Just without a face.
The most honest moment in the room
Two questions laid this bare: "Who has fire insurance?" – every hand went up. "Who has a tested incident response plan for an IT outage?" – a handful of hands. Between those two shows of hands sit, roughly speaking, 200,000 years of evolution. We reliably insure the rare event and ignore the frequent one.
According to researcher Ralph Hertwig at the Max Planck Institute for Human Development, that is no accident but a pattern: deliberate ignorance. We do not tune out dangers because we do not know them, but because we do not want to know them – knowledge can hurt. On top of that comes what risk researcher Gerd Gigerenzer describes: we mainly fear what the people around us fear. As long as nobody talks about backups over lunch, the brain learns: harmless.
The countermeasure fits on one page
The good news: an evolutionary false negative does not need a brilliant model to fix it, just a simple routine. Four questions are enough to start a workable cyber risk management practice:
- What could happen?
- How likely is it?
- What would it cost me?
- What am I doing about it?
That is not a compromise compared to a more sophisticated method – quite the opposite. Nobel laureate Harry Markowitz famously did not invest his own money according to his celebrated portfolio formula, but simply split it 50/50 – and beat his own formula doing so. Simple heuristics regularly outperform complex models under uncertainty, as Hertwig's research shows.
From checklist to a resilient ISMS
A sheet of paper is a good starting point, but at some stage risk needs a lasting framework – owners, review cycles, evidence. That is exactly what an information security management system under ISO 27001 provides, or, as a quick entry point, a cyber risk check under DIN SPEC 27076. Both answer the same four questions from the talk, just systematically, repeatably and on the record.
The threat was never really the problem. Our decision-making was. So the question that hung in the room at the end of the talk is still addressed to you: which risk are you currently choosing not to see?
Read more: Cyber Risk Check under DIN SPEC 27076 · ISO 27001 & IT-Grundschutz · Our expertise