Home › Blog

#ninjatheme 2026/Uncertainty at Speed Part 2: The Cost of Pretending You’re in Control

If uncertainty is the native condition of modern cybersecurity, then many security programs are not merely underprepared; they are structurally and psychologically misaligned with the environment they operate in.

For decades, we optimized security organizations around the elimination of uncertainty. We reward confidence. We fund long-range plans. We promote leaders who project control over systems that are continuously mutating. These instincts once made sense. Infrastructure was slower. Adversaries were noisier. Change happened on annual cycles rather than hourly ones.

That world no longer exists.

By 2026, the most dangerous phrase in cybersecurity will not be “we didn’t know.” It will be “we were confident.”

Confidence has a cost. It freezes decisions. It hardens assumptions. It defends sunk investments long after their relevance has decayed. Most importantly, it teaches organizations to treat early signals as noise when those signals threaten the story of control they have already committed to telling.

This is how mature programs quietly become fragile.

Uncertainty Is Not a Failure Mode

Security teams are still taught, implicitly and explicitly, that uncertainty is a defect to be engineered away. We build controls to close gaps. We build dashboards to clarify state. We align to frameworks that promise completeness.

Modern cyber conflict does not reward completeness. It rewards responsiveness under ambiguity.

Attackers already operate this way. They do not wait for full information. They probe, observe reactions, discard hypotheses, and adapt. They act inside uncertainty because it is cheaper than waiting for clarity.

Defenders often behave as if action must be justified by certainty. The result is delay. Delay converts weak signals into strong incidents. By the time certainty arrives, the opportunity to act cheaply has already passed.

Uncertainty is not a failure mode. It is the environment.

When Process Becomes the Enemy

As uncertainty increases, organizations compensate by adding process. More reviews. More approvals. More alignment exercises. More artifacts. These mechanisms create the feeling of control while extending the distance between signal and decision.

This is the quiet failure mode that will define 2026.

Not breaches that trigger headlines, but security organizations that slowly lose relevance as decisions migrate elsewhere; to cloud teams, product teams, and operators who can move faster without permission.

The post-incident document written in passive voice is not an outcome. It is a symptom.

The Mirror Effect

Automation and analytics will accelerate this divide, not because they magically solve security, but because they expose organizational behavior at scale.

Used honestly, these systems reveal how often alerts were acknowledged but not acted upon; how often anomalies were investigated just enough to justify deferral; how often risks were known, documented, and left unresolved; how frequently explanation was mistaken for progress.

This feels less like optimization and more like indictment.

Organizations that treat these capabilities as another certainty engine, a way to produce cleaner answers or more reassuring narratives, will miss the point. Their value lies in compressing feedback loops until hesitation becomes visible and costly.

They do not remove uncertainty. They remove the ability to pretend it was not there.

From Roadmaps to Missions

This is why execution models matter more than tools.

Security programs that succeed will move away from static roadmaps and toward mission-oriented execution. Initiatives will be time-boxed. Learning objectives will be explicit. Authority will move closer to the signal. Architectures will be evaluated on reversibility rather than permanence. Failure will be treated as data rather than disgrace.

This is not chaos. It is disciplined adaptability.

This is why I keep pointing to systems like DARPA’s. Not because cybersecurity should become a research lab, but because DARPA was designed for environments where the adversary adapts, the problem is poorly defined, and the cost of delay exceeds the cost of visible failure.

In other words, reality.

The Psychological Shift Leadership Resists

The hardest adjustment is not technical. It is psychological.

Leaders must become comfortable acting without consensus, learning in public, and admitting when previous decisions no longer make sense. Most organizations are structured to punish exactly this behavior.

By 2026, resilience will not look like calm mastery. It will look like organizations that are visibly busy, occasionally wrong, continuously adjusting, and learning faster than their adversaries.

They will not claim certainty. They will claim speed.

The Real Divide

The divide in 2026 will not be between organizations with better tooling and those without it. It will be between organizations that can operate effectively inside uncertainty and those that still require certainty to move.

Security will not win by becoming more confident. It will win by becoming more honest about what it knows, what it does not, and how quickly it can act either way.

The future belongs to organizations that can decide, move, and learn while the ground is shifting, without pretending otherwise.

That is the bar for 2026.

scottg/out

The Probably Fine Daily

Threat intelligence every morning — new victims, new groups, what matters, in plain English. Free, with receipts.

Subscribe to the Daily →

Originally published on LinkedIn ↗

← All writing