Insights

Your Biases Are Setting Your Cybersecurity Priorities

Dave Goldberg Dave Goldberg · 8 min read
Your biases are setting your cybersecurity priorities

Every budget is a set of judgment calls

Every security budget includes a number of judgment calls. Each decision prioritizes what gets explored, funded and staffed. And each comes with its own subtle biases which affect the outcome and ultimately what we work on. Knowing these biases helps prevent spending effort in areas which might not yield the best results.

The 2026 Verizon DBIR clearly outlines that you cannot fix everything. Decisions must be made as to what to patch. That's just vulnerabilities. Add IAM, data protection, posture management and all the other mitigations and the number of things to prioritize against one another grows exponentially. That means every business needs to make intelligent choices part of their core strategy.

But if choosing is now part of the strategy, who or what is doing the choosing?

In most organizations the answer is human judgment, applied under time pressure, with incomplete information, imperfect resources, in a domain where nothing happening is the only signal you have that you got it right. That's about as ambiguous as it gets.

Those are precisely the conditions where judgment fails in predictable, well-documented ways. Behavioral science has spent years cataloging how decisions break down under sub-optimal conditions. Layer in some outdated assumptions from what worked at your last job, and the whole thing gets shakier. Security programs exhibit these biases and more. Each bias compounds and moves money away from where the potential risk actually sits.

Why security is a natural habitat for bias

Bias thrives where feedback is weak. A sales forecast meets the actuals every quarter. There is an inherent feedback loop that can be tested over time. A security prioritization decision may never meet reality at all because the incident it prevented stays invisible. A quiet year reads as vindication of what you worked on. There are no KPIs for what didn't happen. So, we naturally fill in the gaps with our own stories.

Add the other conditions which make judgment difficult:

  • The threats are probabilistic
  • The data is filtered or incomplete
  • The stakes make dramatic scenarios memorable and newsworthy
  • Vendors have an incentive to make the threat they prevent the vivid one
  • We assume past successes apply to current or future scenarios, even when conditions have changed

Pick your poison.

Really though, the point is not to blame the people making the calls. It is to notice that trying to apply judgment was going to have a hard time surviving these circumstances, and that failing to recognize this bias makes bad decisions far more likely.

Knowing “bias exists” changes nothing about a budget. Knowing that a specific bias is currently overweighting your ransomware project and not giving enough priority to your privileged remote access request is something you can actually correct for. That's why they're worth calling out one by one instead of lumping them together.

Here are six biases doing the choosing in most security programs, how they slip into decision making, and how to mitigate against them. They're things you've probably watched happen in a budget meeting, maybe even done yourself. It's not easy to eliminate them all. Let's face it, we're human. But the more you shine the light on where bias is creeping in, the more you can catch it before it sets your budget for you.

Quick note. A biased judgment call and an unbiased one may land on the same conclusion. That doesn't justify the bias, that's just a fortunate accident. Don't let the right call for the wrong reasons persist. Annie Duke's book, “Thinking in Bets,” calls this “resulting”, judging a decision by whether it worked out rather than whether the reasoning was sound. Worth a read if you want the fuller picture.

1. The headline

Every week it's a new headline. The Anthropic Mythos hype swept through security teams the moment it became public knowledge. Are we exposed to this? Slides got built. Meetings got scheduled. Meanwhile the boring stuff, the exposed API, the third party vendor with too much access, the account that never got MFA, kept quietly not getting focus.

It's called “availability bias.” What's easy to recall feels more urgent, and headlines are engineered to be recalled. The 2026 Verizon DBIR tells a different story: most breaches involve unglamorous stuff like stolen credentials and simple mistakes. Nobody schedules an emergency meeting about a boring thing.

2. The blind spot

You can only prioritize the risks you can picture. The scenario nobody's imagined gets a budget of zero. Every time. Not a single person decided that on purpose.

This isn't a bias in the clinical sense, more of a structural gap. But it might be the most dangerous item on this list, because it's invisible by definition. Missing the truly novel is understandable. Missing the much larger set of known risks is a different story, and we should be considering a far larger set of them than memory alone is likely to surface.

3. The old playbook

“That's how we've always done it” is influencing your priorities more than anyone wants to admit. Sometimes it's not even your own history. A new security leader arrives with the playbook that worked at their last company, and applies it without asking if the new business looks anything like the old.

It rarely does. A retail bank and a fintech startup might seem similar and still have almost nothing in common in terms of what needs protecting. One runs on decades of legacy infrastructure and slow-moving compliance. The other runs on a handful of cloud-native services with a much smaller attack surface and a different regulatory footprint. What worked at your last job was tuned to that organization's dependencies, its way of making money, its regulatory exposure. None of that transfers by default.

This “status quo” bias is sneaky because it doesn't feel like a decision. It feels like experience. But experience from a different business is still someone else's playbook.

4. The HiPPO problem

The CEO read an article in their feed. A board member's brother-in-law got phished. Suddenly that's this quarter's top priority, whether or not it reflects your actual exposure. There's a good chance it's a distraction from what really matters.

It's sometimes called the HiPPO effect (Highest Paid Person's Opinion). The person with the biggest salary or outsized influence wins. Senior people aren't wrong to care, they should be asking questions. But seniority isn't evidence. If the HiPPO and the biggest risk happen to be the same thing, that's a coincidence, not a plan.

5. Borrowed exposure

A competitor gets breached and suddenly you're buying whatever stops that specific attack. It feels responsible. It's actually called “herding.”

One company's breach tells you what happened to them, not what's most likely to happen to you. Same issue as the old playbook, their business isn't yours, so their incident doesn't automatically rank the same on your list. It might even be a real exposure for you too, that's not the issue. The issue is where it ranks.

Did you just let it cut the line because it made the news? Moving it to the front means something that was actually first gets pushed back. Reacting to their incident protects you against their risk profile, at the expense of yours.

6. Outsourced judgment

A vendor hands you a risk score. Your auditor hands you a list of gaps. The framework you're using provides a maturity model. All useful. None of them are specific to your business.

The trap is treating someone else's generic priority list as your own, built to apply broadly across a wide range of companies, not built for yours. These rankings can be a useful starting point, but they need translating to your specific way of working. A system with no 2FA might show up as high risk on a generic scorecard. You know that system only holds public marketing content, so the real damage from a compromise is minimal. Priorities are not one size fits all.

Shrinking the space bias operates in

No one is doing anything wrong on purpose. Seniority feels like insight. Consensus feels like safety. Experience feels like knowledge. That feeling is exactly why these are hard to catch from the inside.

You cannot reason your way out of a blind spot. What moves the needle is a methodology, applied consistently to every scenario, so the outcome depends on the data rather than on who's in the room. Collect information across the whole business rather than from whoever's loudest. Then run the analysis without an attached opinion. You cannot fully remove bias, humans are still setting up the model. But you can shrink the space where it operates.

That's the problem Cordaata is built to solve. It maps risk to how your business actually operates, its processes, systems, and dependencies, and runs every scenario through the same evidence-based model. No headline gets a head start. No borrowed playbook gets grandfathered in. The output is a number, built the same way every time, for a business that isn't like anyone else's.

See your cyber risk in financial terms

Book a Demo