September 26, 2025
Cybersecurity is technical, but technology alone does not determine whether a security program works. In the welcome episode of the Hotman Group podcast, Cheri Hotman explains why effective cybersecurity requires judgment, risk management, business alignment, people, process, technology, and the ability to make practical decisions within real-world constraints.
In this introductory episode, Cheri explains why cybersecurity is as much art as science, why there is no one-size-fits-all security program, and what listeners can expect from future conversations about Cyber GRC, risk, compliance, business strategy, tools, people, and practical cybersecurity leadership.
Cybersecurity is as much art as science because organizations cannot eliminate risk, apply the same security model everywhere, or solve cybersecurity simply by buying technology.
Every organization has different business objectives, regulatory obligations, data, people, technology, risk tolerance, resources, and constraints. Cybersecurity practitioners have to understand those differences, identify meaningful risk, communicate it clearly, and design protections that support the business while reducing risk to an acceptable level.
That requires technical expertise — but it also requires judgment, communication, strategy, governance, people change management, and continuous improvement.
Cybersecurity has technical standards, frameworks, controls, testing methods, technologies, and well-established practices. That is the science.
The art begins when practitioners have to decide how those elements should actually be applied inside a specific organization.
A ten-person company and a 10,000-person company do not have the same risk profile. An organization handling regulated health information faces different considerations than one that does not. A rapidly growing technology company may accept different risks than a mature organization focused on stability.
The practitioner therefore has to evaluate the situation, understand the constraints, identify the risk, and determine what combination of controls, processes, technology, and oversight makes sense.
No organization can reduce cyber risk to zero while continuing to operate.
Doing business inherently creates exposure. Organizations use technology, collect data, rely on employees, work with vendors, connect systems, serve customers, introduce new products, and pursue opportunities.
The goal of cybersecurity is therefore not perfect protection. It is to identify risk, understand its potential impact, apply appropriate controls, monitor the environment, and help leadership decide what remaining risk the organization is prepared to accept.
Cybersecurity is not the pursuit of zero risk. It is the discipline of making better risk decisions.
That is why a strong cybersecurity risk assessment should give leadership decision-useful information rather than simply produce another technical document.
Frameworks and industry practices provide valuable structure, but organizations still need to determine how those practices apply to their own environment.
The right cybersecurity program depends on factors such as:
The framework may be standardized. The program built around it should still reflect the organization it is protecting.
Security exists to support the organization, not operate as a separate business inside it.
If leadership plans to enter a new market, pursue customers in a regulated industry, expand internationally, introduce new technology, or change its business model, those decisions may change the organization’s cybersecurity requirements and risk profile.
Cybersecurity leadership should understand those objectives and build a strategy that supports them.
That alignment also makes investment conversations more productive. Instead of asking leadership to fund an isolated security activity, practitioners can explain which business objective the investment supports, which risk it addresses, and what may happen if the organization chooses not to make it.
Technology can dramatically improve cybersecurity, but purchasing a tool does not automatically create an effective control.
Someone still needs to implement it correctly, configure it around the organization’s environment, assign responsibilities, monitor it, investigate failures, maintain it, and improve the surrounding process.
Cheri describes organizations with multiple vulnerability management or scanning tools that are not being used effectively because the broader lifecycle and process were never established.
The lesson is not that organizations should avoid technology. It is that technology should support a well-designed Cyber GRC operating model rather than substitute for one.
No.
Compliance can provide meaningful structure, assurance, customer trust, and revenue enablement. When implemented with integrity, compliance requirements can absolutely strengthen an organization’s security posture.
But an audit is still conducted within a defined scope and period, and testing may involve sampling. It does not automatically prove that every relevant cyber risk is being managed appropriately.
“Passing an audit is not security.”
— Cheri Hotman
That distinction matters because a clean audit can create false confidence if leaders begin treating it as proof that no further security investment is required. Read more about why passing a cybersecurity audit does not necessarily mean an organization is secure.
Cybersecurity programs depend on people making decisions and performing activities every day.
Employees need to understand expectations. Control owners need to know what they own. Teams need clear roles and responsibilities. Training needs to change behavior. Failures need to be identified and corrected. Leaders need useful metrics. Accountability and escalation need to exist when expectations are not met.
That means people change management is not peripheral to cybersecurity. It is part of cybersecurity.
A highly technical solution can still fail if the people and processes around it do not work.
Security awareness training is a good example of the difference between compliance activity and risk management.
If the goal is merely to prove that training occurred, the organization may technically satisfy a requirement without meaningfully changing behavior.
If the goal is risk reduction, the questions change: Did the right people complete the training? Do they understand the material? Is it relevant? Is it reinforced? Are expectations clear? Are completion and behavior monitored? What happens when someone does not comply?
When training is designed to reduce human risk, compliance becomes a natural byproduct of doing the underlying security activity well.
Security practitioners are often closest to technical risk, but leadership needs that information translated into something useful for business decisions.
That means moving beyond lists of controls, vulnerabilities, tools, and technical findings and explaining:
Leadership can then make an informed decision rather than being asked to approve a technical recommendation without enough context.
Cybersecurity should not operate as an endless series of isolated projects.
A cybersecurity strategy creates a roadmap for where the organization needs to go and connects near-term work with longer-term objectives.
That strategy should align directly with the business strategy. If the organization plans to enter banking, expand into the European Union, pursue new customers, grow through acquisition, or adopt new technology, security planning should anticipate what those decisions will require.
When cyber priorities connect directly to business objectives, leaders can understand why specific investments, controls, capabilities, or staffing decisions belong on the roadmap.
Cybersecurity is a crowded marketplace, and simple solutions are appealing.
A tool may be excellent. Automation may remove substantial manual work. A platform may dramatically improve visibility. A service may solve a real problem.
The problem begins when a product or service is presented as though it eliminates the need for the surrounding people, process, governance, oversight, and judgment.
If a cybersecurity solution sounds like it eliminates all the hard parts of cybersecurity, the organization should ask what work is still required around it.
Effective cybersecurity rarely comes from finding the easiest answer. It comes from understanding the real problem and applying the right combination of people, process, technology, and governance.
Cybersecurity includes technical standards and established practices, but organizations still need judgment to determine how those practices should be applied based on risk, business objectives, technology, people, regulations, and available resources.
The core purpose of cybersecurity is to manage and reduce risk to people, data, systems, operations, customers, and the organization while enabling the business to achieve its objectives.
No. Organizations accept some level of risk simply by operating. Cybersecurity helps identify, assess, mitigate, monitor, communicate, and make informed decisions about that risk.
No. Compliance can contribute significantly to cybersecurity when requirements are implemented effectively, but an audit or certification represents assurance over a defined scope and should not replace broader risk management.
Security technology still needs appropriate implementation, configuration, ownership, monitoring, maintenance, processes, and human oversight. A tool can support a security capability but does not automatically create one.
Business decisions change cyber risk. Understanding where the organization plans to grow, what markets it will enter, what customers it wants to serve, and what technology it plans to adopt helps security leaders build capabilities that enable those objectives safely.
People operate controls, make decisions, use technology, respond to incidents, complete training, manage vendors, and own business processes. Effective cybersecurity therefore requires clear responsibilities, education, communication, accountability, and change management.
This article is based on Episode 0 of the Hotman Group podcast, Cybersecurity Is as Much Art as Science, hosted by Cheri Hotman, Managing Partner of Hotman Group.
In this welcome episode, Cheri explains the philosophy behind the podcast: cybersecurity exists to mitigate risk, every organization is different, business context matters, technology is only part of the answer, compliance is not the finish line, and practitioners need to combine technical expertise with strategy, judgment, communication, and people change management.
Future conversations build on that foundation through practical, real-world discussions about cybersecurity, Cyber GRC, risk, compliance, tools, business strategy, and the challenges practitioners encounter while trying to protect organizations.
Organizations often bring in Hotman Group when cybersecurity activity exists but leadership needs help turning that activity into a coherent, risk-based program. HG can help when:
Hotman Group helps organizations build cybersecurity and Cyber GRC programs around real business risk, practical constraints, clear ownership, effective governance, and the outcomes the business is actually trying to achieve.
Hotman Group is a cybersecurity and Cyber GRC professional-services firm that helps organizations diagnose, design, build, remediate, implement, operate and mature cybersecurity programs. HG provides hands-on vCISO and vGRC leadership, supports multi-framework environments, and helps organizations select and implement GRC technology while connecting cybersecurity decisions to business risk and strategy.
Hotman Group works with organizations to move beyond disconnected tools, audit-driven activity, and one-size-fits-all security programs by aligning cybersecurity with the organization’s actual risk, operating environment, and business objectives.
Because there is no universal easy button, strong cybersecurity requires the right combination of people, process, technology, governance, judgment, and continuous improvement.