Cybersecurity Is as Much Art as Science: Why Risk and Business Context Matter

September 26, 2025

Cybersecurity is technical, but technology alone does not determine whether a security program works. In the welcome episode of the Hotman Group podcast, Cheri Hotman explains why effective cybersecurity requires judgment, risk management, business alignment, people, process, technology, and the ability to make practical decisions within real-world constraints.

Listen to the Episode

In this introductory episode, Cheri explains why cybersecurity is as much art as science, why there is no one-size-fits-all security program, and what listeners can expect from future conversations about Cyber GRC, risk, compliance, business strategy, tools, people, and practical cybersecurity leadership.

The Short Answer

Cybersecurity is as much art as science because organizations cannot eliminate risk, apply the same security model everywhere, or solve cybersecurity simply by buying technology.

Every organization has different business objectives, regulatory obligations, data, people, technology, risk tolerance, resources, and constraints. Cybersecurity practitioners have to understand those differences, identify meaningful risk, communicate it clearly, and design protections that support the business while reducing risk to an acceptable level.

That requires technical expertise — but it also requires judgment, communication, strategy, governance, people change management, and continuous improvement.

Key Takeaways

  • Cybersecurity exists to mitigate risk. The objective is not zero risk, because eliminating all risk would usually mean eliminating the business itself.
  • There is no universal cybersecurity blueprint. The right program depends on the organization’s business model, objectives, data, size, people, regulatory environment, risk tolerance, and constraints.
  • Security must support the business. Cybersecurity strategy should align with what the organization is trying to accomplish rather than operate independently of business objectives.
  • Tools are only part of the answer. Technology needs people, process, ownership, configuration, monitoring, and continuous improvement around it.
  • Passing an audit is not the same as being secure. Compliance can strengthen security when done with integrity, but an audit is still limited by scope, sampling, and timing.
  • People change management is cybersecurity work. Roles, responsibilities, training, communication, accountability, coaching, and escalation all affect risk.
  • Strong practitioners translate cyber risk into business decisions. Leaders need clear information they can use to prioritize investment and make informed risk decisions.

Why Is Cybersecurity as Much Art as Science?

Cybersecurity has technical standards, frameworks, controls, testing methods, technologies, and well-established practices. That is the science.

The art begins when practitioners have to decide how those elements should actually be applied inside a specific organization.

A ten-person company and a 10,000-person company do not have the same risk profile. An organization handling regulated health information faces different considerations than one that does not. A rapidly growing technology company may accept different risks than a mature organization focused on stability.

The practitioner therefore has to evaluate the situation, understand the constraints, identify the risk, and determine what combination of controls, processes, technology, and oversight makes sense.

Can Cybersecurity Eliminate Risk?

No organization can reduce cyber risk to zero while continuing to operate.

Doing business inherently creates exposure. Organizations use technology, collect data, rely on employees, work with vendors, connect systems, serve customers, introduce new products, and pursue opportunities.

The goal of cybersecurity is therefore not perfect protection. It is to identify risk, understand its potential impact, apply appropriate controls, monitor the environment, and help leadership decide what remaining risk the organization is prepared to accept.

Cybersecurity is not the pursuit of zero risk. It is the discipline of making better risk decisions.

That is why a strong cybersecurity risk assessment should give leadership decision-useful information rather than simply produce another technical document.

Why Can’t Every Company Use the Same Cybersecurity Program?

Frameworks and industry practices provide valuable structure, but organizations still need to determine how those practices apply to their own environment.

The right cybersecurity program depends on factors such as:

  • The organization’s size and operating model
  • The types of data it stores and processes
  • Customer and regulatory requirements
  • Industry and threat exposure
  • Technology architecture and third-party dependencies
  • Workforce and organizational structure
  • Available budget, time, skills, and resources
  • Business strategy and appetite for risk

The framework may be standardized. The program built around it should still reflect the organization it is protecting.

Why Must Cybersecurity Align With Business Objectives?

Security exists to support the organization, not operate as a separate business inside it.

If leadership plans to enter a new market, pursue customers in a regulated industry, expand internationally, introduce new technology, or change its business model, those decisions may change the organization’s cybersecurity requirements and risk profile.

Cybersecurity leadership should understand those objectives and build a strategy that supports them.

That alignment also makes investment conversations more productive. Instead of asking leadership to fund an isolated security activity, practitioners can explain which business objective the investment supports, which risk it addresses, and what may happen if the organization chooses not to make it.

Why Isn’t Buying More Cybersecurity Technology Enough?

Technology can dramatically improve cybersecurity, but purchasing a tool does not automatically create an effective control.

Someone still needs to implement it correctly, configure it around the organization’s environment, assign responsibilities, monitor it, investigate failures, maintain it, and improve the surrounding process.

Cheri describes organizations with multiple vulnerability management or scanning tools that are not being used effectively because the broader lifecycle and process were never established.

The lesson is not that organizations should avoid technology. It is that technology should support a well-designed Cyber GRC operating model rather than substitute for one.

Is Passing a Cybersecurity Audit the Same as Being Secure?

No.

Compliance can provide meaningful structure, assurance, customer trust, and revenue enablement. When implemented with integrity, compliance requirements can absolutely strengthen an organization’s security posture.

But an audit is still conducted within a defined scope and period, and testing may involve sampling. It does not automatically prove that every relevant cyber risk is being managed appropriately.

“Passing an audit is not security.”

— Cheri Hotman

That distinction matters because a clean audit can create false confidence if leaders begin treating it as proof that no further security investment is required. Read more about why passing a cybersecurity audit does not necessarily mean an organization is secure.

Why Are People and Process Such a Big Part of Cybersecurity?

Cybersecurity programs depend on people making decisions and performing activities every day.

Employees need to understand expectations. Control owners need to know what they own. Teams need clear roles and responsibilities. Training needs to change behavior. Failures need to be identified and corrected. Leaders need useful metrics. Accountability and escalation need to exist when expectations are not met.

That means people change management is not peripheral to cybersecurity. It is part of cybersecurity.

A highly technical solution can still fail if the people and processes around it do not work.

What Does Security Awareness Training Have to Do With Risk?

Security awareness training is a good example of the difference between compliance activity and risk management.

If the goal is merely to prove that training occurred, the organization may technically satisfy a requirement without meaningfully changing behavior.

If the goal is risk reduction, the questions change: Did the right people complete the training? Do they understand the material? Is it relevant? Is it reinforced? Are expectations clear? Are completion and behavior monitored? What happens when someone does not comply?

When training is designed to reduce human risk, compliance becomes a natural byproduct of doing the underlying security activity well.

How Should Cybersecurity Leaders Communicate Risk to the Business?

Security practitioners are often closest to technical risk, but leadership needs that information translated into something useful for business decisions.

That means moving beyond lists of controls, vulnerabilities, tools, and technical findings and explaining:

  • What risk exists
  • Why it matters to the organization
  • What business objective could be affected
  • What options are available
  • What resources would be required
  • What residual risk remains after action is taken

Leadership can then make an informed decision rather than being asked to approve a technical recommendation without enough context.

Why Does Cybersecurity Need a Strategy?

Cybersecurity should not operate as an endless series of isolated projects.

A cybersecurity strategy creates a roadmap for where the organization needs to go and connects near-term work with longer-term objectives.

That strategy should align directly with the business strategy. If the organization plans to enter banking, expand into the European Union, pursue new customers, grow through acquisition, or adopt new technology, security planning should anticipate what those decisions will require.

When cyber priorities connect directly to business objectives, leaders can understand why specific investments, controls, capabilities, or staffing decisions belong on the roadmap.

Why Should Organizations Be Skeptical of the Cybersecurity “Easy Button”?

Cybersecurity is a crowded marketplace, and simple solutions are appealing.

A tool may be excellent. Automation may remove substantial manual work. A platform may dramatically improve visibility. A service may solve a real problem.

The problem begins when a product or service is presented as though it eliminates the need for the surrounding people, process, governance, oversight, and judgment.

If a cybersecurity solution sounds like it eliminates all the hard parts of cybersecurity, the organization should ask what work is still required around it.

Effective cybersecurity rarely comes from finding the easiest answer. It comes from understanding the real problem and applying the right combination of people, process, technology, and governance.

What Should Organizations Do Now?

  1. Start with risk. Identify what could materially affect the organization’s people, data, customers, operations, reputation, and business objectives.
  2. Understand business priorities. Know where the organization is going before deciding which cybersecurity capabilities it needs.
  3. Develop a cybersecurity strategy. Connect near-term initiatives and longer-term capabilities to business objectives and risk.
  4. Build the operating model. Define ownership, processes, controls, monitoring, reporting, escalation, and improvement.
  5. Use compliance as structure, not the finish line. Let frameworks strengthen the program without allowing the audit to become the definition of security.
  6. Choose technology intentionally. Understand the process and outcome the tool is supposed to support before assuming technology will solve the problem.
  7. Invest in people change management. Train, coach, communicate expectations, assign accountability, and correct problems when they occur.
  8. Continuously reassess. Business conditions, technology, threats, regulations, people, and risk all change. The cybersecurity program needs to change with them.

Frequently Asked Questions

Why Is Cybersecurity Considered Both Art and Science?

Cybersecurity includes technical standards and established practices, but organizations still need judgment to determine how those practices should be applied based on risk, business objectives, technology, people, regulations, and available resources.

What Is the Main Purpose of Cybersecurity?

The core purpose of cybersecurity is to manage and reduce risk to people, data, systems, operations, customers, and the organization while enabling the business to achieve its objectives.

Can Cybersecurity Eliminate All Risk?

No. Organizations accept some level of risk simply by operating. Cybersecurity helps identify, assess, mitigate, monitor, communicate, and make informed decisions about that risk.

Is Compliance the Same as Cybersecurity?

No. Compliance can contribute significantly to cybersecurity when requirements are implemented effectively, but an audit or certification represents assurance over a defined scope and should not replace broader risk management.

Why Isn’t Buying Security Tools Enough?

Security technology still needs appropriate implementation, configuration, ownership, monitoring, maintenance, processes, and human oversight. A tool can support a security capability but does not automatically create one.

Why Should Cybersecurity Strategy Align With Business Strategy?

Business decisions change cyber risk. Understanding where the organization plans to grow, what markets it will enter, what customers it wants to serve, and what technology it plans to adopt helps security leaders build capabilities that enable those objectives safely.

What Role Do People Play in Cybersecurity?

People operate controls, make decisions, use technology, respond to incidents, complete training, manage vendors, and own business processes. Effective cybersecurity therefore requires clear responsibilities, education, communication, accountability, and change management.

About This Episode

This article is based on Episode 0 of the Hotman Group podcast, Cybersecurity Is as Much Art as Science, hosted by Cheri Hotman, Managing Partner of Hotman Group.

In this welcome episode, Cheri explains the philosophy behind the podcast: cybersecurity exists to mitigate risk, every organization is different, business context matters, technology is only part of the answer, compliance is not the finish line, and practitioners need to combine technical expertise with strategy, judgment, communication, and people change management.

Future conversations build on that foundation through practical, real-world discussions about cybersecurity, Cyber GRC, risk, compliance, tools, business strategy, and the challenges practitioners encounter while trying to protect organizations.

When to Bring in Hotman Group

Organizations often bring in Hotman Group when cybersecurity activity exists but leadership needs help turning that activity into a coherent, risk-based program. HG can help when:

  • Cybersecurity priorities are driven primarily by audits, customer requests, or whichever problem is most urgent that week.
  • The organization has invested in security tools but lacks the processes, ownership, monitoring, or governance needed to use them effectively.
  • Leadership receives technical findings but does not have a clear picture of business risk.
  • The company is growing, entering new markets, pursuing new customers, or changing technology and needs cybersecurity strategy aligned to those goals.
  • Compliance has become the definition of security rather than one component of a broader cyber program.
  • Roles, responsibilities, accountability, and people processes are limiting otherwise strong technical security work.
  • The organization needs an experienced outside perspective on how to prioritize limited cybersecurity time, budget, and resources.

Hotman Group helps organizations build cybersecurity and Cyber GRC programs around real business risk, practical constraints, clear ownership, effective governance, and the outcomes the business is actually trying to achieve.

Talk With Hotman Group About Your Cybersecurity Program

About Hotman Group

Hotman Group is a cybersecurity and Cyber GRC professional-services firm that helps organizations diagnose, design, build, remediate, implement, operate and mature cybersecurity programs. HG provides hands-on vCISO and vGRC leadership, supports multi-framework environments, and helps organizations select and implement GRC technology while connecting cybersecurity decisions to business risk and strategy.

Hotman Group works with organizations to move beyond disconnected tools, audit-driven activity, and one-size-fits-all security programs by aligning cybersecurity with the organization’s actual risk, operating environment, and business objectives.

Because there is no universal easy button, strong cybersecurity requires the right combination of people, process, technology, governance, judgment, and continuous improvement.

Talk With Hotman Group