My wife formerly worked for an organ donor network, where motorcyclists who rode without helmets were sometimes referred to, solemnly, as “future donors.” It wasn’t a joke or an attempt to be insensitive. The people working there saw the consequences of serious motorcycle accidents firsthand and wished (simply) that no one would ride them.
My family has experienced those consequences too. My cousin-in-law died a couple of years ago in a motorcycle accident that involved no one else. He was wearing a helmet and slid on slightly damp ground.
Most of us understand that riding a motorcycle comes with risk. However, knowing that doesn’t stop people from riding them.
I’ve been thinking about risk perception a lot lately… I see something similar in cybersecurity quite often.
Most people understand that cyberattacks are a serious problem. We regularly hear about ransomware, stolen passwords, compromised email accounts and data breaches, etc. We know businesses lose money and struggle to keep doors open after an attack.
Even knowing all of this doesn’t always translate into believing it could happen to our own business.
Psychologists have studied the way people perceive personal risk for decades.
One explanation is optimism bias, our tendency to believe that we are less likely than other people to experience negative events.
Psychologist Neil Weinstein explored this phenomenon in a 1984 paper appropriately titled Why It Won’t Happen to Me: Perceptions of Risk Factors and Susceptibility. Across four studies, Weinstein found that people could be excessively optimistic when evaluating their own susceptibility to different risks.
That distinction matters. A person can fully understand that something is dangerous while still underestimating the chance that it will affect them personally.
Researchers have since found evidence that optimism bias can influence cybersecurity behavior as well. A 2024 study published in Computers & Security examined non-IT employees in U.S. organizations and found that optimism bias contributed to risky cybersecurity behavior and was negatively associated with attitudes toward cybersecurity.
Our challenge isn’t always convincing people that cybercrime exists. Most people already know that.
It’s often harder to help people recognize their own place in the statistics.
There is another psychological concept that may help explain our reaction to cybersecurity warnings.
It’s called habituation. When we’re repeatedly exposed to the same stimulus, our response to it can decrease over time.
Researchers have observed this with computer security warnings. In one study, researchers used eye tracking to measure how people responded when they repeatedly encountered security warnings. Participants began paying less attention to warnings after only a few exposures.
A hospital experiences a cyberattack. Customer records are stolen from a major company. A school district shuts down systems after detecting suspicious activity. Another company pays millions following a ransomware attack.
We see these stories in the news a lot, so we keep scrolling. Cyberattacks feel less like individual warnings and more like part of the normal news cycle.
I recently traveled to London for a family vacation. While I was there, I picked up a local newspaper (they still exist) and found myself reading about a cyberattack.
I had traveled thousands of miles from Cincinnati and cybersecurity was still in the news.
I learned that Transport for London (TfL) in London had already experienced a significant cyber incident in 2024. Two teenagers were able to successfully gain access to the TfL network.
According to TfL, certain customer information was accessed during the attack, including names and contact information. According to BBC, about 10 million people had their private data stolen.
When I came home from London, my family received a letter informing us that our adoption agency had experienced a data breach and our personal information was at risk.
This wasn’t a large organization I’d read about while sitting in another country. It was an organization my family trusted (back in 2019) with personal information to adopt our son. Seven years later after giving our personal information, our data is at risk.
Unfortunately, I see these attacks far too often.
Recently, a small business contacted 4BIS after being hacked. Within days, another small company reached out after experiencing a cyber incident.
At some point you have to wonder how close cybercrime needs to get before we stop thinking of it as something that primarily happens to other people.
It’s understandable why a business owner might think that way. If you’re running a 30-person company in Cincinnati, why would an international cybercriminal spend time targeting you when companies with billions of dollars exist?
The problem is that this isn’t necessarily how modern cybercriminals think.
Attackers use phishing campaigns, automated scanning, stolen credentials and other techniques to look for opportunities across many organizations to send out messages- it only takes one small click for a ransomware event to occur.
Data also shows that smaller businesses aren’t escaping the problem. Being small doesn’t provide the protection many business owners assume it does.
A business can go years without experiencing a major cyberattack. During that time, employees use the same systems, follow the same processes and rely on the same security protections.
We’ve always done it this way. We’ve never been hacked. Why spend money changing something that hasn’t caused a problem?
Someone can ride a motorcycle for 20 years without having an accident. Those 20 accident-free years don’t make the next ride inherently safe. They tell us what happened in the past, not what will happen tomorrow.
A business’s history works the same way. Years without a known cyber incident don’t necessarily tell us whether the company’s current defenses are appropriate for the threats it faces today.
Past luck isn’t a cybersecurity control.
Business leaders need to understand what an attack would look like in the context of their own operations.
Which systems are necessary to keep the business running? What sensitive information does the company possess? Who has access to it? What would happen if employees couldn’t access email, files or critical applications for several days?
Businesses should also know which protections are currently reducing those risks. That includes understanding how quickly suspicious activity would be detected, how an incident would be contained and whether backups can be used to restore operations.
Cost matters too. If an important system became unavailable tomorrow morning, what would one day of downtime cost? What about three days or a week?
Those questions create a much more useful conversation than simply deciding whether cybersecurity feels important. They also help leadership determine how much risk the organization is willing to accept.
Every business accepts some amount of risk. Companies hire people, sign contracts, extend credit, adopt technology and make investments without knowing exactly what the outcome will be. The goal isn’t to eliminate uncertainty. It’s to understand the potential consequences well enough to make informed decisions.
Cybersecurity strategies should be approached the same way.
The same principle applies to cybersecurity. Multi-factor authentication can significantly improve account security, but accounts can still be compromised. Endpoint detection and response can identify suspicious activity, but it can’t guarantee malicious activity will never occur. Backups won’t prevent an attack, but they can make an enormous difference in a company’s ability to recover.
This is why effective cybersecurity relies on layers rather than a single product or precaution.
Businesses need protections that reduce the likelihood of an attack succeeding, ways to detect suspicious activity when something does happen and a plan for containing the damage and recovering afterward.
The appropriate combination will look different for every organization because the risks aren’t identical.
It’s impossible to predict whether a particular business will experience a serious cyberattack tomorrow, next month or five years from now.
What we can do is evaluate the risk based on what we know today.
We know criminals target businesses of different sizes. We know stolen credentials, phishing, ransomware and other threats continue to cause real financial and operational damage. We also know that our own perception of risk isn’t always reliable.
Psychology gives us some insight into why. Optimism bias can make a known danger feel less likely to affect us personally. Repeated exposure to warnings can make us pay less attention to them. Years without an incident can create a sense of security that may or may not reflect the company’s actual defenses.
None of that means business owners should assume disaster is around the corner. It means they should have enough information to understand the risk they’re accepting.
Instead of asking, “What are the chances anyone will actually hack us?” there is a more useful question:
If our business is the one that gets attacked tomorrow, do we understand our risk and are we prepared to respond?
That’s a question you can actually do something about.
4BIS Cyber Security helps Greater Cincinnati businesses understand their cybersecurity risk, identify weaknesses and determine which protections make sense for their operations. A cybersecurity risk assessment can provide a clearer picture of where your organization stands so that security decisions are based on evidence rather than assumptions.