← Back to all posts

Founder Notes

The Diagnostic Your Risk Program Is Missing

September 21, 2026 · Jesse McKenna

A mechanic named Mike leans over a car's hood listening through a stethoscope while a skeptical customer stands with arms crossed. Behind them, a dust- and cobweb-covered diagnostic computer sits unused on a cart. Speech bubble: "Sounds like the transmission. Or possibly gremlins. Let's replace everything and see what sticks."

When was the last time you ran a diagnostic on your organization? Not a review. Not a workshop. Not a spreadsheet someone updates once a year and calls a risk assessment. An actual diagnostic - something that tells you, specifically, what's wrong right now, not what was wrong the last time someone looked.

Most organizations can't answer that question, because they've never had one. What they have is a document that describes their risk posture in the past tense, and they treat it like a diagnosis anyway.

The difference between a diagnostic and a guess

A diagnostic and a checklist look similar from a distance. Both produce a document. Both involve someone asking questions and writing down answers. The difference is what the answer is built from. A checklist tells you whether a control exists. A diagnostic tells you whether it's working, specifically, for your organization, right now - and if it isn't, exactly where it's failing. One is a survey. The other is a measurement.

Early days at Silver Tail

I learned the difference the hard way, years before "risk assessment" was part of my job description. In the early days at Silver Tail Systems, when something broke in a customer's web application, "troubleshooting" meant getting on a plane. I'd sit on-site with their ops team, staring at logs in real time, forming a theory about what was going wrong, testing it, and revising when I was wrong - which was often. It worked, eventually. It also meant the answer lived entirely in the heads of whoever happened to be in the room, and it took as long as it took.

We built a diagnostic tool to fix exactly that. Instead of a customer's team staring at raw session data and guessing, the tool told them, directly: this pattern, this session, this is what's wrong. Not "here's the data, go figure it out." Not "based on similar cases, it's probably X." A specific answer, tied to their specific system, available the moment they needed it instead of after however many days of guesswork it used to take.

That tool became core to how Silver Tail's product worked. I ran into a similar pattern years later, just relabeled: a risk assessment run as a workshop is still onsite troubleshooting with no measurement tool - a room full of people forming a theory and calling it a finding. Nobody would call that a measurement. A risk assessment gets away with it anyway.

Why most risk assessments skip the diagnostic step

A workshop-and-interview risk assessment is the on-site-guesswork model, just applied to risk instead of uptime. Someone asks questions, someone else answers from memory and instinct, and the result gets written up as findings. It's not wrong, exactly - the same way our early troubleshooting eventually got the right answer. But it's slow, it depends entirely on who's in the room, and it produces an opinion dressed up as a measurement. Nobody would accept that as a diagnostic for a failing application. Most organizations accept it without question for risk.

Signs you're operating without a real diagnostic:

A diagnostic is where the program starts, not where it ends

The diagnostic tool at Silver Tail was never the whole point. Knowing exactly what was wrong mattered because it let customers actually fix it, fast, instead of staying stuck in the troubleshooting loop indefinitely. A diagnostic that just sits there, accurate and ignored, isn't worth much more than the guesswork it replaced.

Same logic applies to risk. A real diagnostic gets you a precise, current read of what's actually wrong in your organization, not a generic checklist and not a guess. What you build on top of that read, continuously, as your organization keeps changing, is the program. The diagnostic is where it starts. It was never supposed to be where it ends.

Jesse McKenna has over 20 years of experience in fraud detection, financial crime, and enterprise risk - building detection systems at PayPal and eBay, leading threat research at Silver Tail Systems and RSA, and building SAR prediction models at Refine Intelligence. He is the Founder and CEO of VeloRisk, a risk strategy platform for regulated industries.
← Back to all posts