← Back to all posts

Founder Notes

Where Does Your Risk Strategy Actually Come From?

August 17, 2026 · Jesse McKenna

A young girl asks her father, working late at his laptop, "Daddy, where did your risk strategy come from?"

Ask a room of executives where their risk strategy came from, and watch the answer wobble. Someone mentions last year's penetration test. Someone else brings up "the risk assessment" - said with the confidence of a recent document, though it's usually 18 months old. A third person says "we did a workshop on this," as if that settles the question. What almost nobody says is: here's the model we used, here's the data that fed it, here's how we weighted this risk against that one.

That's because there's usually no model at all. Most risk strategy is an opinion, assembled after the fact from whatever real data happens to be sitting around. Not because anyone's lazy or dishonest about it. Because the honest version of "where does this come from" is uncomfortable, and most organizations have built enough scaffolding around the process that nobody has to say it out loud.

The scraps get treated like a system

A penetration test tells you what one tester found exploitable, in one scope, on one day. A risk assessment from 18 months ago describes a company that has since changed products, headcount, vendors, and geography. An internal audit finding tells you whether a specific control existed on the day someone checked. None of these are wrong on their own terms. Each one is a legitimate, narrow measurement of something real.

The mistake is stacking three unrelated point-in-time measurements, none of which were ever looking at the same thing at the same moment, and calling the result "our risk strategy." It's the equivalent of diagnosing a patient from three specialist reports that were written months apart and never cross-referenced. Each report might be accurate. The composite picture nobody actually built is where the real diagnosis was supposed to come from.

The opinion comes first, the data gets recruited after

Here's the part that's worth being direct about: in most organizations, the sequence runs backwards. The highest-paid person in the room states a risk priority with real conviction - ransomware, a specific vendor, whatever made headlines recently in the peer group - and then the pentest, the last assessment, and the audit findings get quoted selectively to support it. The data didn't produce the conclusion. The conclusion went looking for data to stand behind it.

This isn't a character flaw. Building an actual systematic model of risk across an entire organization is slow and expensive the traditional way - stakeholder interviews, workshops, scheduling time with a dozen department heads who all have other jobs. Faster to let the person with the most authority assert a view and have everyone else nod along with a supporting citation. You can usually tell when this has happened by watching what changes when the CISO or CRO changes. If the stated risk priorities shift substantially with new leadership, and nothing about the business itself changed, the strategy was mostly opinion the whole time, dressed with data selectively.

The "data-driven" version has the same problem

It's tempting to think a GRC platform or a formal risk register solves this, since it looks more rigorous. Usually it doesn't. Most heat maps are built from control owners self-rating their own areas on a 1-to-5 scale, rolled up into a quarterly view. That's more structure than a gut call in a meeting, but it's still opinion - just distributed across more people instead of concentrated in one. Nobody computed anything. Everybody estimated, and the tool made the estimates look official.

This is why enforcement actions and post-incident reviews so often reveal risks that "everyone kind of knew about." They weren't hidden. They just never made it into a strategy, because nothing in the process was actually designed to surface and weigh them against everything else competing for the same budget and attention.

What an actual answer requires

A defensible answer to "where does this come from" requires a systematic model across the full risk surface, built the same way every time, re-run when something material changes - not stitched together from whichever artifacts happen to be lying around plus whoever has the most seniority in the room. That's a different kind of process than most organizations have today, and it's the reason risk strategy keeps ending up as a restatement of the last thing that scared someone, rather than a picture of where the actual exposure sits.

Next time someone states a risk priority with total confidence, ask the boring question: where did that come from? If the honest answer traces back to an opinion wearing a couple of old reports as camouflage, that's worth knowing before it costs you the budget, the headcount, or the board's attention that a bigger, quieter risk actually needed.

Jesse McKenna has over 20 years of experience in fraud detection, financial crime, and enterprise risk - building detection systems at PayPal and eBay, leading threat research at Silver Tail Systems and RSA, and building SAR prediction models at Refine Intelligence. He is the Founder and CEO of VeloRisk, a risk strategy platform for regulated industries.
← Back to all posts