

Why Cybersecurity Decision-Making Needs More Judgment Than Data
Security teams have never had more visibility into their environments. Modern security platforms generate thousands of alerts every day, artificial intelligence (AI) can identify suspicious activity in seconds, and organisations collect more telemetry than ever before.
Yet attackers continue to outpace defenders.
According to LevelBlue’s Q2 2026 TTP Briefing, business email compromise (BEC) accounted for 45 percent of incidents investigated during the quarter. Phishing and social engineering remained the most common initial attack method, responsible for 65 percent of intrusions. Threat actors are also shortening the time between initial access and data exfiltration, giving defenders fewer opportunities to detect and stop an attack.
The challenge is no longer collecting information. It is making better cybersecurity decisions with the information organisations already have.
At a Glance
- Organisations collect more security data than ever before.
- Business email compromise represented 45 percent of incidents investigated by LevelBlue in Q2 2026.
- Phishing and social engineering accounted for 65 percent of initial intrusion methods.
- AI can identify patterns quickly, but leadership must decide what action to take.
- Better questions often produce better security outcomes than more dashboards.
Why This Matters
Many organisations respond to new cyber risks by purchasing additional security tools or subscribing to more threat intelligence feeds. While greater visibility has value, it does not automatically improve security outcomes.
As attackers move faster, security leaders need confidence to distinguish between alerts that require immediate action and those that pose little business risk. That requires judgment, experience, and business context rather than simply more information.
More Data Does Not Always Mean Better Security
For years, organisations have believed that better security comes from collecting more information. New dashboards, additional monitoring platforms, and extra threat feeds have become common investments.
However, information alone rarely creates clarity.
Jo Salisbury, Regional Director Growth and Performance APAC at LevelBlue, said:
“Most organisations already have access to an enormous amount of security data. The challenge isn’t collecting more information. It’s understanding which information matters and knowing what action to take.”
Security teams can monitor endpoints, cloud environments, identities, and networks in real time. Executive teams receive reports covering vulnerabilities, threat activity, and risk scores. AI can rapidly detect anomalies and recommend next steps.
However, technology can only explain what has happened. It cannot decide what the organisation should do next.
That decision still belongs to people.
Asking Better Questions Improves Cybersecurity Decision-Making
As attackers continue reducing the time between compromise and business impact, organisations cannot investigate every alert with equal priority.
Instead, security leaders need to focus on the questions that influence business decisions.
Rather than asking:
- How many vulnerabilities exist?
Ask:
- Which vulnerabilities could realistically disrupt critical business operations?
Rather than asking:
- How many attacks were blocked?
Ask:
- Which attacks almost succeeded, and what do they reveal about our weaknesses?
Rather than asking:
- How many alerts were generated?
Ask:
- Which alerts actually changed a security decision?
According to Salisbury:
“These questions move cybersecurity beyond technical reporting and towards business decision-making.
“The organisations seeing the strongest outcomes aren’t necessarily the ones collecting the most telemetry. They’re the ones using the information they already have to make faster, more confident decisions.”
Maximising Existing Security Investments
Many organisations already own sophisticated cybersecurity technologies.
The greater opportunity often lies in improving how those capabilities are used rather than purchasing additional tools.
Security leaders should ensure that insights generated by existing platforms directly support operational improvements, investment priorities, and business risk decisions.
Salisbury said:
“Meaningful security metrics should support decisions, not simply report activity. If a dashboard doesn’t influence risk priorities, investment decisions, or operational improvements, it’s providing information without delivering value.”
AI Still Requires Human Judgment
Artificial intelligence is transforming security operations by analysing vast amounts of information in seconds. It can identify patterns, detect anomalies, and recommend actions much faster than human analysts.
However, AI cannot determine an organisation’s appetite for risk.
It also cannot weigh commercial priorities or decide which trade-offs are acceptable for a particular business.
Those remain leadership decisions.
Salisbury said:
“AI is becoming incredibly effective at surfacing insights. However, organisations shouldn’t simply accept every recommendation at face value. They should ask whether the insight is relevant to their environment, whether it aligns with business priorities, and whether there’s sufficient evidence to support the decision.”
Building a Culture That Values Judgment
As cybersecurity threats continue evolving, organisations will need more than better technology.
They will need leaders who question assumptions, challenge recommendations, and translate technical insights into informed business decisions.
Companies that build long-term resilience are unlikely to be those with the largest technology stacks. Instead, they will be the organisations that consistently ask the right questions before making security decisions.
Salisbury concluded:
“The next time the conversation turns to another dashboard, another threat feed, or another security tool, it’s worth asking a simpler question first: What decision are we trying to make that we can’t make today? If that question can’t be answered, more data is unlikely to solve the problem.”
Conclusion
Cybersecurity is no longer limited by the amount of data organisations can collect. Modern security platforms already generate more information than most teams can fully analyse.
The real competitive advantage now lies in cybersecurity decision-making. Organisations that combine AI-driven insights with experienced leadership, business context, and thoughtful questioning will be better positioned to respond quickly and reduce risk in an increasingly fast-moving threat landscape.
Stay Informed With Cyber News Live
Cyber threats are constantly evolving, and staying informed is critical to protecting your organization.
Follow Cyber News Live for the latest cybersecurity news, threat intelligence, expert analysis, and practical guidance to help strengthen your cyber defenses.

