What “Reasonable” Cybersecurity Looks Like: A More Defensible Approach to Risk

What “Reasonable” Cybersecurity Looks Like: A More Defensible Approach to Risk

What “Reasonable” Cybersecurity Looks Like: A More Defensible Approach to Risk

Over the past year, I have noticed a change in the questions executive teams are asking about cybersecurity. Leaders still want to know whether the organization is protected, but the conversation is increasingly extending to the decisions behind those protections. If an incident occurs, can leadership explain what risks were understood, why certain safeguards were chosen, and whether those decisions were reasonable?

For years, cybersecurity conversations focused primarily on tools and controls. Firewalls, endpoint protection, vulnerability scans, and patch cycles. Those remain essential. But boards, insurers, and regulators are now evaluating a broader issue.

They want to know whether leadership exercised reasonable judgment.

Why the Governance Conversation Is Changing

Cybersecurity expectations have expanded beyond whether technical controls are in place. Boards, insurers, and regulators increasingly expect leadership to understand the organization’s material risks, demonstrate how priorities are being set, and explain why particular safeguards are reasonable.

For smaller organizations, that creates a practical challenge. Security resources are finite, while the number of risks competing for attention continues to grow. Leadership cannot address every exposure at once, which makes the process behind those decisions increasingly important.

Strong governance creates that structure. It helps an organization document what was known, which risks were prioritized, why certain safeguards were selected, and where additional improvement is still planned.

What DoCRA Changes in the Conversation

The Duty of Care Risk Analysis Standard (DoCRA) provides a framework for evaluating whether cybersecurity risk and the safeguards used to address it are reasonable. Its principles ask organizations to consider:

  1. The interests of all parties that could be harmed by the risk
  2. Whether risk has been reduced to a level that would not require remedy
  3. Whether the safeguards themselves are proportionate to the risk they are intended to address


That creates a useful leadership discipline: cybersecurity decisions should account for potential harm while remaining reasonable in the context of the organization and its mission.

The practical value for leadership is defensibility. Boards need more than technical dashboards. They need clarity on exposure, potential impact, and why the safeguards in place are considered reasonable.

The Visibility Problem I Continue to See

One of the most consistent gaps I encounter is asset visibility, with 76% of breaches involving unknown or unmanaged assets

The operational problem is straightforward. Leadership cannot evaluate risk accurately when the organization cannot confidently identify the assets, software, vulnerabilities, and access points contributing to that risk.

Defensibility begins with knowing what exists.

What This Means for Regulated SMB Leaders

Across healthcare, financial services, regulated supply chains, and other risk-sensitive environments, leadership teams are asking more direct questions:

What assets are externally visible?

Which systems process high-impact data?

How are those systems prioritized for protection?

Can leadership demonstrate reasonable safeguards?

These are governance questions, not purely technical ones.

Organizations that treat cybersecurity as a silo struggle to answer them. Organizations that align asset visibility, risk analysis, and executive communication are better positioned.

What Defensible Cyber Risk Management Looks Like

A defensible cybersecurity program gives leadership the ability to clearly articulate:

  1. What exposure exists today
  2. How risk is prioritized
  3. Why current safeguards are reasonable
  4. Where improvement is already planned

DoCRA offers a way to evaluate cybersecurity decisions through the lens of reasonable and proportionate risk management.

In my conversations with regulated SMB leaders, the shift is already underway. Compliance checklists are no longer enough. Insurance underwriting is tightening. Regulatory scrutiny is increasing.

The organizations that will lead are not necessarily those with the largest security stacks. They are the ones who understand their exposure, evaluate it honestly, and make defensible decisions to reduce it.

For leadership teams, the implication is clear. Cyber risk belongs in the broader governance conversation because decisions about security affect operations, customers, regulators, insurers, and other stakeholders. The ability to explain those decisions may become just as important as documenting the controls themselves.

A Practical Starting Point for Defensible Cyber Conversations

Leaders do not need to resolve every cybersecurity question in one meeting. A useful starting point is making sure the organization can clearly answer a few fundamental questions:


What are the most significant cyber risks to the organization and its stakeholders?

What safeguards are currently reducing those risks?

Why are those safeguards considered reasonable?

What known gaps remain, and what is the plan for addressing them?


Those questions foster stronger conversations between technical teams and leadership. They also help move cybersecurity governance away from assumptions and toward decisions that can be explained, documented, and defended.

Powered By GrowthZone