Risk and Resilience

The Padlock Is Not the Control

The padlock proves encryption, not legitimacy. Consumer-grade cyber advice given to executives stands in for a risk-appetite decision the board never made.

EraNorth Insights · 30 Aug 2026 · 14 min read

A signal that appears on the fraudulent site as readily as on the genuine one is not a test. It is a habit that feels like a test.

Business guidance still in circulation tells staff that a fraudulent website can be identified because it lacks the padlock icon or the letters https. That advice was weak when written and is now actively harmful.

The padlock attests to one thing: that traffic between the browser and the site is encrypted. It says nothing about who is at the other end, or what they will do with what is typed into the form. Certificates are issued automatically and at no cost, so a fraudulent site presents one as easily as a bank does [FACT CHECK REQUIRED — current proportions should be verified against published telemetry]. Teaching people to read the padlock as evidence of legitimacy installs a false negative into the control the enterprise depends on most: the judgement of the person about to enter a credential.

The reason to open a strategy article on so small a correction is that the correction is diagnostic. Advice of this kind is consumer-grade hygiene delivered to executives, standing in for a decision nobody has taken. The board-level question was never whether staff can spot a fake website. It is how much of this risk the enterprise has decided to carry, what it has spent to hold the exposure there, and whose name is on that decision.

The Strategic Context

Cyber risk is governed as a technology problem because it presents in technical vocabulary. Every material term in the decision is commercial. Which services must not stop, and for how long? Which data, if disclosed, would end a customer relationship, breach a contract or trigger a notification obligation? What is the enterprise willing to spend on prevention it will never observe working?

Those are ordinary board decisions in unfamiliar clothing. Delegated downward they are made anyway — by people optimising for uptime, delivery dates and budget, none of whom has authority to accept enterprise-level risk, and none of whom was asked.

The exposure is also growing from the revenue side. Every initiative that collects more customer data, adds a channel or connects another partner extends the surface. Data held is exposure held: an enterprise that treats customer records as an appreciating asset has taken a liability onto the same balance sheet without recording it. Which data may be collected is a growth decision; what may then be inferred and priced on is a separate question again [Related article: What You May Know About a Customer, and What You May Price On It].

A Checklist Is Not an Appetite

The standard advisory list — train the team, deploy anti-virus software, keep licences current, back up, avoid unsupported software, write a policy — is not wrong. It is a maturity floor and an organisation below it has no serious position at all.

Its harm is that completing it feels like deciding. There is no threshold anywhere in the list. It answers the question have we done things? and leaves untouched the question how much of this risk are we carrying, and is that the quantity we chose?

Two misreadings travel with it.

Training completion is reported as assurance. Attendance is an input. The measure that matters is whether the process survives a competent person being convincingly deceived, because eventually one will be. Controls that depend on nobody being fooled are not controls; they are hopes with a compliance record attached. The design response is to make deception insufficient on its own — payment-detail changes verified through an independently obtained channel, dual authorisation for irreversible transactions, authentication that resists interception — so a deceived person cannot complete the loss unaided.

The threat model is a decade out of date. The anti-virus framing describes intruders breaking in. Much consequential intrusion is now reported as the use of legitimate credentials, which no amount of malware scanning will see [FACT CHECK REQUIRED — current intrusion-vector proportions require verification against published reporting]. A board pack built on the older model shows green indicators for a defence nobody is attacking.

Reframing the Issue

If the board has not set a cyber risk appetite, the enterprise still has one. It is the residue of small operational choices: a budget line trimmed, an exception granted so a project could ship, a supplier accepted without review, a legacy system left running because replacing it belongs to someone else's programme. Each was taken locally, on local grounds, and none was framed as a risk decision. Together they set the enterprise's tolerance with precision, and nobody chose it.

A board-level appetite is expressed in consequence terms rather than technical ones. Which services may be unavailable, and for how long, before the damage becomes strategic rather than operational. What data loss is survivable. What the enterprise will spend to hold that line, and what it will decline to spend. Expressed that way the subject becomes governable by directors with no technical background — it is the translation, not the technology, that has been missing.

One second-order test exposes whether the appetite is real. If a funding request justified by the appetite statement is refused and the statement is not amended, the appetite has been changed by omission and the record no longer describes the enterprise. Requiring the two to move together is among the cheapest governance disciplines available.

What a Board-Level Treatment Requires

Recognised baselines exist. National cyber-security bodies and standards organisations publish control sets and maturity models, and choosing one, naming it and stating a target level converts an open-ended obligation into a measurable position with a date attached [FACT CHECK REQUIRED — the content, status and applicability of any specific baseline require verification with a qualified adviser; ERANORTH is not a security assessor and specifies no control framework here].

What the board should see on one page is short and requires no technical fluency:

  • the baseline selected, the target, the present position against it, and when each was last measured
  • appetite stated in consequence terms, with named services and tolerable outage for each
  • one accountable executive — an individual, not a committee, and not the person who operates the controls
  • assurance performed by someone independent of operations, reporting failures found, not only tests passed
  • an incident plan whose value is its decision rights: who may take a system offline, who authorises refusal to pay, who speaks, and when the board is told
  • third-party dependency registered by criticality, because much of the exposure now sits inside other organisations' systems
  • a review date, and what would trigger an earlier one

Every item is a governance artefact. None asks a director to understand a firewall rule.

The Padlock Failure Is a Class, Not an Anecdote

Generalise the correction, because the pattern is what makes it board business. The defect is a test whose passing condition is present in the bad case as well as the good one. It discriminates nothing, yet it returns a green result, so it is experienced as assurance and displaces the control that would have worked. A test that cannot fail is worse than no test, because no test at least leaves the anxiety intact.

The pattern recurs wherever assurance is designed by people who need the answer to be yes. It appears in fairness testing, where an audit that cannot detect an attribute reconstructed from other variables returns a clean result and is reported as evidence of fairness [Related article: Masking the Attribute Does Not Remove It].

One standing question disposes of the class: what result would this test produce if the thing we fear were actually present? If the honest answer is "the same result", the control is decorative and the board should stop counting it.

The same discipline applies to the assets. Who legally holds the domains, accounts and customer records — and who can revoke access — is a control question routinely mistaken for an operational one; an enterprise whose demand depends on accounts held at another organisation's discretion carries a concentration exposure beside its security exposure [Related article: Do You Own Your Route to the Customer, or Rent It?].

Privacy: The Advice That Names No Jurisdiction

Material circulated to executives frequently prescribes privacy obligations in confident detail — consent, disclosure, retention, age thresholds, user rights, breach handling — without naming a single legal system anywhere in it. That absence is the finding. Obligation is jurisdictional. A rule stated without a jurisdiction cannot be complied with, cannot be tested, and cannot be relied on in a dispute, because the reader cannot know which body of law is described or whether it applies to them.

Enterprises operating in Australia should expect their obligations to be shaped by the Privacy Act 1988 (Cth), the Australian Privacy Principles and the Notifiable Data Breaches scheme, alongside contractual commitments and sector-specific requirements [FACT CHECK REQUIRED — applicability thresholds, the substance of each obligation, notification timeframes and current amendments require verification]. ERANORTH is not a law firm or a financial adviser; nothing here is legal advice, and every statement in this section requires verification by a qualified practitioner before it is relied on.

The governable point survives the legal uncertainty and belongs to the executive rather than to counsel. Data the enterprise does not hold cannot be disclosed, cannot be lost and does not have to be defended. Retention is therefore a risk control before it is a compliance obligation, and one of the few that reduces cost at the same time — a decision the growth function makes, largely without noticing, every time it adds a field to a form.

Decision Framework

Board questionWhat a hygiene answer sounds likeWhat an appetite answer sounds likeEvidence to ask for
How exposed are we?"We have anti-virus, firewalls and high training completion.""Named critical services, each with a tolerable outage, tested against actual recovery times."The last recovery test, its date, and where it fell short
Are the controls working?"The annual checklist is complete.""They were tested by people who do not operate them, and these are the failures found."Independent assurance report and the exception register with ages
What do we carry from others?"Suppliers complete our questionnaire.""These suppliers can stop us trading; here is what we verified and what we knowingly accepted."Third-party register by criticality, with verification method
What data do we hold, and why?"We publish a privacy policy.""These categories, for these purposes, held for these periods — and this is what we stopped collecting."Retention schedule and evidence of deletion performed

The left column is not a failure of diligence; it is the honest output of a hygiene mindset. The middle column is what a risk-appetite decision sounds like when a board has taken one, and the right column is what stops it being an assertion.

From Strategy to Execution

Immediately, withdraw the padlock guidance and anything of its kind, replacing it with the process controls described above. Name the accountable executive. Take one critical service, state the outage the enterprise can tolerate, then test whether that is true. Most discover it is not, and discovering that deliberately is far cheaper than the alternative.

Over the medium term, build governance apparatus rather than more tooling. Name a baseline with a target and a date. Separate assurance from operations, so those testing the controls do not report to those running them. Register third parties by criticality and verify the critical ones rather than surveying them. Rehearse the incident decision rights with the executive team, not the technical team, because the hard calls in the first hours are commercial: whether to stop trading, whether to notify early, and what to say while the facts are incomplete.

The long-term position is commercial. Customers, insurers, acquirers and regulators all price cyber posture, and an enterprise that can describe its position in consequence terms, with evidence, negotiates better in every one of those rooms. The move that outlasts any control set is designing the business to hold less: fewer sensitive fields, shorter retention, fewer systems that can stop the enterprise trading. That is architecture, it is slow, and it is the only change that reduces exposure rather than defending it.

Signals to Monitor

The exception register growing faster than remediation closes it, and exceptions ageing past their expiry. Assurance performed by the same people who operate the controls. An incident plan with no exercise date in the last year. Supplier assurance consisting entirely of self-declaration. Incident reports describing credential misuse while the board pack still describes malware. Insurer renewal questions becoming more specific, coverage narrowing or premiums repricing, and enforcement activity in your sector — the earliest external signals that the market's view has moved. And the leading indicator that outranks the rest: the only cyber metric in the board pack is training completion.

Questions for the Leadership Team

  1. Which services can we not tolerate losing, for how long, and when did we last prove that recovery time rather than assume it?
  2. Where is our cyber risk appetite written down, who approved it, and what changed the last time we declined to fund it?
  3. Which third parties can stop us trading, and what did we verify independently rather than accept on their word?
  4. What data are we collecting that we could stop collecting, and who has authority to make that call?
  5. If a significant breach were confirmed this afternoon, who decides whether we keep trading, who speaks, and when do we hear about it?

Closing Perspective

The padlock endures because it offers certainty in a domain that does not supply any, and because an indicator is easier to teach than a judgement. That is why it should be distrusted. A control has an owner, a design, a test and a known failure mode; an icon in a browser has none of those, and neither does a completed checklist.

The board's task is not to find a reliable signal. It is to decide how much loss the enterprise is prepared to absorb, to fund that decision honestly, and to require evidence that the controls it bought would fail visibly if they were failing. An enterprise that does this has chosen its exposure. An enterprise that does not has one anyway — set this morning, by whoever last declined a budget request for reasons that had nothing to do with risk.


About EraNorth Insights
EraNorth Insights publishes practical analysis on strategy, projects, operations, transformation and decision intelligence for professional and organisational use. About EraNorth.