Introduction
Every significant cybersecurity incident eventually arrives at the same point: someone must make a decision with incomplete information. Whether confronting ransomware, approving the migration of critical systems to the cloud, responding to a software supply chain compromise, or determining whether operations can safely continue during disruption, the decisive factor is rarely the absence of technology. More often, it is the quality of human judgment exercised under uncertainty.
Figure 1: Cybersecurity Judgment Integrates Technology, Risk, and Mission
Over the past two decades, organizations have invested heavily in cybersecurity frameworks, compliance programs, technical controls, and automated defenses. These investments have strengthened . . .
From the Fall 2026 Issue
Cybersecurity as Judgement
Beyond Compliance: Cybersecurity as a Profession of Judgment
Henry J. Sienkiewicz
Adjunct Faculty | Georgetown and George Washington Universities | Former CIO, Defense Information Systems Agency (DISA)
Leave a Comment