Skip to content

Of monkeys, pedestals and cybersecurity

24 October 20253 min read
Guest Insights
Of monkeys, pedestals and cybersecurity

Focus your energy on the controls that actually stop cyber attacks. Perfect policies, risk reports, and maturity frameworks might look good, but they don’t block threats. Get your defences solid first — then build your pedestals.

Introduction

There’s a beautiful metaphor about how human nature often guides us to do things in order of ease, rather than in order of priority. It goes like this: Imagine your team is tasked with teaching a monkey to juggle flaming torches while standing atop a 12-foot pedestal. What do you do first? The right answer lies in assessing critical path and risk. 99.99% of the risk to this project’s success lies in training the monkey. Building a pedestal is easy; we’ve been doing it for millennia. So, logically, we should spend all our effort on the monkey, and only worry about the pedestal once we know the monkey is making clear progress. But that’s not what usually happens, especially in corporate settings. Instead, we build the pedestal first.

Why?

  • Because it’s a clear deliverable.

It shows progress: “Yeah boss, we’re working on the monkey, but check out this awesome pedestal.”

  • Because even if the project fails, we can still say we achieved something: “Shame about the monkey, but hats off to the pedestal team.”

  • This thinking is flawed. If the monkey fails, the pedestal is pointless. (Unless you’re a pedestal manufacturer, in which case... carry on.)

Applying the metaphor to cybersecurity

In conversations with CISOs, IT directors, customers, suppliers and peers, I frequently see this metaphor play out in cyber security. Too often, we place far more emphasis on governance, reporting, and risk documentation, while neglecting the hands-on work that truly protects our organisations. Let me explain. Cyber security, at its core, is about preventing unauthorised access, damage, or disruption to digital assets. Success is when attackers get nothing. Failure is when our business is wiped out by a breach. The difference lies in whether our defences are effective.


Monkeys (Hard Problems)


Pedestals (Less Hard Problems)


Ensuring 100% EDR coverage and robust configuration

Remediating vulnerabilities with a constant downward trend

Securing the SDLC to minimise software risk

Improving email gateway threat blocking


Arranging a third-party security maturity assessment

Completing a risk register for audit

Producing and distributing security policies

Creating risk reports for the board

The right-hand column isn’t unimportant or effortless. But these are well-trodden paths. Writing a security policy? Tens of thousands have done it. Achieving near-zero vulnerabilities at scale? That’s rare. That’s meaningful. And it directly impacts breach prevention. In cyber, we’re facing purely technical threats. Threat actors simply don’t care about your risk register, policies, or maturity score. Somewhat ironically, they might well steal or encrypt those documents, but they certainly won’t be deterred by them. So don’t be tempted to spend all your energy on the right-hand side. Particularly the energy of your most senior and experienced cyber security people – which is so often the case in my personal experience.

    “You can start improving these controls right now. No matter what tool or technology you use today...”

    Addressing the counterarguments

    “The metaphor doesn’t suggest ignoring the pedestal altogether. It suggests not starting there when the monkey is still accidentally setting itself on fire.”