There is no such thing as cyber risk.
That is deliberately provocative, but the distinction matters. My thesis is not that cyber-related uncertainty is unreal or incapable of producing material consequences; it is that cyber is the wrong boundary at which to express, govern, own, and accept the resulting risk.
Risk arises because an organisation is pursuing an objective under uncertainty. It is something to understand, treat, and sometimes accept because the value of pursuing that objective can justify exposure (ideally within applicable legal, ethical, moral, and existing organisational constraints).
A cyber-attack against a computer does not, by itself, describe that. It describes one possible cause of changed system behaviour: a malicious action against one part of a system. Even saying that a computer may be compromised tells us only that the state, or trustworthiness, of that individual part could change, not what that change means for the system as a whole.
The real question is what happens to the system as a whole:
- Can it still perform the required function?
- Does production remain controllable?
- Can information still be trusted?
- Will a safety function operate when demanded?
- Can a critical decision still be made on a sound basis?
From a systems perspective, security, like safety, is an emergent property. It depends on how people, technology, information, processes, and other systems interact within and across that system. Such a part may be compromised without causing a material loss. A system can also produce an unacceptable outcome while every part appears to operate as designed, because the interactions, control actions, or assumptions are wrong for the circumstances. A cyber-attack is one possible cause of changed system behaviour. Depending on the architecture and context, it may be decisive, contributory, already contained, or irrelevant.
Stopping at cyber risk cuts analysis at the wrong boundary. It groups together unrelated events with entirely different consequences just because they somehow involve digital technology. Why are a ransomware incident, exfiltration of data, corruption of information, and manipulation of a safety-related controller overloaded into one risk category? These scenarios concern different objectives, functions, owners, tolerances, and consequences.
A valve may fail is no more a complete risk statement in safety than a computer may be compromised is in security.
At the same time, such a categorisation separates cyber, physical, human, and supply-chain scenarios that could cause a similar loss of function. That separation is dangerous. It fragments the analysis, obscures common dependencies and combined failure pathways, and encourages each discipline to understand only its part of what really is a shared problem. The organisation may then assess and accept a “cyber risk” without understanding whether the system as a whole can adequately perform its required function under credible adverse conditions.
Risks should be framed around objectives and obligations at stake, functions required to achieve them, systems that realise those functions, the performance those systems must sustain in their intended operational environment, and any unacceptable losses to be prevented.
Cyber-related threats, vulnerabilities, and attack paths belong within a causal analysis. Safety analysis similarly distinguishes hazards, failure modes, unsafe control actions, and accident scenarios from losses to which they may contribute. Security should inform the requirements, architecture, constraints, controls, treatments, and assurance used to address them. None of these should substitute for expressing the risk in terms that allow the organisation’s governance bodies to decide whether the resulting exposure is acceptable and who has authority to accept it.
Cyber tells us how the system may be affected. The risk tells us what the organisation stands to lose.
The risk belongs with the objective and the function, and should be owned by the person accountable for them, not by a security team removed from decision-making authority. As in safety, the specialist function remains essential in establishing constraints, providing independent challenge and assurance, and exercising delegated authority without becoming the owner of every risk it helps analyse.
If the risk statement ends with “a valve may fail”, “a cyber-attack is successful”, or “a digital system could be compromised”, the risk has not yet been adequately described.






