Technology
From Detection to Decision
Cybersecurity is shifting from detection to judgement: behavioural analysis and AI-assisted reasoning help turn security signals into better decisions.
6 Min
INSIGHT
FIELD NOTE
I
Technology
6 Min
estimated reading
2026
published
Over the years, I have observed that most enterprise problems follow a familiar pattern. The technology is rarely the constraint, the decision is.
A dashboard may contain all the information needed. A report may contain every significant metric. An alert may correctly indicate that something unusual has happened. Yet the outcome still depends on a simple question:
What should we do now?
Cybersecurity is no different. In fact, modern cybersecurity may be one of the clearest examples of this challenge.
The Alert Paradox
Most organisations are not suffering from a lack of data. If anything, they are overwhelmed by it. Security platforms continuously generate logs, events, alerts, anomalies, warnings, recommendations, and threat indicators.
Every day, systems become better at observing. But observing is not the same as understanding, and understanding is not the same as deciding.
A security team may receive hundreds or even thousands of alerts. The challenge is rarely discovering that something happened. The challenge is determining which events matter, which are related, which can be ignored, and which require immediate action.
The problem is not visibility. The problem is judgement.
Looking Beyond the Event
Traditional detection approaches often focus on individual signals: a suspicious request, a failed authentication attempt, an unfamiliar access pattern. Viewed independently, each event may appear relatively harmless.
The difficulty emerges when behaviour unfolds over time. A system does not attack itself in a single action, and neither does an attacker — the real story normally exists in the sequence.
Small events accumulate; patterns emerge. context develops. What appears insignificant in isolation becomes meaningful when viewed as part of a larger behavioural narrative.
This observation became the starting point for an innovation journey that eventually resulted in LTMP078, an approach focused on behavioural threat detection, evidence-based security analysis, attack prioritisation, and intelligent recommendations.
Security as a Systems Problem
One of the recurring themes in my writing is that systems matter more than individual components. An anthill does not function because of a single ant. A city does not function because of a single building. An enterprise does not function because of a single application. The same is true for cybersecurity.
Attackers rarely exploit a single isolated weakness. Instead, they exploit interactions, sequences, feedback loops, and unexpected combinations of events.
Security therefore becomes a systems problem rather than a technology problem. The goal is not simply detecting an event — it is understanding behaviour.
From Evidence to Understanding
An experienced investigator does not start with a conclusion. They start with evidence, and the same principle should apply to intelligent systems.
When an alert is generated, the most valuable question is often not:
Is this malicious?
Instead, it is:
What evidence supports this assessment?
Trust grows when reasoning becomes visible, and confidence increases when conclusions can be explained. People make better decisions when they understand not only the recommendation but the thinking behind it.
This is one of the ideas that inspired the work behind LTMP078.
Rather than simply generating another alert, intelligent systems should help organise evidence, explain context, highlight behavioural indicators, and support decision-making.
The Rise of Decision Intelligence
Much has been written about artificial intelligence in recent years. Most conversations focus on prediction, automation, generation, and reasoning. Yet perhaps the more interesting question is:
How does AI help people make better decisions?
This question extends far beyond cybersecurity. It applies equally to enterprise architecture, business transformation, operations, governance, and leadership.
In every case, the challenge is remarkably similar: too much information, too little attention, limited time, and competing priorities.
The organisations that will create the greatest value from AI are unlikely to be those that simply automate tasks. They will be those that improve the quality of decisions.
Technology and Judgement
Technology has become exceptionally good at finding signals. It is becoming increasingly good at finding patterns, and soon it will become very effective at recommending actions. Yet judgement remains something different — it requires context, experience, trade-offs, and awareness of consequences.
The future of cybersecurity will not belong entirely to machines or entirely to humans. It will belong to systems where each complements the other: machines providing visibility at scales humans cannot match, and humans providing judgement where context matters most. The most effective solutions will be those that combine both.
A Closing Thought
Every generation of technology promises greater certainty. Every generation of leadership eventually discovers that certainty is rarely the goal — the real objective is better decision-making under uncertainty. That is true of enterprise architecture, leadership, and AI economics, and it is certainly true of cybersecurity.
Technology can detect. Technology can analyse. Technology can recommend. But ultimately, the value of any intelligent system lies in helping people make better decisions than they could have made alone.
“
Cybersecurity is shifting from detection to judgement: behavioural analysis and AI-assisted reasoning help turn security signals into better decisions.
Article summary
CONTINUE EXPLORING
More writing on technology, AI economics, systems thinking, leadership, and mentoring.