August 20, 2026
Why Pessimism Can Be A Strong Cybersecurity Approach
When it comes to keeping a company secure, it is vital to consider a highly non-technical element — human optimism — as both an asset and a…

By Steve Prentice
4 min read
When it comes to keeping a company secure, it is vital to consider a highly non-technical element — human optimism — as both an asset and a liability in the project. This is what our guests, Zoe Rose, CSIRT manager at Canon EMEA, and Chris Harris, AVP, Sales Engineering at Thales, discussed with me in the latest episode of the Thales Security Sessions Podcast, The Hidden Dangers Behind Out-of-the-Box Security.
By our very nature, we humans tend to believe in new solutions and shiny new tools to address the ills that have grown within our system. We also like to believe in ourselves. Even though this is a virtue, it can also be misleading. In cybersecurity, it shows up every time a new technology promises to fix what's broken. We want to believe the shiny new tool will solve the problems we've been wrestling with for years. We want to believe that we can make it work. But unchecked optimism becomes a liability. There is a powerful need for pessimism in the art of change and the introduction of new things into our world.
Why Pessimism Is Good
In the world of project management, for example, a wise project planner is the one who avoids the path of greatest optimism. Overpromising short delivery dates or excessively low-cost estimates can lead to difficult situations later. The belief that it will all come together if we give it that 'old college try' works well in movies, but not so well in the real world. That is why professional project managers take time to calculate and estimate every element of their project and factor in a modicum of pessimism. If your calculations suggest it will take 8 days to complete a project, it's better to quote 10 days or even 11 to account for unscheduled delays and problems. This is the essence of understanding the critical path and wisely stepping off that path.
Pessimism Is Not The Same Thing As Depression
Pessimism in projects is not the same as the emotional condition that a person can experience. It's more about realism. In recognizing that, despite our best efforts and experience, things can happen to a project. It's a well-learned condition based on many thousands of years of human project management, but especially in the last century of infrastructure projects. The reason that it is a fixture in official project management is that it must be taught. Most people believe they can achieve more than is possible, and, sadly, this leads to problems very quickly.
AI: Your Plastic Pal Who's Fun To Be With
We have seen it for decades in cybersecurity, and we are seeing it now with AI. The emotional side of ourselves takes over, hoping that this innovation will be all that we need. That hope grows into expectation, and this further mutates into conviction. This conviction stays with us even as the shiny new tool reveals its flaws and weaknesses.
As AI seduces the world with its mind-bending speed and versatility, the first thing many company owners and senior leaders did was to say, "Let's get this into our system so we can save money, make money, and increase our productivity." Many of them added to this a quick mass-firing of all those expensive employees who used to do the work that AI seemed fully capable of doing.
Certainly, AI is capable of many things, and, like personal computers, GPS, photocopiers, and the internet, it has become part of the evolution of work. Not a replacement, not even an addition — but an evolution. It is a tool with many strengths but also many weaknesses. Regardless, the rush to adopt AI and embed it in every facet of an organization's operations has revealed another variation on the dangers of optimism: the belief that the tool can "be all that" and have no latent problems. Only after the genie was freed from the bottle did people fully realize the dangers of hallucinations, prompt inaccuracy, the cost of tokens, and the fact that people are still needed on both ends of the transaction: to carefully set the stage for AI to do its work and then to verify its accuracy afterward.
The term "Your plastic pal who's fun to be with" was coined by science fiction humourist Douglas Adams, author of The Hitchhiker's Guide to the Galaxy, written long before AI became a thing. But in his book, the company that manufactured semi-sentient robots seemed to already recognize the difficulty in marketing a robot, because, quite simply, a robot is still a robot.
So, How Does All This Fit Into Cybersecurity?
Once again, humans and their human nature become the weak point. We are familiar with phishing, social engineering, and deepfake technologies that exploit people's trusting nature and goodwill to do their dirty work. But so, too, companies and their decision-makers tend to fall into an optimistic delusion when the latest shiny new security tool hits the market.
Whether it is AI-powered or not, there is often a fervent belief that this product, which comes at a high price and a powerful introduction from the sales rep, will be all that is needed to keep the company safe. As Chris Harris puts it: "Just because you've bought the market-leading shiny tool, it doesn't mean you're well protected." The danger is that even if the new security tool is very good at what it does, there will still be things that it does not do. For all the vulnerabilities that it detects, it might overlook a whole bunch of exposed ports, unpatched legacy systems, or other gaping security holes that were not part of its instruction base and therefore will not be part of the security solution.
Yet, the company stakeholders sleep at night, believing with all their hearts that the solution will take care of it all. That's dangerous, and that's why a more pessimistic, pragmatic mindset is essential. Zoe Rose makes the point plainly: "You cannot deploy something as a black box and then just hope it's going to work, especially when it comes to security."
New security software must understand the environment into which it is being deployed, and the humans working with it must understand that as well. The implementation of a tool is a starting point, not a finishing line, and the gap between the two is where the real risk lives. Projects built on belief or charisma alone will not stand the test of time.
To dig more into this, listen to the latest episode of the Thales Security Sessions Podcast, The Hidden Dangers Behind Out of the Box Security.