
Behavioural Science
The turkey illusion: why yesterday’s safety can mislead tomorrow’s security strategy
When security leaders evaluate whether an organisation can handle what comes next, they usually look at the evidence directly in front of them. They look at what has been tested, what has held up under scrutiny, and what has failed to cause trouble so far. That last detail is the one that deserves a closer look.
In my work with security leaders at SoSafe, alongside my background in sports psychology, I often pay attention to how confidence develops inside teams. In sport and security alike, confidence starts with solid evidence, but over time it can outgrow that evidence. A clean incident log, manageable audits, and steady training completion numbers can make an organisation feel well prepared. The complication is that most of this evidence looks backwards. It tells you what held under the exact conditions you have already experienced. It tells you very little about what happens when an unexpected variable gets through.
Key Takeaways
- Past calm is not future proof: An incident-free record can mean controls are working, or simply that an untested operational weakness has not been exploited yet.
- Risk vs uncertainty: Security operates under constant uncertainty, where threat actors adapt and human decisions happen under shifting daily pressures.
- Test the calm: Resilience comes from actively exercising safety instincts and reviewing trusted workflows, rather than ticking off annual compliance items.
The risk of a clean record
In risk theory, this pattern is often illustrated by philosopher Nassim Nicholas Taleb’s adaptation of the turkey problem. A turkey is fed every morning by the same farmer. At first, the turkey has no idea what the visit means. But as morning after morning brings food and safety, the routine builds trust. The pattern feels stable and predictable right up until Thanksgiving arrives, when the turkey learns the hard way that a historical pattern is not a guarantee.
An incident-free history in an organisation can operate in a very similar way. It might mean your controls are working perfectly, or it might mean the business has not yet faced the precise combination of timing, operational fatigue, or process weakness that would test those controls properly.
This is where it helps to separate predictable risk from uncertainty. With standard risk, you calculate known odds. With uncertainty, you make decisions before the world has shown you all the ways events can unfold. Cybersecurity sits firmly in uncertainty because threat techniques adapt, context changes, and people behave differently depending on the pressure of the moment.
Behavioural Insight: Confidence built solely on a quiet calendar is fragile. Real readiness relies on measuring whether safety instincts are active today, rather than assuming past calm guarantees future resilience.
Testing the calm in living systems
Modern organisations run on inherited trust. Access systems trust permissions granted months ago. Approval workflows trust that an executive requesting an urgent change has full context. Supply chain processes trust domains and invoices that look familiar. That inherited trust keeps business moving smoothly, but it is also where exposure accumulates over time.
To evaluate whether your daily workflows support genuine readiness under pressure, look closely at these living systems:
- Identity and access: Are permissions systematically re-evaluated, or do they quietly accumulate as roles evolve?
- Approval flows: Is there a frictionless, second-channel verification step when a high-value or unusual request arrives?
- Decision support: Do employees have an easy way to sense-check suspicious communications directly within the tools they are already using?
Designing for continuous practice
Security awareness cannot remain a static item on an annual calendar while threat techniques become more credible, personal, and urgent. Knowing the correct answer in an annual module is fundamentally different from making the right call when someone is pushing for a quick decision on a busy afternoon.
At SoSafe, we help organisations treat security as a continuous habit rather than a one-off event. By combining role-tailored awareness with realistic simulations, employees get to practise the precise judgements an attacker will try to rush. Bringing behavioural signals from training, reporting, and cultural feedback into a single view gives leaders something far more valuable than a compliance pass rate: it shows whether their confidence is grounded in what people can actually do today.
Every strategy review is an opportunity to question “normal mornings” and ask where the organisation may be trusting an untested routine. If the main proof of readiness is simply that things have been fine so far, it might be time to test the calm before the conditions change for you.
Want deeper insights on human risk and behavioural security? Sign up for the SoSafe newsletter for regular perspectives on building organisational resilience.












