Sciences comportementales

The turkey illusion: why yesterday’s safety can mislead tomorrow’s security strategy

Dr. Christian Reinhardt Dr. Christian Reinhardt · 21 août 2026 · 3 min read

When security leaders evaluate whether an organisation can handle what comes next, they usually look at the evidence directly in front of them. They look at what has been tested, what has held up under scrutiny, and what has failed to cause trouble so far. That last detail is the one that deserves a closer look.

In my work with security leaders at SoSafe, alongside my background in sports psychology, I often pay attention to how confidence develops inside teams. In sport and security alike, confidence starts with solid evidence, but over time it can outgrow that evidence. A clean incident log, manageable audits, and steady training completion numbers can make an organisation feel well prepared. The complication is that most of this evidence looks backwards. It tells you what held under the exact conditions you have already experienced. It tells you very little about what happens when an unexpected variable gets through.

Key Takeaways

  • Past calm is not future proof: An incident-free record can mean controls are working, or simply that an untested operational weakness has not been exploited yet.
  • Risk vs uncertainty: Security operates under constant uncertainty, where threat actors adapt and human decisions happen under shifting daily pressures.
  • Test the calm: Resilience comes from actively exercising safety instincts and reviewing trusted workflows, rather than ticking off annual compliance items.

The risk of a clean record

In risk theory, this pattern is often illustrated by philosopher Nassim Nicholas Taleb’s adaptation of the turkey problem. A turkey is fed every morning by the same farmer. At first, the turkey has no idea what the visit means. But as morning after morning brings food and safety, the routine builds trust. The pattern feels stable and predictable right up until Thanksgiving arrives, when the turkey learns the hard way that a historical pattern is not a guarantee.

An incident-free history in an organisation can operate in a very similar way. It might mean your controls are working perfectly, or it might mean the business has not yet faced the precise combination of timing, operational fatigue, or process weakness that would test those controls properly.

This is where it helps to separate predictable risk from uncertainty. With standard risk, you calculate known odds. With uncertainty, you make decisions before the world has shown you all the ways events can unfold. Cybersecurity sits firmly in uncertainty because threat techniques adapt, context changes, and people behave differently depending on the pressure of the moment.

Behavioural Insight: Confidence built solely on a quiet calendar is fragile. Real readiness relies on measuring whether safety instincts are active today, rather than assuming past calm guarantees future resilience.

Testing the calm in living systems

Modern organisations run on inherited trust. Access systems trust permissions granted months ago. Approval workflows trust that an executive requesting an urgent change has full context. Supply chain processes trust domains and invoices that look familiar. That inherited trust keeps business moving smoothly, but it is also where exposure accumulates over time.

To evaluate whether your daily workflows support genuine readiness under pressure, look closely at these living systems:

  • Identity and access: Are permissions systematically re-evaluated, or do they quietly accumulate as roles evolve?
  • Approval flows: Is there a frictionless, second-channel verification step when a high-value or unusual request arrives?
  • Decision support: Do employees have an easy way to sense-check suspicious communications directly within the tools they are already using?

Designing for continuous practice

Security awareness cannot remain a static item on an annual calendar while threat techniques become more credible, personal, and urgent. Knowing the correct answer in an annual module is fundamentally different from making the right call when someone is pushing for a quick decision on a busy afternoon.

At SoSafe, we help organisations treat security as a continuous habit rather than a one-off event. By combining role-tailored awareness with realistic simulations, employees get to practise the precise judgements an attacker will try to rush. Bringing behavioural signals from training, reporting, and cultural feedback into a single view gives leaders something far more valuable than a compliance pass rate: it shows whether their confidence is grounded in what people can actually do today.

Every strategy review is an opportunity to question « normal mornings » and ask where the organisation may be trusting an untested routine. If the main proof of readiness is simply that things have been fine so far, it might be time to test the calm before the conditions change for you.

Want deeper insights on human risk and behavioural security? Sign up for the SoSafe newsletter for regular perspectives on building organisational resilience.

About the author

Dr. Christian Reinhardt
Director of Human Risk Management, SoSafe

Dr. Christian Reinhardt is a sports psychologist, author, speaker, and former Managing Director of the Saxony-Anhalt Football Association. As an expert in human behavior and adult education, he brings deep psychological insight to his role as Director of Human Risk Management at SoSafe. There, he focuses on how cybercriminals exploit psychological mechanisms to manipulate individuals—and how organizations can harness the same behavioral science to foster secure habits. Previously, he lectured at Martin Luther University Halle-Wittenberg and worked as a learning consultant with international companies, always with a passion for turning complex psychological concepts into practical, people-centered strategies for awareness and behavior change.

En savoir plus

Vous voulez avoir toujours une longueur d’avance en matière de cybersécurité ?

Inscrivez-vous à notre newsletter pour tout savoir sur les actualités, les événements et les ressources disponibles en matière de cybersécurité. Zéro spam, du contenu 100 % utile.

Newsletter visual
Hero Background

Découvrez nos produits de première main

Utilisez notre environnement de test en ligne pour voir comment notre plateforme peut vous aider à donner à votre équipe les moyens d’éviter en permanence les cybermenaces et de préserver la sécurité de votre organisation.

SoSafe G2 award Leader Enterprise 2026 Sosafe Cyber security training platform top 50 award 2026 SoSafe G2 Leader 2026 SoSafe G2 Momentum Leader 2026 SoSafe G2 Leader márché moyen 2026 Sosafe G2 Leader Europe 2026

This page is not available in English yet.

Diese Seite ist noch nicht in Ihrer Sprache verfügbar. Sie können auf Englisch fortfahren oder zur deutschen Startseite zurückkehren.

Cette page n’est pas encore disponible dans votre langue. Vous pouvez continuer en anglais ou revenir à la page d’accueil en français.

Deze pagina is nog niet beschikbaar in uw taal. U kunt doorgaan in het Engels of terugkeren naar de Nederlandse startpagina.

Esta página aún no está disponible en español. Puedes continuar en inglés o volver a la página de inicio en español.

Questa pagina non è ancora disponibile nella tua lingua. Puoi continuare in inglese oppure tornare alla home page in italiano.