---
title: "Cybersecurity Risk Needs to be Simplified"
description: "Simplify cybersecurity risk by understanding that complexity hinders execution and the traditional threat x vulnerability formula is impractical. Learn to…"
lang: en
json-ld: |
  [
    {
      "@context": "https://schema.org",
      "@type": "Person",
      "@id": "https://christianespinosa.com/#person",
      "name": "Christian Espinosa",
      "url": "https://christianespinosa.com/",
      "image": "https://christianespinosa.com/__l5e/assets-v1/de07e44b-a8e0-4bcc-bcb0-13aec15421f1/headshot-front.jpg",
      "sameAs": [
        "https://www.facebook.com/christian.espinosa.official",
        "https://x.com/Ironracer",
        "https://www.instagram.com/christian.espinosa.official/",
        "https://www.youtube.com/@ChristianEspinosaOfficial",
        "https://www.linkedin.com/in/christianespinosa/"
      ],
      "jobTitle": "Bestselling Author, Keynote Speaker, Entrepreneur",
      "worksFor": {
        "@type": "Organization",
        "name": "Blue Goat Cyber",
        "url": "https://bluegoatcyber.com/"
      }
    },
    {
      "@context": "https://schema.org",
      "@type": "WebSite",
      "@id": "https://christianespinosa.com/#website",
      "name": "Christian Espinosa",
      "url": "https://christianespinosa.com/",
      "publisher": {
        "@id": "https://christianespinosa.com/#organization"
      },
      "inLanguage": "en-US"
    },
    {
      "@context": "https://schema.org",
      "@type": "Organization",
      "@id": "https://christianespinosa.com/#organization",
      "name": "Christian Espinosa",
      "url": "https://christianespinosa.com/",
      "logo": {
        "@type": "ImageObject",
        "url": "https://christianespinosa.com/logo.svg"
      },
      "founder": {
        "@id": "https://christianespinosa.com/#person"
      },
      "sameAs": [
        "https://www.facebook.com/christian.espinosa.official",
        "https://x.com/Ironracer",
        "https://www.instagram.com/christian.espinosa.official/",
        "https://www.youtube.com/@ChristianEspinosaOfficial",
        "https://www.linkedin.com/in/christianespinosa/"
      ]
    },
    {
      "@context": "https://schema.org",
      "@type": "Article",
      "headline": "Cybersecurity Risk Needs to be Simplified - Christian Espinosa",
      "description": "Simplify cybersecurity risk by understanding that complexity hinders execution and the traditional threat x vulnerability formula is impractical. Learn to…",
      "image": "https://christianespinosa.com/__l5e/assets-v1/93d6f8ee-f370-498b-bef8-a237b5aebe38/cybersecurity-risk-needs-to-be-simplified-card.png",
      "datePublished": "2021-09-04T04:45:55+00:00",
      "dateModified": "2026-06-26T05:33:15.708Z",
      "mainEntityOfPage": {
        "@type": "WebPage",
        "@id": "https://christianespinosa.com/blog/cybersecurity-risk-needs-to-be-simplified"
      },
      "author": {
        "@type": "Person",
        "name": "Christian Espinosa",
        "url": "https://christianespinosa.com/about"
      },
      "publisher": {
        "@type": "Organization",
        "name": "Christian Espinosa",
        "logo": {
          "@type": "ImageObject",
          "url": "https://christianespinosa.com/logo.svg"
        }
      }
    },
    {
      "@context": "https://schema.org",
      "@type": "FAQPage",
      "mainEntity": [
        {
          "@type": "Question",
          "name": "What is the core idea behind \"Cybersecurity Risk Needs to be Simplified - Christian Espinosa\"?",
          "acceptedAnswer": {
            "@type": "Answer",
            "text": "Complexity is the enemy of execution. Unnecessary complication is tied to ego & lack of clarity. In cybersecurity everything is overly complicated."
          }
        },
        {
          "@type": "Question",
          "name": "Who is this post for?",
          "acceptedAnswer": {
            "@type": "Answer",
            "text": "Honestly, security leaders, medical device teams, and technical operators who want the honest version, not the vendor version. If you want a listicle, this is not that. If you want the honest version of what I have actually lived and worked through, keep reading."
          }
        },
        {
          "@type": "Question",
          "name": "How do I actually apply this, not just nod along?",
          "acceptedAnswer": {
            "@type": "Answer",
            "text": "Pick the single line in the post that made you flinch or look away, and change one thing in your week because of it. One choice this week beats a whole framework you never touch."
          }
        }
      ]
    }
  ]
---

[Skip to content](#main)

[](/)

[About](/about)[Speaking](/speaking)[Cybersecurity](/cybersecurity)[Programs](/programs)[Books](/books)[Media](/media)

Writing

Search Ctrl K[Connect](/connect)

[Cybersecurity](/blog/category/cybersecurity)

# Cybersecurity Risk Needs to be Simplified

September 4, 2021 4 min read 860 words 

I believe complexity is the enemy of execution. Unnecessary complication is often tied to ego and lack of clarity. In cybersecurity, just about everything is overly complicated. I’m not sure why.

![](/__l5e/assets-v1/1fe08f2c-d5e8-45a0-833f-2079715325ce/cybersecurity-risk-needs-to-be-simplified-hero.webp)

The takeaways

1.  01 
    
    Introduction I believe complexity is the enemy of execution.
    
    What to do next Open your current introduction plan today and identify the one gap you would not want an auditor to find.
    
2.  02 
    
    Unnecessary complication is often tied to ego and lack of clarity.
    
    What to do next Add unnecessary to the next leadership review as a standing item, not a one-time slide.
    
3.  03 
    
    In cybersecurity, just about everything is overly complicated.
    
    What to do next Add cybersecurity to the next leadership review as a standing item, not a one-time slide.
    
4.  04 
    
    The cybersecurity industry seems to want to learn new methods to slam dunk, without learning how to dribble first.
    
    What to do next Add cybersecurity to the next leadership review as a standing item, not a one-time slide.
    

## ![cybersecurity risk](/__l5e/assets-v1/3dddb98f-d8ae-408b-8bad-a3659bab1feb/55e2cc71270a.jpg) Introduction

I believe complexity is the enemy of execution. Unnecessary complication is often tied to ego and lack of clarity. In cybersecurity, just about everything is overly complicated. I’m not sure why. I sometimes even wonder if I understand it. We have all the frameworks, best practices, maturity models, team/hacker colors, next-gen appliances. It’s hard to keep up. The cybersecurity industry seems to want to learn new methods to slam dunk, without learning how to dribble first. I get it; slam dunking is sexy; dribbling is boring. The fact of the matter though is most people that master a skill get very good at a few key moves and ignore the rest.

In cybersecurity, there’s this notion that you need to master 100 things to be secure. This doesn’t work. The reality is mastering the Top 5 to 6 things is often enough, especially if you know your critical assets (data and systems) and the risk facing them.

## Risk. Traditional Definition

Risk is a misunderstood and elusive topic in cybersecurity. Over my career I’ve met very few cybersecurity professionals that actually understand risk. Sure, they read about it in a book or learn about it preparing for the CISSP or Security+ certification exams, but they don’t really understand risk. They’ll tell you the formula:

**_Risk = Threat X Vulnerability_**

This is what the academics say. What does this really mean though?

What is a threat? What is a vulnerability?

What about impact or probability?  These aren’t even listed in the equation above, yet they are the most important parts.

A threat is something that could cause damage.

A vulnerability is an exposure to a threat.

So, using the formula that most cybersecurity professionals have been taught for risk, it’s understandable why it’s not understood.

If a threat is water from rain and the vulnerability is an open car window, what’s the risk?

Risk = Water X Open Car Window ?

This is where most cybersecurity professionals start mumbling about frameworks, qualitative, quantitative, and other lingo with the intent to complicate something that should be simple. And, there’s not much you can do with that formula; very little value.

The problem is how do you prioritize which open car windows to close first? If you are a nationwide organization with 1000 cars and 800 of them have an open window, what do you do? You only have so many resources.

Let’s dig a little deeper on this.

Of the 800 cars with open windows, they fall in different categories:

**Arizona**

-   50 brand new cars parked in garages
-   50 brand new cars parked outside
-   200 old cars parked in garages
-   100 old cars parked outside

**Seattle**

-   50 brand new cars parked in garages
-   50 brand new cars parked outside
-   200 old cars parked in garages
-   100 old cars parked outside

So, using the risk formula, what do you do? **_Risk = Threat X Vulnerability_**

Exactly. The formula is kind of useless. You can’t close all the car windows at once; you have limited resources.

## Risk. Practical Explanation

A more useful risk formula is **_Risk = Probability X Impact_**

Risk = **Probability** of Threat Being Realized X **Impact** if Threat is Realized

Probability can also be referenced as likelihood.

Impact can also be referenced as a consequence.

To me, this makes more sense than Threat X Vulnerability, which is what CISSP and other cybersecurity certs teach us.

Let’s take the open car window scenario:

**Arizona**

-   50 brand new cars parked in garages
-   50 brand new cars parked outside
-   200 old cars parked in garages
-   100 old cars parked outside

**Seattle**

-   50 brand new cars parked in garages
-   50 brand new cars parked outside
-   200 old cars parked in garages
-   100 old cars parked outside

Likelihood of rain (water)

Simple Risk Matrix

1.  Seattle = Near Certain
2.  Arizona = Likely
3.  In Garage (location doesn’t matter) = Rare

Impact:

1.  New car = Significant
2.  Old car = Minor

Which windows do we close first? Let’s use the matrix as a guide.

-   Seattle, New Car
    -   Near Certain X Significant = Critical Risk [![cybersecurity risk](/__l5e/assets-v1/a2ce4e40-70f2-4d07-bb26-3b67a4158f64/872b903dce67.jpg) ](https://christianespinosa.com/resources/spitr/cybersecurityrisksimplified-christianespinosa/)
-   Seattle, Old Car
    -   Near Certain X Minor = High Risk
-   Arizona, New Car
    -   Likely X Significant = Medium
-   Arizona, Old Car
    -   Likely X Minor = Low
-   Garage, New Car
    -   Rare X Significant = Medium
-   Garage, Old Car
    -   Rare X minor = Informational

So, we would prioritize the windows to close in order of risk:

1.  Critical Risk = Seattle, New Car
2.  High Risk = Seattle, Old Car
3.  Medium Risk = Arizona, New Car
4.  Medium Risk = Garage, New Car
5.  Low Risk = Arizona, Old Car
6.  Informational Risk = Garage, Old Car

## Conclusion

Think of risk in terms of probability and impact, not threat times vulnerability.

Frequently asked

### What is the core idea behind "Cybersecurity Risk Needs to be Simplified - Christian Espinosa"?

### Who is this post for?

### How do I actually apply this, not just nod along?

### Work with me

I help founders and cybersecurity leaders build teams that ship, not teams that stall. If that's the problem you're trying to solve, let's talk.

[Start a conversation](/contact)

Share this essay

[X ](https://twitter.com/intent/tweet?url=https%3A%2F%2Fchristianespinosa.com%2Fblog%2Fcybersecurity-risk-needs-to-be-simplified&text=Cybersecurity%20Risk%20Needs%20to%20be%20Simplified) [LinkedIn](https://www.linkedin.com/sharing/share-offsite/?url=https%3A%2F%2Fchristianespinosa.com%2Fblog%2Fcybersecurity-risk-needs-to-be-simplified) [Facebook](https://www.facebook.com/sharer/sharer.php?u=https%3A%2F%2Fchristianespinosa.com%2Fblog%2Fcybersecurity-risk-needs-to-be-simplified) [Email](mailto:?subject=Cybersecurity%20Risk%20Needs%20to%20be%20Simplified&body=https%3A%2F%2Fchristianespinosa.com%2Fblog%2Fcybersecurity-risk-needs-to-be-simplified)Copy link 

![Christian Espinosa, headshot](/__l5e/assets-v1/de07e44b-a8e0-4bcc-bcb0-13aec15421f1/headshot-front.jpg)

About the author

[Christian Espinosa](/about) · Founder & CEO, Blue Goat Cyber

Christian is the founder and CEO of Blue Goat Cyber, a medical device cybersecurity firm. He's an Air Force Academy graduate, 24x Ironman, climber of two of the Seven Summits, and the author of The Smartest Person in the Room and The In-Between: Life in the Micro.

Keep reading

-   [
    
    ### Risk Comprehension Is a Basic Cybersecurity Skill, Yet Most Practitioners Lack It - Christian Espinosa
    
    Same thread: cybersecurity.
    
    Read essay → ](/blog/risk-comprehension-is-a-basic-cybersecurity-skill-yet-most-practitioners-lack-it)
-   [
    
    ### The Cybersecurity Status Quo Needs to Change - Christian Espinosa
    
    Same thread: cybersecurity.
    
    Read essay → ](/blog/the-cybersecurity-status-quo-needs-to-change)
-   [
    
    ### Cybersecurity Trends Every Professional Needs to Know in 2026 - Christian Espinosa
    
    Same thread: cybersecurity.
    
    Read essay → ](/blog/2023-cybersecurity-trends-what-every-cyber-professional-needs-to-know)

[← Previous essay 

Questions to Ask a vCISO - Christian Espinosa

](/blog/questions-to-ask-a-vciso)[Next essay → 

Hacking Medical Devices for Profit and Terror - Christian Espinosa

](/blog/hacking-medical-devices-for-profit-and-terror)

Related, Cybersecurity

### Need medical-device or offensive security expertise?

Blue Goat Cyber, Christian's firm, runs FDA-aligned premarket submissions, penetration testing, and SBOM/SOUP analysis for medtech and high-stakes industries.

[Explore Blue Goat Cyber](/cybersecurity)

Christian Espinosa

Bestselling author, keynote speaker, and Founding CEO of [Blue Goat Cyber](https://bluegoatcyber.com/). Helping technical leaders develop the soft skills that turn brilliance into impact.

[](https://www.linkedin.com/in/christianespinosa/)[](https://x.com/Ironracer)[](https://www.instagram.com/christian.espinosa.official/)[](https://www.youtube.com/@ChristianEspinosaOfficial)[](https://www.facebook.com/christian.espinosa.official)

Explore

-   [About](/about)
-   [Timeline](/timeline)
-   [Speaking](/speaking)
-   [Cybersecurity](/cybersecurity)
-   [Programs](/programs)

Read

-   [Books](/books)
-   [Guides](/guides)
-   [Blog](/blog)
-   [Media](/media)
-   [Podcast Interviews](/podcasts)
-   [Success Stories](/success-stories)

Connect

-   [Contact Christian](/connect)
-   [LinkedIn ↗](https://www.linkedin.com/in/christianespinosa/)
-   [Blue Goat Cyber ↗](https://bluegoatcyber.com/)
-   [Resources](/resources)

© 2026 Christian Espinosa. All rights reserved.

[Privacy](/privacy-policy)[Terms](/terms-of-use)