Control is the Biggest Illusion 

Laura Kaltenbrunner

4 Min Read

Real cyber resilience begins when leaders stop chasing certainty and ask what they can still influence when control ends. 

Cyber risk sits where transformation becomes uncomfortable: between the technologies organisations rely on, the systems they cannot fully control, and the speed at which new vulnerabilities emerge. Ulrich Fleck, CEO of CERTAINITY, believes that organisations thinking more systems, rules, and safeguards can make them secure, is part of the problem. Real cyber resilience begins when leaders stop chasing certainty and ask what they can still influence when control ends. 

The Limits of Control 

Kaltenbrunner: Cyber risk is no longer seen as a purely technical issue. Where do you see organisations still underestimating the true scale of the risk? 

Fleck: The Internet and the associated information technology is everywhere and form the basis for nearly all business processes, as a result, exposure is also everywhere. Many organisations recognise that in principle; but in practice, they still underestimate how quickly things can escalate and how far the impact can reach. 

Kaltenbrunner: Many organisations assume risks can ultimately be controlled. How dangerous is that assumption today? 

Fleck: It is very dangerous. In reality, almost anything can happen, from a simple interruption of operations to the theft of information. What’s more, we have to remember that information can be stolen without disappearing from the original owner. That fundamentally changes how we must think about risk. It is not something you can fully contain. 

Kaltenbrunner: From your experience, where do organisations overestimate how much control they actually have over cyber risks? 

Fleck: Often in the belief that if systems are in place, the problem is solved. But security is not something you can install once and then tick off. Risks evolve constantly and, even with strong measures, vulnerabilities remain. The important point is to understand that control is always limited. 

Europe’s Sovereignty Gap 

Kaltenbrunner: To what extent has global dependency on technology providers reduced Europe’s ability to control its own risk exposure? 

Fleck: We are not particularly well positioned as Europeans in terms of sovereignty, neither in IT nor in energy. We depend heavily on value chains from outside which is creating exposure. At the same time, we must be realistic: no one can fully secure the entire supply chain down to the silicon. Not the Americans, not the Chinese, and certainly not us.

Kaltenbrunner: Europe is often described as strong in regulation but weaker in scaling innovation. How does that affect our ability to manage emerging risks? 

Fleck: The Americans are clearly better at scaling and commercialising technologies. And European regulation does not necessarily help here. I am in favour of data protection, but while data still flows around the world GDPR has become a bureaucratic monster. This is particularly true for smaller companies where it can feel like a façade. Most EU regulation is also targeting the use of technology, not so much the tech itself. I think it would be much better to have the possibility to sanction the tech providers; for example, by not allowing them to simply bail out of their liability via license agreements. The Cyber Resilience Act is a step into the right direction, but again in tries set boundaries and rules. It does not make the tech provider liable. 

Kaltenbrunner: Many organisations still believe that storing data in Europe guarantees control. Why is that assumption flawed? 

Fleck: It’s flawed because the location of the data is not the decisive factor. What matters is who controls the infrastructure where it is stored and even more important the technology that infrastructure is built on. The US Cloud Act shows that clearly: if a provider is based in the United States, data can be accessed by US authorities, regardless of where it is physically stored. What we are sometimes seeing is a kind of sovereignty washing. Companies claim sovereignty because data is stored locally, but control remains elsewhere, and control is what matters.  

And again, it’s not only the operator of the data centre that matters.  The real power often sits with the provider of the technology inside it.  Imagine if they don’t provide a crucial and important fix for a vulnerability, the operator may have no choice but to switch the system off, even without anyone forcing them to. Open Source might help a bit in this matter, but only if you have the means to actually look into it and develop potential fixes on your own. 

AI and the Speed of Exposure 

Kaltenbrunner: AI is developing at enormous speed. Will it help organisations manage cyber risk, or simply expose how many vulnerabilities already exist? 

Fleck: Both, but especially the latter. Even for people working in this field, it is difficult to keep up because something new happens daily. AI will have a massive impact on cybersecurity and an even greater one on how software is developed. With large language models, software can now be analysed and created extremely quickly, including its weaknesses. The problem is that these systems can identify vulnerabilities much faster than organisations can fix them. AI does not create those vulnerabilities; it reveals them more efficiently. The question is therefore, not whether vulnerabilities exist, but how quickly you find them and who finds them first. 

From control to resilience 

Kaltenbrunner: In your experience working with organisations, what kind of decisions require real courage when it comes to cyber risk? 

Fleck: Most investment in cyber security still goes into measures designed to prevent incidents. That is not wrong.  But in my experience, organisations invest far too little in preparedness for the moment a cyber crisis actually happens; especially in how they get out of it. Organisations have to accept that they will become a victim of a cyber-related crisis, and they need at least some kind of plan for that situation. Investing in resilience, not only in avoidance, is what I would call courageous. 

Kaltenbrunner: What changes when organisations accept that cyber risk cannot be fully controlled, and what practical shifts are needed to build real resilience instead? 

Fleck: Have a plan B. Do not rely on only one provider. Have somebody that can help during this dire time – have them close at hand and make sure they’re prepared. Have some emergency funding or insurance that covers two to three weeks of business interruption as a minimum. Organisations that do this are the ones that maintain overall control in a cyber crisis.  

Kaltenbrunner: If there is one mindset shift leaders need to make on cyber risk, what would it be? 

Fleck: Stop believing that cyber risk can be fully controlled. You cannot. The best organisations are not the ones that assume prevention will always work, but those that are prepared for the time after it does not. Resilience means knowing what you depend on, reducing single points of failure, keeping essential capabilities close, and having the right people ready – before a crisis begins. 

About Ulrich Fleck 
Ulrich Fleck is CEO of CERTAINITY and a cyber security expert with deep experience in information security, risk management, and cyber resilience. He works with organisations on the strategic and practical challenges of managing digital risk in an increasingly complex threat environment. 

About Certainity 
CERTAINITY is an independent cyber security consultancy founded in Austria and focused on Europe. The company supports organisations in strengthening cyber resilience through offensive and defensive security, process consulting, and security engineering. 

Laura Kaltenbrunner

Marketing Manager
CERTAINITY

Ulrich Fleck

Cybersecurity expert
CERTAINITY

Related Industries & Solutions

Share this article

Related Insights

GrECo and DIGNITA Join Forces to Strengthen Their Position in Bosnia and Herzegovina
MGAs operate within authority granted by insurers, with responsibility for underwriting, policy issuance, portfolio management and, depending on the model, claims support or coordination.
MGAs operate within authority granted by insurers, with responsibility for underwriting, policy issuance, portfolio management and, depending on the model, claims support or coordination.