Hero image for "The Disaster You Didn't Have Is Quietly Running Your Risk Budget"

The Disaster You Didn't Have Is Quietly Running Your Risk Budget


Here's a scenario that should feel uncomfortably familiar.

A competitor suffers a high-profile data breach. The story runs on LinkedIn for two weeks. Executives testify before a committee. A month later, your leadership team sits down for its quarterly risk review — and within an hour, everyone agrees the cybersecurity budget should triple.

Nobody has pulled up a risk analysis for your own infrastructure. Nobody has asked whether the actual threat to your organization has materially changed.

Meanwhile, a burnout crisis has been spreading through the organization for two years. The absenteeism data is there. The cost is — by conservative estimate — ten times higher than any realistic data breach scenario. But nobody talks about it. It's slow, it's invisible, and it lacks the dramatic charge of a cyberattack on the evening news.

This is the availability heuristic doing what it always does: making the vivid feel probable and the mundane feel negligible.

Why Your Brain Swaps "Memorable" for "Likely"

The mechanism here is worth understanding precisely, because it's sneakier than it first appears.

When Tversky and Kahneman first described the availability heuristic in 1973, they showed that people don't estimate probability by calculating — they estimate it by asking a simpler question: how quickly can I think of an example? Speed of retrieval gets translated directly into perceived frequency. What comes to mind easily feels like what happens often.

Their classic demonstration: are there more English words that begin with K, or words where K is the third letter? Most people say words starting with K. They're wrong — words with K in the third position (think, make, bike) are far more common. But think and make don't leap to mind the way king and knife do. The brain substitutes retrieval speed for statistical reality, and the substitution doesn't feel like a shortcut. It feels like thinking.

Three things make an event cognitively available: recency, vividness, and emotional charge. A competitor's breach hits all three. Your organization's slow-burn absenteeism problem hits none of them. So one dominates the risk conversation and the other gets a footnote.

This is what Kahneman called WYSIATI — "what you see is all there is". System 1 builds the most coherent story it can from whatever information is currently active in memory. Information that isn't retrieved might as well not exist. A risk assessment built on WYSIATI isn't an assessment of actual risk — it's an assessment of recent news.

Where This Gets Genuinely Dangerous

The availability heuristic works reasonably well in stable environments where memorable events are actually representative ones. The problem is that high-stakes decisions rarely happen in stable environments.

Consider how availability bias shapes task estimation at work: a project similar to one that recently went badly over budget gets padded with extra time and resources, while a project that resembles a recent success gets underestimated — regardless of the actual structural differences between them. The recent experience colonizes the estimate.

The same pattern runs through risk management at every level. After a plane crash dominates the news cycle, people significantly overestimate the risk of dying in a plane crash while underestimating far more common risks like car accidents or cardiovascular disease. The statistical rarity of the dramatic event is irrelevant — its vividness makes it feel probable.

What makes this particularly hard to catch is that the reasoning feels rigorous. The executives tripling the cybersecurity budget aren't being lazy. They're responding to real information about a real event. The bias isn't in ignoring evidence — it's in which evidence gets weighted, and why. System 2, the slow deliberate reasoning process, is supposed to check System 1's intuitive leaps — but it tends to accept them when they arrive with a compelling recent story attached.

The Structural Fix (and Its Limits)

The standard advice here is to slow down and consult base rates — look at the actual frequency of events rather than the vividness of recent examples. That's correct, and it's also genuinely hard to do in a room where everyone just watched the same news cycle.

What works better in practice is structural: build the risk review process so that it forces attention to slow-moving, low-drama risks before the recent vivid event gets discussed. If the agenda starts with the competitor's breach, the whole conversation is already anchored there. If it starts with a systematic review of the organization's own risk register — including the unglamorous stuff — the vivid recent event has to compete with actual data rather than dominating by default.

The deeper discipline is learning to ask: what risks are we not talking about, and why? The answer is almost always that they're slow, invisible, and lack a recent dramatic example. Which is precisely when they deserve more attention, not less.

I've written before about how the last disaster tends to run your risk model — how organizations systematically over-prepare for the crisis they just had. The availability heuristic is the mechanism underneath that pattern. The disaster you just heard about feels like the disaster most likely to happen next. Usually, it isn't.

The risks worth worrying about are the ones nobody's brought up yet.