← Back to Insights
Diagnosis

The House problem in the boardroom.

Medicine replaced hunches with a repeatable process decades ago. Security still calls a color-coded slide a diagnosis, and boards keep signing off on it.

A single specimen vial lit electric blue, lifted from an ordered rack on a lab bench
Contents

Medicine stopped guessing

House opens with a patient who "just feels off" and a chart full of noise. He then does the thing television never really shows: he runs a process. Vitals. History. A first panel of tests. A differential, ranked by likelihood and by consequence. A second-line test to break the tie. Only then does he treat. The show is a courtroom about the guessing. Every diagnosis is really a discipline holding under pressure.

That discipline is the point, and it did not come from any one brilliant doctor. Clinical medicine spent the better part of a century building standardized intake, triage protocols, and structured differential diagnosis, specifically because unstructured judgment kills people at scale. A clinician does not ask "is this patient healthy?" as one question. They ask it against a history, a set of known risk factors, and a stack of objective readings, in that order. The question only means something once it is scoped.

The discipline also survives the individual doctor. Morbidity and mortality reviews force a hospital to reopen the worst outcomes and ask what the process missed, not just what the doctor missed. Board certification makes the workup itself something a clinician is tested on, repeatedly, for an entire career. Medicine did not just write the process down once. It built institutions whose whole job is to keep the process honest after the initial enthusiasm wears off.

Cyber still loves vague symptoms

Boards keep accepting the security equivalent of "your vitals look fine this quarter." A slide with tool counts. An alert volume trend line. A coverage percentage for the endpoint agent. None of it says whether a real attacker, today, could get from the internet to the crown jewels, or how long it would take the team to notice and stop them if they tried.

The Verizon Data Breach Investigations Report has made the same point for years without much changing: the paths attackers actually use are a short, repeatable list, not a mystery. Security does not lack information about what the real risks look like. It lacks the discipline to report against them instead of around them.

The result is House's first patient on a loop, every quarter, forever: dramatic symptoms, no structured workup, and a room full of smart people agreeing to treat a hunch as a plan because the hunch came with a nice chart.

Part of this is a demand problem, not just a supply one. A board asking "are we secure" wants relief, and a slide full of green checkmarks delivers relief faster than a ranked list of ways the company could get hurt this year. A CISO who brings the second kind of report is choosing a harder meeting on purpose. Medicine solved this by making the harder report mandatory, not optional. A surgeon does not get to skip the pre-operative checklist because the room would rather hear that everything looks fine.

The three-part workup

Medicine-level accuracy requires medicine-level structure. That means retiring the dashboard and building a diagnostic process with three fixed parts.

A standard intake.

Before any conversation about controls, know the patient: a real asset inventory, the business processes that actually make money, and an explicit threat model for who would want to hurt this specific organization and why. Most security reporting skips straight to treatment because nobody wrote down the patient history first.

A routine panel.

Fixed, quarterly labs on identity, endpoints, data flows, and third-party access, scored the same way every quarter. Not a new metric because last quarter's number looked bad. A clinician does not swap out cholesterol for a friendlier number when the reading disappoints, and the board should not tolerate a security team doing the equivalent.

A real differential.

An explicit, ranked list of the five most likely ways this specific organization gets seriously hurt this year, each one mapped to the scenario and the control that actually addresses it, not a generic heat map borrowed from a vendor's template. A differential names the disease before it names the treatment.

What changes on Monday

A security leader who takes this seriously does not wait for next quarter's board deck to start. The change is visible inside a week.

Pull the last board report and cross out every line that describes an activity, deployed, patched, trained, instead of a state: exposed, contained, unknown. What is left is usually thin. That is the honest starting size of the actual diagnostic.

Write the top five differential on one page, by name, before the next board meeting, and put a named control against each one. If a control cannot be named, that line is not covered. It is a guess wearing a checkbox.

Pick one item from the routine panel, identity is usually the fastest, and score it the way a clinician reads a lab result. Not "identity looks good" but, for example, a specific count of accounts holding standing access to the crown-jewel systems and how many of them have gone stale. A number tied to a specific exposure is a reading. A number with no exposure attached is decoration.

Name an owner for each item on the differential the way a chart names an attending physician. A risk with no named owner is not managed. It is noticed.

None of this requires new tooling. It requires refusing to present a summary as an answer.

Stop playing House

House gets to the truth because the format forces him to. He cannot walk into the differential meeting and say the patient seems fine. The structure will not let dramatic symptoms and no diagnosis coexist for more than an episode.

Security has no equivalent format forcing it, so it defaults to the version boards will accept without pushback: a dashboard that looks thorough and commits to nothing. The fix is not a better slide. It is a security function willing to say, in front of the board, exactly what it believes is most likely to hurt the business this year, and stand behind that list until the next test proves it wrong. That is the difference between practicing medicine and performing it.

Key point

A number tied to a specific exposure is a reading. A number with no exposure attached is decoration.

On Monday

Cross out every board-report line that names an activity instead of a state. What is left is the honest size of the diagnostic.

The takeaway

The fix is not a better slide. It is a security team willing to name, in front of the board, the five ways the business most likely gets hurt this year, and stand behind the list until the next test proves it wrong.

Keep reading

More from the seat.