← All insights

Top Priority and Still No Decision: Decision Avoidance

Published: 17 April 2026

Top Priority and Still No Decision: Decision Avoidance

Why ‘top risk’ and ‘top priority’ in boardroom discussion so often fail to produce a decision in practice.

The pattern repeats with remarkable consistency. On stage, it is ‘top risk’, ‘highest priority’, ‘we must act’. Inside the company, what follows is: no decision, no owner, no programme, and little change.

At the same time, the market manufactures permanent urgency. Barely a week passes without another study warning that whoever fails to act now will be left behind tomorrow. A significant share of this pressure comes from the AI or cybersecurity industry itself, from vendors, analysts, and conferences with a commercial interest in fast decisions. This urgency deserves scepticism. Not everything presented as imperative actually is. Not every supposedly immediate need to act survives a sober strategic review.

Anyone steering cybersecurity and artificial intelligence initiatives at board or executive level must understand both sides: the market pressure that tempts rushed action, and the mechanisms that produce paralysis despite all the urgency. In most cases, the problem is neither ignorance nor a lack of seriousness. The problem has a name: decision avoidance.

The decision not taken is itself a decision

I have observed this pattern often in my own leadership practice, as CEO and as a board member, as well as in mandates outside my own organisation. The people responsible for the decision know exactly what is at stake. Yet no decision is made. The justifications are strikingly consistent.

Four justifications and how they work

  • Prioritisation: ‘We already have enough on our plate.’ This statement is rarely a sign of ignorance. It describes a capacity and prioritisation problem. When an initiative looks large and resources are tight, deferral becomes the default option. Decision research calls this behaviour choice deferral, the systematic postponement of decisions as complexity rises: the more cluttered the decision space, the more attractive not deciding becomes.

  • Value lever: ‘The ROI is not clear.’ This objection is understandable, but it leads to a dangerous fallacy. Cyber and AI initiatives are treated like ordinary investment projects, even though at their core they are risk management, resilience, and a strategic value lever all at once. ROI is not the only valid justification for initiatives that primarily serve loss prevention and strategic positioning. Tversky and Shafir described the underlying dynamic three decades ago: the more conflict a decision space contains, the more likely deferral becomes. Anyone who sets a clear ROI as a precondition for every decision has already institutionalised deferral.

  • Harmony and management debt: ‘Projects like this surface things we don’t want to discuss right now.’ This is the most delicate of the four objections, and also the one voiced most rarely in the open. In my experience, almost nobody states it directly. What happens instead: resistance emerges from operations, disguised as a resource or cost argument, or as a reference to ongoing initiatives that should not be disrupted right now. What actually lies behind it is inefficient processes, workarounds built around people, siloed digitalisation, unclear data ownership, shadow IT, technical debt, integration gaps, legacy burden. Active work creates transparency, and transparency creates accountability. That accountability is precisely what many want to avoid. The omission bias explains why inaction can feel subjectively more attractive than action: harm caused by inaction is often judged more leniently than equivalent harm caused by active decisions, even when the inaction is objectively riskier. That is understandable on a human level, and untenable from a governance perspective all the same.

  • Never change a running system: ‘We’ll stick with what has worked so far.’ This is the most elegant form of blockage. Small, non-binding steps are taken; structural decisions are avoided. The status quo bias systematically favours the existing state, because it requires less justification. What already exists is treated as self-legitimising. What is new must justify itself. This asymmetry is structurally embedded in most boards and executive teams, and rarely discussed explicitly.

Two reflexes, one path

Kicking the issue further down the road is, of course, no answer either. Whoever waits until regulation, competition, or an incident forces what a decision could have pre-empted has already lost time, room to manoeuvre, and in many cases trust as well.

The consequences of both reflexes differ, but they are equally damaging:

  • Decision avoidance produces risk accumulation: vulnerabilities stay open, dependencies grow unchecked, and pressure to act increases with every quarter that passes unused.

  • Action bias produces unwind costs: ten proofs of concept run in parallel, three security tools get licensed before requirements are clear, and a task force delivers activity rather than results. In both cases, the same thing is missing: a deliberate strategic decision on how to approach the issue. Not whether, not immediately, not everything at once. Rather, with a clear target picture, defensible prioritisation, and a governance logic that makes progress measurable.

What I changed in my own meetings: focus

From topic to decision. The most effective change in my own leadership practice was to consistently translate topics into decision questions. The question ‘We should manage cyber and AI risk better’ invites deferral. Status: ongoing. The question ‘Which three risks will we measurably reduce in the next ninety days?’ forces an answer. The difference looks small; the effect is substantial.

Reversing the default. If deferral is the default option, deferral happens. If deciding is the default option, deciding happens. Boards and executive teams need formats that force a resolution: a decision paper with clearly distinct options, an assessment of risk, cost, owner, and timeline, and, at the end, a clear resolution of ‘yes’, ‘no’, or ‘yes with conditions’. This format strips the status quo of its silent majority.

Reframing ROI in the language of risk. Anyone who applies ROI as the sole benchmark will regularly fail with cyber and AI programmes, because a substantial part of the value lies in losses avoided, and that value is inherently hard to quantify precisely. More useful are questions that are directly actionable and answerable: what downtime is acceptable, measured against RTO and RPO? Which crown jewels take priority? Which minimum controls are non-negotiable, such as privileged access, multi-factor authentication, backup and recovery capability, review of critical third parties? Which AI use cases are permitted, which are excluded, and under what guardrails? These questions can be answered without a perfect ROI model. And they produce a governance basis that an ROI model cannot deliver in this form.

Transparency as a tool, not a threat. When a project exposes legacy problems, that is not failure. It is early risk reduction. The governance logic should be built accordingly: what newly becomes visible goes into the backlog. What is critical goes into the ninety-day plan. What is structural goes into the multi-year programme. The board then does not steer the individual findings. It steers how they are handled. This substantially eases the political situation inside the company, because the message becomes: we want to know, we categorise it, we work through it.

‘The secret of getting ahead is getting started.’ – attributed to Mark Twain

The smallest useful start. A starting approach I have implemented successfully in different settings follows three horizons.

  • In the first thirty days: define the crown jewels, name the three largest risks across cybersecurity and AI, and appoint an owner with a board sponsor.

  • In the next ninety days: actually deliver baseline measures in both fields. On the cyber side, this includes privileged access, multi-factor authentication, a tested backup and recovery exercise, a third-party review, and an incident playbook ready for use. On the AI side, it includes an inventory of AI applications already in use, including unsanctioned use, an initial risk assessment of the identified use cases, and clear rules for handling sensitive data.

  • In month six: the AI use register, clarified data ownership, guardrails, one or two scaled AI use cases, and the integration of cyber and AI governance into existing risk governance.

What matters is small but targeted steps in a defined direction towards a defined goal. No unrealistic expectations, no exaggerated time pressure, but constant steps towards the goal.

What remains in the end

The decision not taken is itself a decision. It is quiet, it is convenient in the short term, and under a board’s understanding of governance it is just as attributable as an active decision. But a hasty decision, driven by market pressure and without a strategic basis, does not protect against accountability either. On the contrary: it generates cost, complexity, and unwind projects that later turn out to have been avoidable.

Anyone who holds responsibility for cybersecurity and artificial intelligence at board or executive level does not face the question of whether a decision gets made. They face the question of whether it is made deliberately and with full information, or whether the market, chance, or an incident makes the decision instead. Decision avoidance and action bias are two sides of the same coin: both are a way of dodging the actual leadership task, which is to reach a sound strategic decision and to implement it consistently.


Glossary

  • Decision avoidance describes the systematic avoidance or postponement of decisions in order to sidestep the psychological burden of deciding.
  • Choice deferral is a specific form of decision avoidance, in which a decision is consciously postponed because the options are perceived as too complex or conflict-laden.
  • Omission bias describes the tendency to judge harm from inaction as less serious than equivalent harm from active decisions.
  • Status quo bias is the systematic preference for the existing state over change, regardless of whether the existing state is objectively advantageous.
  • Action bias describes the tendency to act under uncertainty or observation pressure, even when waiting or targeted analysis would produce a better outcome.
  • Tool sprawl describes the uncontrolled proliferation of software tools within an organisation.
  • RTO (Recovery Time Objective) defines the maximum acceptable period before a system or business process must be functional again after an outage.
  • RPO (Recovery Point Objective) defines the maximum acceptable data loss, measured in time, meaning how far back the last saved version is allowed to be.

Sources and further reading

  • Tversky, A. & Shafir, E. (1992). Choice under conflict: The dynamics of deferred decision. Psychological Science, 3(6), 358–361.
  • Samuelson, W. & Zeckhauser, R. (1988). Status quo bias in decision making. Journal of Risk and Uncertainty, 1(1), 7–59.
  • Baron, J. & Ritov, I. (2004). Omission bias, individual differences, and normality. Organizational Behavior and Human Decision Processes, 94(2), 74–85.
  • Anderson, C. J. (2003). The psychology of doing nothing: Forms of decision avoidance result from reason and emotion. Psychological Bulletin, 129(1), 139–167.