I have seen a decade of strategy evaporate in under a minute. Not because the strategy was weak, and not because the people were incompetent but because one ordinary, well-meaning employee clicked a perfectly normal-looking email.
That is the messy reality executives avoid. Organizations do not collapse through grand failures. They unravel through small, human ones. One click feels insignificant, years of progress feel solid and that false comparison is where leaders misjudge risk.
Think of an organization as a cathedral built stone by stone. Governance, culture, systems, trust, reputation. Each year adds height, one careless strike at the foundation does not look dramatic but the crack travels faster than the builders ever climbed. That is how one click undoes years.
Most boards believe progress is cumulative and risk is incremental. That assumption is flawed. Progress compounds slowly. Risk compounds silently and detonates suddenly.
I was engaged by a regulated institution that had done almost everything right. Clean audits, stable leadership, strong growth and a respected brand. Cybersecurity was “covered” through policies, firewalls, and a competent IT team. Training had been done, slides were signed and boxes ticked.
Then a senior manager clicked a link that appeared to come from an internal department. No malware alarm, no strange behavior, Just a prompt to reauthenticate. Credentials were harvested, within days, customer data was accessed. Within weeks, regulators were asking questions that no PowerPoint could answer.
Nothing collapsed immediately. That is what made it dangerous. Customers were not angry at first, Staff kept working, Systems stayed online but trust leaked quietly.
Investigations began. Senior leaders shifted from growth conversations to damage control. Strategic projects stalled. Talent started to leave, not loudly, but deliberately.
One click did not cause the damage. It revealed the fragility. Here is what executives miss. Digital systems now sit at the intersection of human behavior and organizational memory. A single action can unlock access to years of accumulated data, relationships, and credibility. That asymmetry did not exist before. Today, it defines modern risk.
Leaders invest heavily in strategy documents, transformation programs, and culture initiatives. They assume these assets are protected by their size and seriousness. Yet they are not, they are protected by everyday decisions made under cognitive load.
Pressure is the accelerant. In high-performing organizations, people move fast, they multitask, they trust internal signals and they are rewarded for responsiveness. That environment, ironically, increases vulnerability.
The faster and more confident the organization, the more likely a bad click slips through. This is not a technology problem. It is a leadership design problem.
The real issue is not that someone clicked. The issue is that the organization assumed progress was robust, when in fact it was brittle. Brittle systems look strong until stressed. Resilient systems expect failure and absorb it.
In another case, this time a public institution, a similar incident occurred. An employee clicked a link. Credentials were compromised but the outcome was different. Access was segmented but privileges were limited. Alerts triggered immediately. The incident was contained within hours. No public fallout and no strategic derailment.
Same click. Different design. Years of progress are undone when leaders confuse compliance with resilience. Policies do not stop clicks. Culture does not stop clicks. Even awareness does not stop clicks. Design limits damage.
Boards like to ask, “Who failed?” The better question is, “What was exposed?”
When one click can access core systems, sensitive data, or decision-making platforms, the organization has quietly centralized risk without noticing. Convenience has replaced control. Speed has replaced separation.
This is where progress becomes its own enemy. As organizations digitize, integrate, and streamline, they often remove friction that once acted as protection. Single sign-on, shared drives, broad access rights and everything works beautifully, until it does not.
One click becomes a master key. The lesson for executives is not to slow people down. It is to design for human error as a certainty, not an exception.
That means three things in practice;
First, assume your best people will make mistakes under pressure. Design systems that limit blast radius.
Second, treat cyber risk as a governance issue, not an IT one. If a single action can threaten strategy, the board owns that risk.
Third, stop measuring progress only by growth and efficiency. Measure how quickly the organization can absorb a shock without losing trust.
The most dangerous organizations are not the careless ones. They are the confident ones who believe their success makes them safe.
One click undoes years of progress when progress is built on optimism instead of realism.
Resilient organizations do not hope people will not click. They plan for the click, contain it, learn from it, and move on without losing their soul.
That is the difference between progress that looks impressive and progress that lasts.
I remain, Mr. Strategy.
