↵ select ↓ ↑ navigate esc close

Preparing for Uncertainty: Incidents, the Stoic Discipline of Judgment, and Premeditatio Malorum

Stoicism Today ·

Welcome to Stoicism Today! This week cybersecurity expert Paolo Gasperi writes about the importance of good judgment and preparation in handling crises of all kinds. Drawing on parallels between cybersecurity incidents and other types of life crisis, Gasperi highlights the Stoic principles that can lead us through difficulties.


Preface

This article arises from a concrete professional experience of mine: a cybersecurity tabletop exercise that I personally designed and used to test not only procedures and operational capabilities, but above all the way people make decisions under pressure.

The first part reconstructs the exercise scenario in order to make the uncertainty, incomplete information and dilemmas that emerge during a crisis visible. The second reinterprets what happened through several principles of Stoicism, showing how the discipline of judgment, the distinction between what is up to us and what we cannot control, and preparation for adversity can find practical application in the management of cybersecurity crises.

The final section broadens the perspective, highlighting how Stoicism can guide us in facing crises in real life—not only in cybersecurity.

Part I: Description of the Cyberattack

9:00 a.m. — The First Blow

At nine o’clock on Sunday morning, the first message appeared. It was on the official account of ACME, a small financial consultancy. A business that sells expertise, but above all trust. The name ACME is an ironic reference to the ACME Corporation from the Wile E. Coyote and Road Runner cartoons, supplier of his improbable contraptions and explosives.

The post was political, provocative and completely out of character for the company. Then another appeared. And another. It was neither a gaffe nor a joke. Someone controlled the account and was amusing themselves by publishing posts online in the company’s name.

For ACME, the potential damage was enormous. A few lines carrying the company logo and identity were enough to trigger shares, comments and suspicion. Deleting them afterwards would achieve little. Screenshots travel faster than denials.

The first question was obvious: how do we remove the posts?

Marketing tried to log in: incorrect password.

At that point, the situation changed. It was no longer a communications problem. It was a security incident. Political activism? Data theft? No one knew for certain.

A stranger controlled one of the company’s public channels. They could post again. No one knew how they had gained access, how long they had been in control or which other accounts might have been compromised.

The crisis team was convened.

Managers, technical staff and legal advisers began asking questions. Should the CEO be informed? Do we need to issue a denial? Should we call the police?

There were few facts. Already too many hypotheses. And just as many unanswered questions.

9:25 a.m. — Twenty-Four Hours

The company managing the platform ACME used to publish its posts responded to the urgent request. It might restore the account. But the process could take twenty-four hours.

Might. Could. No guarantees.

Twenty-four hours is normal for a technical fault. It is an eternity when a stranger is speaking to the world in your name. ACME could preserve evidence, secure other accounts, alert employees and prepare a statement.

It could not make the platform move faster. It could not stop screenshots. It could not prevent clients and journalists from drawing their own conclusions.

In a crisis, it is easy to confuse action with control. We do something simply because we cannot bear to remain still. Not because it is useful, but because uncertainty is intolerable.

That was the real test: to act on what was within the company’s power without pretending to control everything else.

9:40 a.m. — The Offer

A private message broke the silence: it came from the hacker who controlled ACME’s account.

The proposal was simple: $25,000 in Bitcoin. In exchange, immediate access and deletion of the posts. The offer was seductive. It did not merely promise the return of the account. It promised an end to the anxiety.

No waiting. No new messages. No clients to reassure.

For a financial consultancy, $25,000 might seem insignificant compared with a shattered reputation.

But the question was: what would ACME actually be buying? No guarantee that the account would be returned. No certainty that the posts would be deleted. No assurance against a second demand.

Paying might solve the problem. Or make it worse. It could encourage the extortion, create legal risks and put money into the hands of a criminal.

The pressure did not make these questions disappear. It merely made them easier to ignore.

In every crisis, there comes a moment when relief disguises itself as a solution. A bad bargain is accepted because waiting is frightening. We react impulsively because silence is hard to endure.

The payment was not merely testing ACME’s procedures. It was testing its judgment.

10:05 a.m. — The Suspicion

A specialist incident-response firm entered the scene, brought in by senior management to manage the situation.

Its first assessment was unforgiving. The account had not been adequately protected. Additional authentication was missing. The password had been poorly managed.

There were two possible explanations. An employee might have fallen for a scam and disclosed the password without realising it. Or the employee might have provided it deliberately.

At that point, there was no evidence supporting either conclusion.

Yet the moment the words ‘internal involvement’ were spoken, the atmosphere changed. A technical problem became a betrayal. From then on, every detail risked looking like evidence. An absence became suspicious. An old disagreement acquired new meaning. The search for a cause could turn into a hunt for someone to blame.

The team had to secure the accounts, reconstruct access activity and preserve records. It also had to protect its own judgment.

A company can recover an account and still lose something more important. It can respond to a breach of trust by accusing an innocent person. It can choose a convenient culprit instead of a difficult truth.

Urgency does not justify injustice, but it often makes injustice the easier path.

10:30 a.m. — The Journalist

The final development came by telephone. A journalist had seen the posts and wanted a statement.

ACME had to speak before it knew everything.

Silence might look evasive. Denying it too confidently could result in a lie. Accusing an employee would be irresponsible. Going into technical detail could confuse the public and perhaps disclose sensitive information.

Saying too little meant leaving the story to others. Saying too much meant turning a hypothesis into an official truth.

In a crisis, the temptation is always the same: ‘manufacture certainty’.

‘The situation is under control.’

‘Client data is safe.’

‘It was a disloyal employee.’

Clear statements. Reassuring statements. And possibly false ones. The correct response was less dramatic: we are aware of unauthorised posts. We are working to regain control of the account and establish what happened. We will communicate further information as soon as it has been confirmed.

What is to be done? How should we act? Issue a press release, or respond directly to the journalist?

Part II: Stoicism in Cybersecurity Practice: Training Judgment in Crises

No account had been taken over. No ransom had been demanded. No employee was under suspicion and no journalist was waiting for a statement.

What I have just described is a tabletop exercise that I actually used in my professional work: a facilitated exercise in which a crisis develops through a sequence of new events and participants must decide how to respond.

The situations were imaginary. The reactions were not.

During the exercise, when the ransom demand appeared, one manager reacted immediately: ‘Let’s pay and close the case.’ The others remained silent until the head of IT raised a simple but decisive objection: we had no certainty that, after payment, the attacker would actually return control of the platform. In my notes, I wrote that acting merely to make a problem disappear quickly can create greater problems later. This recalls Marcus Aurelius: before reacting, we should avoid adding to a situation more than the facts themselves actually tell us (Meditations 8.49). At that moment, payment appeared to be a solution; in reality, it was only one possibility, driven above all by the desire to bring uncertainty to an end. The same discipline also requires us to be willing to correct our judgment when an objection or new evidence shows that our initial assessment may have been wrong (Meditations 6.21).

The sense of urgency was real. So were the desire to regain control immediately, the attraction of a quick solution, the discomfort of admitting uncertainty and the impulse to identify someone responsible. The exercise did not reproduce the full intensity of a real incident, but it exposed habits that a real incident would place under far greater pressure.

For this reason, I began to see tabletop exercises as something more than a test of plans and procedures. They can also function as an organisational form of premeditatio malorum: a structured encounter with possible adversity before that adversity arrives. Seneca observes that adversity anticipated and considered in advance strikes less violently when it comes, because the mind has already learned to confront it (Moral Letters 76.33–35).

For Seneca, considering difficulties in advance does not mean living in expectation of the worst. It means reducing the force of surprise and preparing oneself to face adversity with greater steadiness (Seneca, Moral Letters 91.3–8).

A tabletop exercise applies an analogous principle to a group. It does not prepare for the exact crisis — the next incident will almost certainly differ from the scenario — but for conditions that tend to recur: incomplete information, time pressure, disagreement, public scrutiny, distributed responsibilities and the need to act before certainty is available.

What was really being tested?

The visible subject of the exercise was a compromised social-media account. Its deeper subject was judgment. As one of the leading experts in cybersecurity, Bruce Schneier observes, real security and perceived security do not always coincide, partly because risk assessment is influenced by fast and often automatic heuristics; training judgment therefore also means learning to recognise them before they become decisions (Schneier, 2008).

At the outset, ACME knew only that inappropriate posts had appeared. Almost immediately, facts attracted interpretations: the company was under attack; its reputation was collapsing; someone inside the organisation might be responsible. Some of these interpretations might eventually have proved correct.

The problem was not that people formed impressions. We cannot avoid doing so. The problem was the speed with which an impression could be promoted into a conclusion.

Epictetus famously writes that human beings are not disturbed simply by events, but by the judgments they form about them. This does not mean that a cyber incident is imaginary, or that changing one’s attitude is enough to recover an account. It means that an act of interpretation stands between the event and our response. Under pressure, that interpretation can become difficult to see because it presents itself as though it were the event itself (Epictetus, Enchiridion 5; Marcus Aurelius, Meditations 8.47).

‘The password has been changed’ is a fact. ‘We have lost control of everything’ is an interpretation.

‘An employee may have disclosed the password’ is a possibility. ‘An employee has betrayed us’ is a judgment.

‘A journalist is asking questions’ is a fact. ‘Our reputation is destroyed’ is a prediction.

The Stoic discipline begins by preserving these distinctions. Epictetus observes that the mind tends to assent to what appears true, reject what appears false and suspend judgment in the face of what it recognises as uncertain (Discourses 1.28). For this reason, he urges us not to be carried away by the force of the first impression, but to pause and examine it before following it (Discourses 2.18). In a crisis team, this principle becomes a series of practical questions:

What do we know?

How do we know it?

What are we merely assuming?

Which decision cannot wait?

What can remain undecided until we have better evidence?

Suspending assent does not mean refusing to act. ACME could not wait for perfect knowledge before contacting the platform, securing its other accounts or preparing a public response. The difficulty was to act decisively without pretending to know more than the evidence allowed.

The twenty-four-hour wait introduced a second Stoic problem: the boundary between choice and outcome. At the beginning of the Enchiridion, Epictetus distinguishes between what is up to us and what is not up to us (Epictetus, Enchiridion 1). In organisational life, this distinction rarely maps neatly onto ‘controllable’ and ‘uncontrollable’. A team can influence an outcome without being able to guarantee it.

ACME could choose the quality of its response: whom to contact, what to document, how to protect other accounts, how precisely to communicate and how fairly to treat employees. It could not determine when the platform would restore access, how widely the posts would spread or how every client would react.

This distinction does not justify passivity. It directs effort. It prevents people from neglecting the quality of their own choices while exhausting themselves in an attempt to dominate outcomes they cannot command.

The ransom demand introduced a third test. Stoicism is sometimes reduced to remaining calm, but calm is not its highest aim. A calm person can still act dishonestly, unjustly or foolishly. The central question is not whether a decision reduces anxiety, but whether it expresses practical wisdom, justice, courage and self-control.

The demand exploited impatience and fear. It offered immediate relief in exchange for a decision with uncertain consequences. In this context, temperance meant resisting the impulse to purchase emotional comfort and asking which course of action would still be justifiable once the immediate pressure had passed.

The suspicion surrounding an employee tested justice. A crisis team wants to understand causes, and leaders often feel pressure to demonstrate that they are in control. Naming a culprit can satisfy both needs. But the possibility of guilt is not proof of guilt. Justice requires the organisation to investigate without allowing fear to determine the outcome in advance.

Finally, the journalist’s telephone call tested truthfulness. Marcus Aurelius offers a severe but useful instruction: if something is not right, do not do it; if it is not true, do not say it (Meditations 12.17).

In public communication, the temptation is often to say whatever will produce the desired reaction. The Stoic standard is different. Say only what can be supported. Acknowledge what remains unknown. Correct the narrative when the facts change.

This approach may not produce the most reassuring statement. It produces the most defensible one.

Premeditation Without Panic

There is an important risk in comparing tabletop exercises with premeditatio malorum. Preparation for adversity can become anxiety about adversity. Marcus Aurelius uses the image of a rocky promontory that remains firm while the waves break against it: the challenge is not to avoid pressure, but not to be overwhelmed by it (Meditations 4.49). An organisation can spend so much time imagining attacks, failures and betrayals that a possibility begins to feel like an imminent reality.

Seneca warns us against suffering before it is necessary and against suffering because of events that may never happen (Seneca, Moral Letters 13.4–12). Stoic preparation therefore does not mean catastrophising. It is not an attempt to populate the future with every conceivable disaster. Its purpose is to reduce the tyranny of surprise and improve the quality of the response.

A well-designed exercise creates pressure without claiming to predict the future. It gives participants a safe opportunity to discover where responsibilities are unclear, where a decision depends too heavily on one absent individual, where communication moves faster than the evidence and where the need for certainty becomes an obstacle to action.

The most valuable part often comes after the scenario ends.

In the debrief, the aim is not merely to determine whether participants chose the ‘correct’ procedure. It is to make visible what happened to their judgment as the exercise progressed.

Which assumption became a fact too quickly?

Which decision was driven mainly by the desire to make the discomfort stop?

Where did the team spend energy trying to control an outcome instead of improving its own actions?

When did the investigation begin to turn into the attribution of blame?

What was the organisation prepared to state publicly without sufficient evidence?

These questions do not belong exclusively to cybersecurity: they form part of a pattern common to incident management.

Bad news arrives. Information is incomplete. Time seems short. One course of action promises immediate relief. Someone appears responsible. Other people demand an answer.

The details change. The demands placed on judgment do not.

Before Next Sunday Morning

The purpose of the ACME exercise was not to rehearse a script that could later be followed mechanically. No real crisis would unfold in exactly the same sequence. The purpose was to allow the organisation to encounter its own tendencies before those tendencies produced real consequences.

A plan can specify who must be called. It cannot guarantee that people will distinguish evidence from fear.

A communications template can provide useful language. It cannot guarantee that leaders will resist the temptation to say more than they know.

A security control can make it harder to take over an account. It cannot decide whether a suspected employee will be treated justly.

This is where judgment enters the picture.

Stoic philosophy does not replace technical expertise, crisis plans or professional experience. Rather, it helps us practise what these tools cannot do on our behalf: suspend assent when the evidence is insufficient, focus on the choices that remain in our hands, resist the false relief of an immediate solution, investigate without creating scapegoats and speak within the limits of the truth.

Through repeated practice, these dispositions can become more readily available precisely when pressure makes them harder to exercise.

The exercise staged an imaginary crisis, but it revealed something real: how people respond to uncertainty when time contracts, information is incomplete and the need for an answer grows.

The next crisis would not follow that scenario. That was not the point.

The point was that, when adversity eventually arrived, their judgment would not be encountering it for the first time. These reflections did not begin as a theoretical application of Stoicism; they emerged from an exercise I actually conducted and from the decisions I observed there.

Conclusion

Conducting this kind of tabletop exercise, simulating a cyber crisis with managers and giving them a perspective that we might describe as “Stoic attitude”, has taught me a few things that I would like to share.

The first is that, as a well-known aphorism puts it, “If the only tool you have is a hammer, you will see every problem as a nail” (Abraham Maslow).

In cybersecurity, many people tend towards the hyper-specialisation of technical skills, neglecting other abilities that we might describe as more humanistic. University curricula also often encourage this approach. It is not my intention to diminish the role of technical expertise and incident-management procedures: they remain fundamental. What is certain, however, is that if, alongside the hammer of the aphorism, we add a set of Stoic resources to our toolbox, crisis management takes on a different perspective and, in my view, a better one.

At the end of the exercise, the head of IT services shook my hand and said with a smile: “Message received loud and clear: more Stoicism, less hardware.” In response, as a result of the exercise, I printed out for him a short reflection prepared specifically for him, centred on a Stoic principle that I consider particularly relevant to the management of a cyber incident. It reads as follows:

“Do little,” he says, “if you wish always to be serene.” Would it not be better to do what is necessary, and what the reason of a being social by nature prescribes, and in the way in which it prescribes it? For this brings not only the serenity that comes from acting according to virtue, but also that which comes from doing little. For if one eliminates most of our words and actions as unnecessary, one will have more free time and a more secure tranquillity. Therefore, in every single circumstance, one must remind oneself: “But will this not be something unnecessary?” And one must eliminate not only unnecessary actions, but also unnecessary impressions; for in this way no superfluous actions will follow from them either.”

(Marcus Aurelius, Meditations 4.24)

The second thing I have learnt is that all of us experience crises or unexpected events: an illness, the loss of a job, to mention just a few examples. Although, at first sight, these crises may seem far removed from the development of a cyber incident, their management can in fact be regarded as similar. Here too, having a set of Stoic tools in our toolbox can make a difference in two fundamental ways. First, it helps us maintain a Stoic attitude: distinguishing what has actually happened from the judgments and fears we add to it. Second, it gives us a practical capacity to deal with the problem itself: to identify what requires action, go straight to the point, and avoid emotional spirals or reactions that are disproportionate to the facts.

“Say nothing to yourself beyond what the immediate representations announce to you. It has been reported to you that so-and-so speaks ill of you. This has been reported to you, not that you have suffered harm from it. I see that the child is ill. I see this, I do not see that the child is in danger. Thus always remain with the first representations, without adding anything of your own from within, and nothing will happen to you; better: add something, if you wish, but as one who knows how to recognize each single event in the cosmos.”

(Marcus Aurelius, Meditations 8.49)

This distinction between what happens and what we add to what happens lies at the heart of the Stoic attitude described throughout this paper. In both a cyber incident and a personal crisis, it helps us separate facts from fears and assumptions, so that we can identify what actually requires action. By remaining close to the facts, we are better able to respond appropriately, without allowing unnecessary emotional reactions to complicate the crisis further.

Editor’s Note: This piece was translated from Italian using DeepL. The author confirms that AI was not used for idea generation, research, conceptual framework, argumentation, or substantive content.


Essential References

Epictetus. The Discourses of Epictetus, with the Encheiridion and Fragments. Translated by George Long. London: George Bell and Sons, 1887. Digital edition, Scaife Viewer, Perseus Digital Library, Tufts University. Accessed 08 August 2026.

Epitteto. Il manuale. Translated by Giacomo Leopardi; with selections from the Discourses and fragments of Musonius, edited by Nicola Festa. Milan: Istituto Editoriale Italiano, 1913.

Marc Aurel. Selbstbetrachtungen. Translated from the Latin by Carl Cless. Cologne: Anaconda Verlag, 2018.

Schneier, Bruce. “The Psychology of Security.” In Progress in Cryptology - AFRICACRYPT 2008, Lecture Notes in Computer Science, vol. 5023, pp. 50-79. Springer, 2008.

Seneca. Ad Lucilium Epistulae Morales. With an English translation by Richard M. Gummere. Vols. I-II. London: William Heinemann; Cambridge, MA: Harvard University Press, 1917-1920. Digital facsimile, Internet Archive, University of Toronto.

Coyote vs. Acme. “Coyote vs. ACME | Official Trailer.” YouTube, 22 April 2026. Ketchup Entertainment.


About the Author

Paolo Gasperi holds a degree in Economics, with a thesis on the civil-law aspects of software. He later undertook PhD studies in Software Engineering, working on open-source solutions, although he did not complete the final dissertation defence. He has held various roles in cybersecurity, primarily as a consultant, and for many years held the Certified Information Security Manager (CISM) and Certified Data Privacy Solutions Engineer (CDPSE) certifications. In 2023, he received the “Special Jury Mention” in the “Innovation Speed Date” competition, organised by the Swiss association ATED, for the project “Stoicism for Cyber Security Managers”.


Thanks for reading Stoicism Today! This post is public so feel free to share it.

Share


Photo credit: Vitaly Gariev