What does the proverb mean — and why does it often miss risk management?
“Es wird heißer gekocht als gegessen” is the German way of saying the announcement is worse than reality: people threaten more than they deliver. Applied to risk management, many hear: that is overcooked. That is scare tactics.
The answer is no. Not because nothing bad can happen — because the proverb sits in the wrong place. Knowing your risks is not cooking for fear. It is deciding, in peace, what you protect, what you carry and what you take on deliberately.
A second reading is useful in the kitchen: cooks often season more strongly because the plate will taste milder. In risk management, scenarios may be sharper than Tuesday morning. That is not drama. That is preparation so Tuesday stays calm.
Is risk management scare tactics or clarity?
Scare tactics freeze action. Clarity creates it. After a serious risk analysis, leadership and team know what to do — before something happens.
In consulting we hear this often: the overview of the business gets better, not worse. Longer-term planning becomes usable. Knowing the risks does not steal courage — it steals blindness. More fear than before? Usually no. What remains is the sober insight that some areas need work. Those steps can still be taken while there is time.
That is why risk management matters: not a traffic light and a binder, but euros, probability and a short list that actually steers decisions. What risk management is remains the base — this article asks what early prevention is worth.
What changes when you know the risks before something happens?
Three shifts appear once risks are named and roughly valued in euros.
- Time: measures are designed in calm, not at night after the incident.
- Priority: not everything is equal. A special tool with a three-week lead time can be more critical than the visible warehouse.
- Opportunity: if you know the weak spots, you also see where you can carry risk — a new market, a new tool, a new role.
Anonymised from practice: after the joint work, one founder described overview, not more fear. Longer-term planning became tangible. Knowing the risks helped her understand the firm and see potential. She also gave clear feedback: materials and task structures need to be clearer. Both belong together. Benefit without usability stays theory.
Not X — but Y: not more documents. Less surprise.
What do studies say about prevention versus damage?
Market figures are not your P&L. They do show that “nothing has happened yet” is not proof of safety.
According to Bitkom Wirtschaftsschutz 2025, German companies lost €289.2 billion to theft, sabotage and industrial espionage. 70 percent of that — €202.4 billion — came from cyber attacks. 87 percent of respondents were affected or suspected attacks. The sample is firms with at least ten staff and €1 million turnover — mid-market, not every solo trader.
The IBM Cost of a Data Breach Report 2026 puts the global average leak at USD 4.99 million. Germany sits at USD 4.93 million. The sample is large-enterprise heavy; it is not a typical craft business. The cost mix is still instructive: detection, escalation and lost business dominate — costs after the event.
The German BSI 2025 IT security report states that around 80 percent of reported attacks, including ransomware, hit SMEs. 950 ransomware reports, 72 percent with data leaks or the threat of them. Weak protection often makes a firm the more attractive target — not the group with a large defence centre.
In the Allianz Risk Barometer 2026, cyber incidents remain the top perceived business risk for the fifth year (42 percent of mentions) — including smaller companies under USD 100 million revenue. Artificial intelligence rises to second; business interruption to third. Interruption is often the consequence of other risks, not a stand-alone topic.
For cyber attacks on SMEs, prevention and an emergency plan belong together. A file nobody has practised is decoration.
What does “nothing has happened yet” cost?
It costs optionality. While nothing visible breaks, prevention feels like a luxury. Once something breaks, time, nerves and often cash are missing at once.
| Dimension | After the damage | With early clarity |
|---|---|---|
| Decision | under pressure, with gaps | in calm, with named scenarios |
| Cost | detection, downtime, reputation, legal follow-on | a few prioritised measures |
| Team | blame or silence | a shared language for the top risks |
| Leadership | reacts | steers |
This is not a promise that nothing will happen. Risk never hits zero. The aim is to make it smaller, smoother and steerable — direction over fake precision, as in the method.
Why do risk management while things are going well?
Because that is when the calm exists that good work needs. In a crisis the kitchen really is hot: customers wait, insurers ask for records, the team looks at leadership.
Prevention in a quiet phase means: run scenarios, clarify roles, test backups, note supplier alternatives, inventory data protection and AI use. It looks unspectacular. It is the difference between “we have it in writing” and “we can steer”.
Germany’s StaRUG requires directors, among other things, to detect developments that could threaten going concern. That is not a sales line and not legal advice. It is the statutory hint that early warning belongs to leadership — not only to an insolvency practitioner.
What is the value of involving employees in decisions?
Awareness training is useful and often mandatory. It does not replace a say in decisions.
ISO 31000 lists inclusive as a principle: involve the right people in time. Whoever writes the order, runs the machine or holds the customer access sees breaks first.
Amy Edmondson describes psychological safety as the condition under which people raise risks and errors. Without it the early-warning system stays mute — not because nobody saw anything, but because nobody was allowed to say it.
In high reliability organisations, “deference to expertise” applies: in the critical moment the person who knows the process best counts, not automatically the highest title.
Three practical rules:
- Not everyone must know everything — but everyone must know enough to act in the first minutes.
- Top-three risks must sit spoken in the team, not only in a file.
- Anyone who raises a risk must not be treated as a nuisance. Otherwise the system learns silence.
More in the articles on a risk-aware culture and on why employees make risky decisions.
Take risks deliberately, or be caught cold?
There is no growth without risk. The error is rarely that a risk is carried. The error is carrying it unnamed.
Taking risks consciously means: identify, assess, cushion, prepare — then decide. You can still choose a market, a person or a tool while uncertainty remains, because the residual risk is known.
Being caught cold means: the scenario was thinkable, but nobody put it on the table. Then it really does cook hot. And then the proverb that it will not be eaten that hot helps nobody.
Where can banal compliance gaps become existential?
In places that look small in daily work: no processing inventory, an unclear AI chatbot facing customers, a dataset with no deletion concept.
GDPR allows fines up to €20 million or 4 percent of worldwide annual turnover, whichever is higher. The AI Act sanctions prohibited practices with up to €35 million or 7 percent; other duty breaches with up to €15 million or 3 percent. For SMEs and start-ups the AI Act uses the lower of the sum and the percentage.
These are ceilings, not a forecast for your firm. Whether and how a supervisor fines depends on the case. This paragraph is not legal advice. It explains why data protection and AI belong in a risk inventory, not in a drawer. Duties since August 2026 are set out in the article on the AI Act in Germany.
What is the first concrete step in an SME?
Four weeks, three risks, one language.
- Collect hazards without scoring them yet — with people from sales, production, finance and IT, not only from the board.
- Value roughly in euros: what would a realistic scenario cost — downtime, rework, penalties, lost trust?
- Pick three measures you can finish in the next four weeks. Not thirty.
- Speak the top three in the next stand-up. If nobody can explain them, the plan is not in the business yet.
If you do not want to moderate that internally, the mid-market path is under risk management for SMEs. The method stays the same: hazards before risks, direction over fake precision, people before systems.
Conclusion: do not cook hotter — see earlier
Is risk management cooked hotter than it is eaten? As a prejudice — scare tactics, inflated scenarios, fear as a business model — no. As craft — thinking scenarios sharper than a quiet Tuesday — yes, and that is the point.
The value of early prevention is clarity: knowing what to do before something happens; involving the people who see the day-to-day; carrying risks on purpose instead of suppressing them. The figures on cyber, downtime and regulation are not a horror story for the evening. They explain why the cheap moment is the one in which things still look fine.
Next Monday: three risks on one page, damage in euros, one action per risk. Then the proverb is answered — not in theory, but in the firm.
