The Black Belt Problem: When Confidence Gets You Hurt

For close to twenty years, I trained and taught martial arts. Judo, jujitsu, and even kung fu for a while. I competed, I taught classes, I spent thousands of hours drilling techniques that were supposed to prepare people for violence. And yet the handful of times I found myself in genuine confrontations, I barely used any of it.

Watch the whole recording here.

I defaulted to the simplest thing available almost every time. Basic strikes. Simple movement. Instinctive reactions. Once because I was wearing dress shoes and knew I’d lose my footing if I tried anything complicated. Another time because I was on a packed train and there simply wasn’t room to do anything else. All those years of throws, joint locks, groundwork, and technical precision disappeared the moment reality stopped behaving like training.

For a long time, I treated that as bad luck or personal failure. Eventually, though, I had to ask myself a harder question. What if the problem wasn’t me? What if I’d spent close to twenty years preparing for a version of violence that barely exists outside controlled environments?

That question changed everything for me.

I realised most traditional training environments looked nothing like the situations people actually face. You’re barefoot on soft mats. Your training partner attacks the way you expect them to. They stop when something goes wrong. Nobody is swearing at you, deceiving you, intimidating you, or trying to create panic. The environment is cooperative, predictable, and controlled.

Real violence is none of those things.

Real aggression is sudden. Fast. Emotional. Confusing. It happens in awkward spaces, on slippery surfaces, with fear and adrenaline involved. The person attacking you does not stop because your technique failed. And the more I looked at it honestly, the more I realised I’d built confidence in an environment that had never properly tested competence.

That led me back to being a student again. I started training in reality based self-defence systems and immediately saw the difference. Instead of hundreds of techniques, there were a small number of reliable defaults built around what the body naturally does under stress. Instead of trying to override instinctive reactions, the training worked with them.

One of the simplest examples was the flinch response. If somebody suddenly swings at you, your body reacts before your brain catches up. Your hands come up. You protect yourself instinctively. Traditional systems often try to suppress that response and replace it with technically correct movement. The reality based systems accepted that the flinch is going to happen anyway, so they built responses on top of it instead.

That sounds small, but it changes everything.

It also highlighted a massive blind spot in most self-defence training. We spent years teaching people what to do after a confrontation became physical, while barely spending time on everything that happens beforehand. Awareness. Avoidance. Reading behaviour. Trusting instinct. Recognising deception. Understanding how predators actually select targets.

The reality is that most personal safety has very little to do with fighting ability. It’s about recognising risk early enough that you never need to fight in the first place.

And that’s where the parallel with business security became impossible for me to ignore.

The same mistake I’d made in martial arts was happening everywhere in cybersecurity.

Most businesses have antivirus software. Firewalls. Compliance frameworks. Annual training videos everyone clicks through half asleep. They follow best practice because that’s what everyone else is doing. The problem is that following best practice can create the illusion of safety without ever testing whether it actually matches the threat you face.

I’ve spent years responding to breaches. Ransomware attacks, insider threats, financial theft, data breaches, business shutdowns. I’ve sat with leadership teams at two in the morning trying to work out whether their business is going to survive the week. And what I’ve learned is that the technical failure is rarely the real issue.

The deeper problem is usually false confidence.

Businesses often invest heavily in looking secure instead of understanding what they’re actually defending against. They inherit processes they never question. They buy the same tools as everyone else. They follow compliance checklists without ever asking who is targeting them, why they would be targeted, or how those attacks are most likely to happen.

It’s the business equivalent of a black belt who has only ever sparred in a controlled dojo.

The confidence is real. The competence just hasn’t survived contact with reality yet.

One of the biggest mindset shifts for me came from understanding how much real world security depends on awareness and avoidance rather than response. In self-defence, most violence follows patterns. Opportunistic attackers choose environments that limit your ability to react. They look for distraction, isolation, uncertainty, intoxication, hesitation. They use deception to close distance before you realise there’s danger.

Once you understand that, your behaviour changes. You choose where you park. You notice exits. You trust your gut feeling instead of overriding it to avoid social discomfort.

Business security works the same way.

Most organisations never look beyond generic threats. They’ve had phishing emails arrive, so they tell staff not to click links and assume that’s enough. But very few businesses ask deeper questions. Who is actually targeting our industry? What are they looking for? What tactics are they using against organisations like ours? Are we even the primary target, or are we simply the easiest way into someone larger?

I’ve seen small businesses breached simply because they provided access to bigger organisations further up the chain. They thought they were too small to matter, right up until they became the weak point somebody else exploited.

That’s why threat intelligence matters. Not in the Hollywood sense. Just understanding your actual exposure instead of relying on generic assumptions.

Another thing I’ve learned through both self-defence and cybersecurity is that appearance can be deceptive in useful ways too. In self-defence, there’s a posture that looks passive but actually places you in a position to react immediately if needed. Open hands. Calm body language. Non-threatening on the surface, but prepared underneath.

Cybersecurity has equivalents. Systems designed to observe attackers without exposing critical assets. Layers that create visibility instead of simply pretending prevention is perfect. Because eventually, somebody gets through. The question is whether you notice early enough to respond effectively.

That’s the uncomfortable part many businesses avoid. We like the idea that good preparation guarantees safety. It doesn’t. Preparation reduces risk. Awareness reduces exposure. Testing assumptions reduces blind spots. But confidence alone protects nobody.

One of the analogies I use often is the difference between somebody selling sprinklers and an arson investigator. The sprinkler salesperson believes in the product. The arson investigator understands how fires actually start. The people who truly understand prevention are usually the people who’ve seen failure up close.

That’s true in cybersecurity. It’s true in self-defence. Honestly, I think it’s true in leadership generally.

The biggest lesson I’ve taken from all of this is that growth comes from testing assumptions, not defending them. I had to stop protecting my confidence and start asking whether my preparation would survive contact with the real thing. That question changed how I train people, how I run my businesses, and how I think about risk altogether.

And I think it’s a useful question for every business owner to sit with.

Are the systems, strategies, and assumptions you rely on actually built for the threats you face, or for the comfortable version of those threats?

Because those two things are rarely the same.

If this struck a chord, I’d encourage you to keep asking the uncomfortable questions. The useful ones usually are uncomfortable at first. And if you want to continue the conversation, come along to the Masterclass or grab me for a coffee sometime. I’m always happy to talk about the gap between feeling secure and actually being secure.

Grant Haroway on LinkedIn

Share