PREPARING FOR THE INEVITABLE Board & ELT Cybersecurity Briefing
Home Self-Assessment Download PPTX Projects

PREPARING FOR THE INEVITABLE

What boards and executive leadership need to understand and prepare for — before a cyber incident, not after.

Grounded in first-hand experience leading Business & Technical Information Security Officer (BISO / TISO) teams through a major 2025 retail-sector cybersecurity incident and supporting business continuity throughout the response.

INDEPENDENT CYBERSECURITY ADVISORY  ·  BOARD & ELT BRIEFING  ·  CONFIDENTIAL

Contact: consult@chatcpt.pro

Why this conversation, why now

This Is Not a Hypothetical Conversation

“IF it happens to us”

The comfortable assumption

Most boards plan around this mindset: security as hygiene, budgeted modestly, treated as someone else's operational concern.

“WHEN it happens to us”

The realistic planning premise

Professional security and continuity functions plan investment, response structure and culture around this certainty, not around hope.

“IT MAY ALREADY be happening”

The uncomfortable likelihood

Not scaremongering — it reflects how most real incidents are actually discovered: an alert, a complaint, a ransom note, systems failing. The board is very rarely first to know.

Most boards plan around the first mindset, brief occasionally on the second, and rarely confront the third. Tap a card above for more.

What this actually requires

Know what to do.
Know when to do it.
Know how to do it.
Don't make it easy for them.
Don't be a bigger impact than the threat actor.

Resetting four assumptions

Four Beliefs That Leave Organisations Exposed

Tap a card to see why it doesn't hold up.

“It won't happen to us.”

Tap to reveal →

It is likely already happening, in some form — you simply have not detected it yet.

“Our defences will stop it.”

Tap to reveal →

Defence-in-depth lowers the odds; it does not guarantee prevention. Off-the-shelf attack tooling has cut the skill and effort a threat actor needs to succeed.

“The impact will stay inside IT.”

Tap to reveal →

Real incidents halt revenue, fulfilment, production and customer trust — for weeks, not hours.

“We'll know how to react.”

Tap to reveal →

Without a tested plan and pre-agreed decision rights, the first 48 hours are usually chaos, not command.
The question underneath all four: is your risk position a true representation of reality — do you actually know all of your issues and vulnerabilities, including those held by your suppliers and service providers, or only the ones you have already found?

A changed threat calculus

The Target Logic Has Changed

Old assumption 2025 reality

THE OLD ASSUMPTION

“State-linked threats target energy grids, defence systems and financial infrastructure. That's not us.”

Energy · Defence · Finance · Government

THE 2025 REALITY

Retail is one of the fastest ways to hit an entire population's daily life, all at once, visibly.

Empty shelves, failed deliveries and broken payments are immediate, universal and impossible to ignore — precisely why state-sponsored and state-motivated actors now treat consumer-facing sectors as strategic targets, not just financially-motivated criminals do.

Retail is no longer a bystander in geopolitical conflict — and boards are typically the last in the organisation to know an actor is already inside.

Case in point — retail

When It Isn't Contained to IT

TRADE: Major retail-sector organisation  ·  WHEN: 2025

Ransomware deployed
Online & fulfilment operations down
Phased recovery
0of disrupted online ordering and fulfilment operations
0of wider business disruption before operations fully normalised
Hundreds of millionsin estimated operating-profit impact, in local currency

Root cause pattern: social engineering of help-desk / identity-recovery processes to bypass technical controls entirely — not a sophisticated exploit. One of several major retailers hit within the same short window, by related actors.

A different lens on incident response

Clearing a Building, Clearing a Network

The stages of an active-shooter building clearance map almost exactly onto a cyber incident — because both are about controlling an unknown threat inside your own perimeter.

1
SEE
Get eyes on the scene. Work out where the threat is and how far it's spread.
2
CORDON
Place a cordon. Move to secure, offline comms the threat can't hear.
3
CLEAR
Clear room by room — vet every identity, check for booby traps.
4
CLOSE IN
Quietly tighten the hard perimeter, without tipping off the threat.
5
STAND DOWN
Remove the threat. Let people back in slowly, checking as you go.
The hardest part of both processes is the same: holding the perimeter against people who want back in. Staff and business teams who don't understand the risk or the procedure will push to reopen the room, or reconnect the system, before it's safe — giving in wastes the time and effort already spent, and endangers everyone still inside.

The framework for this briefing

Resilience Rests on Three Pillars

ORGANISATIONAL RESILIENCE
Investment gap
DEFENCE
RESPONSE
CULTURE

Most organisations don't deliberately over-fund Defence. They fund it to a level that matches their own understanding of risk and threat likelihood — an understanding that, per the previous slides, is usually too low. Response and Culture are rarely part of that risk calculus at all, so they receive whatever is left over. Often, that is very little.

Deep dives into each pillar — coming soon.

Reframing the goal

The Goal Isn't a Wall. It's a Smaller Blast Radius.

UNCONTAINED — full business impact

CONTAINED & SLOWED — limited, manageable impact

Once an actor is inside, success is no longer measured by "did we stop it." It's measured by how much you contained, and how fast.

Know your environment: know the minimum you need to keep operating, and exactly what that takes.
Act on intel, not guesswork — build real-time visibility into your environment, and into your IR and BC plans.

Pillar 1 of 3 — Defence

Defence-in-Depth: Necessary, Not Sufficient

Perimeter & network
Identity & access
Endpoint & device
Application & data
The asset that matters

Each layer slows an actor down and shrinks the blast radius. None of them, alone or together, is a guarantee. Tap a layer for detail.

KNOW YOUR BUSINESS

Layers of technical control only protect what you know to point them at.

FunctionsProcessesServicesSuppliersPeopleAssets

What really matters in your business environment — mapped and understood, not assumed.

Pillar 2 of 3 — Response

Incident Response Is a Structure, Not a Folder on a Drive

Sector ISACs / peer groups Industry peers IR retainer

Your IR team

Tap a ring to see what it represents — support during a real incident very often comes from further out than people expect.

ISAC = Information Sharing and Analysis Center — a sector-specific, often not-for-profit body through which organisations share threat intelligence with peers, sometimes including direct competitors.

DECIDE THIS BEFORE YOU NEED IT

Named owner for isolating or taking a system offline — and they know it's them
A pre-agreed ransom-payment stance, decided outside the heat of the moment
A separate, low-visibility channel to coordinate IR & leadership if the corporate environment itself is compromised
A roster of people with IR-useful skills outside their normal role — “cooks become firefighters”
Tabletop exercises (TTXs), run regularly — not once, then filed away
Authorised voices for regulators, media and customers

Support often comes from unexpected places — even competitors become allies when a shared threat actor, or shared customer trust, is at stake.

Pillar 2 of 3 — Response

The Comms Plan Is the Highest-Leverage IR Asset

Uncoordinated, slow or contradictory communication can cause more financial, reputational and time damage than the threat actor's original action.

Who actually owns this: the comms plan is not solely a PR or marketing document. It needs named, authorised owners across IR, legal, HR, customer service and executive leadership — each accountable for their own audience above, and for knowing when to escalate to the others.

Employees Recovery teams Business leads System operators Customers Regulators Media Suppliers Investors /Board COMMS PLAN

Tap an audience above to see what it needs from the plan.

Pillar 3 of 3 — Culture

Culture Decides Whether the Other Pillars Work

WHAT BREAKS IT
Risk appetite quietly erodes whenever security competes with speed-to-revenue
“We've always done it this way” / “it's been fine for 10 years”
Security engaged late — treated as a gate, not a partner
People bypass controls or under-report rather than engage security
Information is protected and siloed instead of shared and escalated
WHAT FIXES IT
Leadership visibly protects the agreed risk appetite, even under commercial pressure
Security is resourced and timed into projects from day one
Escalation is fast and blameless — reporting a problem is rewarded, not punished
Day-to-day secure behaviour is modelled from the top
InfoSec is embedded in every function, at every level — not a separate silo you escalate to

What this actually costs

This Requires Sustained, Not One-Off, Investment

Retail benchmark 2024 (0.57%)
Retail benchmark 2025 (0.75%)
Cross-industry avg. (0.69%)
Recommended target (1.5%)

Sources: RH-ISAC, 2025 retail-sector benchmarking; IANS Research / Artico Search, cross-industry security-spend benchmark. Directional planning anchor only — size the real figure with your CISO and finance function.

Roughly double current retail-sector spend — sustained, year over year, as a standing cost of doing business.

Retail is a strategic target now (slide 4), and this budget must fund all three pillars — not just Defence tooling.

This investment devalues quickly: defences work, perceived risk falls, and budget gets quietly cut back — until the gap is wide enough to be hit. Spend has to keep rising just to hold pace with the threat.

The building blocks, in priority order

Get These Foundations in Place, First

These are the minimum foundations every organisation needs — listed in the order to build them. Each layer depends on the one below it; skipping ahead is how the exercise at the bottom finds nothing useful. Track your own organisation's progress below — saved privately in this browser only.

0 / 6 in place
1. Comms Plan
Pre-agreed channels and messaging for staff, customers, regulators and press — decided before you need them.
2. Data & Process Map (built on CMDB)
Know what you run, where data lives, and how systems and processes connect to each other.
3. Business Continuity Plan (BCP)
How the business keeps operating, in some form, while systems are down.
4. Disaster Recovery Plan (supports BCP)
How you technically restore the systems and data the BCP assumes will come back.
5. Incident Response Plan (for varied threat types)
The playbook for detecting, containing and eradicating an active threat, tailored to how you're likely to be attacked.
6. Cyber Incident Tabletop Exercise
Tests the incident response plan — and every layer beneath it — across the whole business, not just IT.

Closing

What This Means for You, Starting Now

1
Accept the premise: compromise is likely, and may already be underway — plan from there, not from hope.
2
Commit sustained, multi-year budget across Defence, Response and Culture — not a single project.
3
Get a tested, owned incident comms plan in place within the next two quarters.
4
Run a leadership-level tabletop exercise — including how you'd talk to press, regulators and customers.
5
Map, today, who has authority to make the hard calls during an incident, before you need it.
6
Model the culture from the top — what you protect under pressure is what your organisation will actually do.

None of this prevents the incident.
All of it determines how much it costs you when it happens.

INDEPENDENT CYBERSECURITY ADVISORY  ·  consult@chatcpt.pro

Before you move on

Answer These Honestly — to Yourself, Not a Room

This is a private, honest-reflection checklist — not part of the main 15-section flow, not a group exercise, and not a compliance checklist to score. Your answers are saved only in this browser, on this device, and are never sent anywhere.
Could you name, right now, who has the authority to take a system offline during an incident?
When was your incident comms plan last tested — and did anyone outside IT/security see it?
When did your organisation last say no to a business initiative on security grounds — and what happened next?
Do you know, in currency terms, what one week of a major system outage would actually cost you?
Has your organisation built any relationship — formal or informal — it could call on for help during a crisis?
If told today that a threat actor had been inside your systems for months, would that genuinely surprise you?

Tick each box once you've genuinely sat with the question. If any answer causes discomfort, that is the signal to revisit that pillar in more depth, and to raise it as a specific, named agenda item with your CISO or security leadership.