PREPARING FOR THE INEVITABLE
What boards and executive leadership need to understand and prepare for — before a cyber incident, not after.
Grounded in first-hand experience leading Business & Technical Information Security Officer (BISO / TISO) teams through a major 2025 retail-sector cybersecurity incident and supporting business continuity throughout the response.
INDEPENDENT CYBERSECURITY ADVISORY · BOARD & ELT BRIEFING · CONFIDENTIAL
Contact: consult@chatcpt.pro
How to use this document: it is designed to be read standalone, without a live presenter — every slide's notes carry the full explanation, the reasoning behind it, and (where used) the source for any statistic. If you are presenting this to a group, these notes are written to double as talking points.
Anonymization approach used throughout this deck: real, public 2025 incidents inform the case studies and the argument, but no organisation is ever named. References are by trade/sector and by failure mode only. This is a deliberate choice, not an oversight — the goal is the pattern, not the company.
The core thesis of this briefing, stated plainly up front: (1) a threat actor gaining access and causing real harm is highly likely, and in many organisations is probably already happening in some form — you will likely be the last to know; (2) technical defence is only one third of the problem — incident response readiness and organisational culture matter at least as much; (3) this requires sustained, multi-year investment, not a one-off project, sized well above what most organisations — especially retail — currently spend.
This is written for a board/ELT audience: assume commercial and governance fluency, not technical depth. Everywhere a technical term appears, it is explained in the notes.
ELT = Executive Leadership Team. BISO = Business Information Security Officer. TISO = Technical Information Security Officer.
Why this conversation, why now
This Is Not a Hypothetical Conversation
“IF it happens to us”
The comfortable assumption
“WHEN it happens to us”
The realistic planning premise
“IT MAY ALREADY be happening”
The uncomfortable likelihood
Most boards plan around the first mindset, brief occasionally on the second, and rarely confront the third. Tap a card above for more.
What this actually requires
Purpose of this slide: reset the premise before any content is presented. Most boards operate, without saying so, on the first mindset — security is discussed as a hygiene topic, budgeted modestly, and treated as someone else's operational concern.
The realistic planning premise professional security and continuity functions use is the second: assume compromise will happen, and plan your investment, response structure and culture around that certainty rather than around hope.
The third and most uncomfortable framing — that a threat actor may already have access, right now, undetected — is not scaremongering. It reflects how most real incidents are actually discovered: not by the board being told in advance, but by an alert, a customer complaint, a ransom note, or systems failing, often after an actor has already been present for some time. The board is very rarely the first to know.
The five statements at the bottom are the operating principles the rest of this briefing is built around. The first three — know what, when and how to do it — are about readiness. The last two are about discipline under pressure: do not make the attacker's job easier through poor hygiene or panic, and do not let your own response cause more damage than the incident itself would have.
If presenting live: pause here. Ask the room, honestly, which of the three statements described their organisation's posture yesterday, before this briefing.
Resetting four assumptions
Four Beliefs That Leave Organisations Exposed
Tap a card to see why it doesn't hold up.
“It won't happen to us.”
Tap to reveal →
“Our defences will stop it.”
Tap to reveal →
“The impact will stay inside IT.”
Tap to reveal →
“We'll know how to react.”
Tap to reveal →
This slide exists to name, out loud, the four assumptions that most commonly keep boards and ELTs under-prepared. Each is addressed at more length elsewhere in the briefing; this slide is the anchor to return to.
1) "It won't happen to us" — addressed further on slide 4 (why retail specifically is now a target) and slide 5 (a real, anonymized case). No sector, size, or profile is a reliable exemption any more.
2) "Our defences will stop it" — addressed on slides 7-9. Defence is one of three pillars, not a guarantee. Ransomware-as-a-service, commodity phishing kits and off-the-shelf intrusion tooling mean a capable outcome no longer requires a highly skilled attacker. The more useful question is not "will we be breached" but "how small can we keep the damage when we are."
3) "The impact will stay inside IT" — addressed directly by the case vignette on slide 5, which shows weeks-long, board-level commercial impact, not a contained technical event.
4) "We'll know how to react" — addressed on slides 10-11 (incident response structure and the comms plan). Confidence without a tested plan and clear decision rights is usually false confidence — untested plans fail in the same ways untested code does.
The closing callout raises a fifth, underlying point: most risk registers are a record of what has already been found, not a true picture of what actually exists. This extends beyond your own walls — your risk position is only as strong as the suppliers and service providers who hold your data or connect into your environment, and they must be held to the same standard you hold yourselves to, not taken on trust.
If presenting live: ask which of the four the room finds least comfortable to hear. That is usually the one worth spending the most time on.
A changed threat calculus
The Target Logic Has Changed
THE OLD ASSUMPTION
“State-linked threats target energy grids, defence systems and financial infrastructure. That's not us.”
Energy · Defence · Finance · Government
THE 2025 REALITY
Retail is one of the fastest ways to hit an entire population's daily life, all at once, visibly.
Empty shelves, failed deliveries and broken payments are immediate, universal and impossible to ignore — precisely why state-sponsored and state-motivated actors now treat consumer-facing sectors as strategic targets, not just financially-motivated criminals do.
Retail is no longer a bystander in geopolitical conflict — and boards are typically the last in the organisation to know an actor is already inside.
This is one of the more important reframes in the whole briefing, and often the one boards find most surprising: retail, hospitality and other consumer-facing sectors are no longer "lower tier" targets that only attract opportunistic criminals.
The logic driving this: a state-sponsored or state-motivated actor seeking to demonstrate impact, apply pressure, or simply cause visible disruption to a country's population gets very little from breaching a well-defended, low-visibility piece of infrastructure the public never sees fail. Hitting a major retailer's ability to take payments, fulfil online orders or keep shelves stocked is immediate, front-page, and felt directly by ordinary people within hours. In several well-documented 2025 cases, the operational techniques used were shared across multiple, unrelated retail-sector victims within the same short window — evidence of a deliberate, repeatable playbook being run against the sector as a whole, not one-off opportunism.
The second point — boards being "last to know" — is a structural, not a competence, problem. Detection typically starts deep in IT/SOC tooling or with a third party long before it reaches board awareness. A useful, blunt board-level question: "if we were compromised right now, how many days would it take before this board was told, and by whom?" If nobody in the room can answer that with confidence, that is itself the gap to close.
Sources for context: public 2025 reporting on the wave of UK retail-sector ransomware attacks attributed to overlapping criminal collectives.
SOC = Security Operations Centre — the team and tooling that monitor for and triage security alerts.
Case in point — retail
When It Isn't Contained to IT
TRADE: Major retail-sector organisation · WHEN: 2025
Root cause pattern: social engineering of help-desk / identity-recovery processes to bypass technical controls entirely — not a sophisticated exploit. One of several major retailers hit within the same short window, by related actors.
This is a deliberately anonymized composite of a real, well-documented 2025 retail-sector ransomware incident, referenced by trade and failure mode only.
What happened, at a level appropriate for this audience: a threat actor obtained privileged access not through a technical vulnerability but by manipulating a human process — impersonating a legitimate employee to a help desk or identity-recovery workflow to reset credentials or bypass multi-factor authentication. Once inside, ransomware was deployed against core systems, forcing a shutdown of online ordering, click-and-collect and parts of the supply chain for an extended period measured in weeks, not hours or days.
The business impact was not an IT event, and it did not end when systems came back online: customers were unable to shop and warehouses unable to fulfil for around six weeks, but the wider business disruption ran for closer to twelve months in total, alongside reported impact to operating profit in the hundreds of millions. This incident occurred within a short window of several other major retailers experiencing similar attacks, using similar techniques — strong evidence of a deliberate, repeatable campaign against the sector, not an isolated failure by one company.
Why this matters: it directly disproves the myth that impact stays inside IT, and illustrates why identity and help-desk processes deserve as much security investment and testing as any firewall or endpoint tool.
A different lens on incident response
Clearing a Building, Clearing a Network
The stages of an active-shooter building clearance map almost exactly onto a cyber incident — because both are about controlling an unknown threat inside your own perimeter.
This slide is deliberately not a case study — it's a framework, offered as an analogy because it is the fastest way to make an unfamiliar process feel immediately familiar to a board audience.
Stage 1 (See): visibility — where the threat is, how it got in, and how far it has already spread. In cyber terms: detection and scoping.
Stage 2 (Cordon): sealing off the area and switching to communications the threat cannot listen in on. Digitally: isolating or segmenting affected systems and moving incident coordination to channels the attacker cannot read.
Stage 3 (Clear): clearing room by room, vetting every identity, checking for booby traps. Cyber equivalent: triaging system by system, re-verifying access and identity, hunting for hidden persistence.
Stage 4 (Close in): tightening the hard perimeter quietly, without alerting the threat, because a cornered actor who realises they are about to be evicted may lash out. Cyber equivalent: hardening and encircling access carefully before the final, visible step of removal.
Stage 5 (Stand down): re-entry begins slowly, with active validation at every step. Cyber equivalent: phased recovery — restoring and reconnecting systems in careful, tested stages.
The callout is, in practice, the hardest part of running either process for real: people not in the room where decisions are made rarely understand why it is taking so long, and push to get back in. Giving in before it is actually safe is exactly how a contained incident becomes an uncontained one.
If presenting live: ask the room who, in a real incident, would be the loudest voice demanding early re-entry — and whether that person currently has the authority to overrule the incident commander.
The framework for this briefing
Resilience Rests on Three Pillars
Most organisations don't deliberately over-fund Defence. They fund it to a level that matches their own understanding of risk and threat likelihood — an understanding that, per the previous slides, is usually too low. Response and Culture are rarely part of that risk calculus at all, so they receive whatever is left over. Often, that is very little.
Deep dives into each pillar — coming soon.
This slide introduces the organising framework for the rest of the briefing: three pillars — Defence, Response, Culture — that together hold up organisational resilience. Slides 8-9 cover Defence, 10-11 cover Response, 12 covers Culture.
The specific nuance intended here: the imbalance shown is not because organisations are irrationally obsessed with defence or deliberately neglecting the other two. It's because most risk assessments, board reporting and budget conversations are built around a threat model that itself understates likelihood and impact. Given that understated threat model, funding Defence to "a reasonable level" can look responsible on paper, while Response and Culture end up funded reactively, if at all.
The practical implication: fixing the imbalance does not start with cutting Defence spend. It starts with correcting the underlying threat model so that Response and Culture are recognised, budgeted and reported on with the same seriousness as Defence.
If presenting live: ask the room how their own last risk or budget conversation weighted these three areas, and whether Response and Culture were even discussed as investment categories.
Reframing the goal
The Goal Isn't a Wall. It's a Smaller Blast Radius.
UNCONTAINED — full business impact
CONTAINED & SLOWED — limited, manageable impact
Once an actor is inside, success is no longer measured by "did we stop it." It's measured by how much you contained, and how fast.
This slide carries one of the key reframes of this briefing: prevention will fail eventually. Once that is accepted, the more useful question stops being "how do we stop every attack" and becomes "how small can we make the damage when one succeeds, and how quickly can we shrink it."
The two diagrams: the left ("uncontained") shows a breach point whose consequences spread outward, unchecked, to the edge of the business. The right ("contained and slowed") shows the same starting breach point, but with rings that stop expanding early — the actor still got in, but detection, isolation, and a practiced response held the damage to a fraction of what it could have been.
This ties the three pillars together: Defence determines how many layers an actor has to get through. Response determines how fast you notice, isolate and communicate. Culture determines whether people escalate fast enough, honestly enough, for containment to even be possible.
The two field-tested practices: first, know your minimum viable operating state — which systems, in which order, you truly cannot function without. Second, containment decisions must be made on intel, not guesswork — you cannot shrink a blast radius you cannot see.
IR = Incident Response. BC = Business Continuity.
Pillar 1 of 3 — Defence
Defence-in-Depth: Necessary, Not Sufficient
Each layer slows an actor down and shrinks the blast radius. None of them, alone or together, is a guarantee. Tap a layer for detail.
KNOW YOUR BUSINESS
Layers of technical control only protect what you know to point them at.
What really matters in your business environment — mapped and understood, not assumed.
This is the Defence pillar. The stacked-layer diagram illustrates "defence-in-depth" — no single control is trusted to work alone.
The message to hold onto: these layers exist to slow an actor down and reduce the blast radius, not to promise immunity. Both case studies in this briefing involved organisations with real, modern defensive layers in place — the retail case bypassed technical layers entirely through social engineering of a human process.
The panel on the right makes a different point: no amount of layered technical control matters if it is not pointed at the right things, because the organisation does not have a complete or current picture of what it actually runs. Ask your CISO to walk through this list plainly — inventory of critical business functions, supplier/service-provider coverage, people risk, and a genuinely current asset inventory.
This is deliberately not framed around named external frameworks, because for a board or ELT audience the operative question is not which framework you are certified against, but whether you can honestly answer these questions about your own business.
MFA = Multi-Factor Authentication. EDR = Endpoint Detection and Response. CISO = Chief Information Security Officer. ELT = Executive Leadership Team.
Pillar 2 of 3 — Response
Incident Response Is a Structure, Not a Folder on a Drive
Your IR team
Tap a ring to see what it represents — support during a real incident very often comes from further out than people expect.
ISAC = Information Sharing and Analysis Center — a sector-specific, often not-for-profit body through which organisations share threat intelligence with peers, sometimes including direct competitors.
DECIDE THIS BEFORE YOU NEED IT
Support often comes from unexpected places — even competitors become allies when a shared threat actor, or shared customer trust, is at stake.
This is the first of two Response-pillar slides. The core message: incident response is an organisational structure that must be built and rehearsed in advance, not a document read for the first time during a crisis.
The concentric diagram illustrates: support during a real incident very often comes from further out than people expect. Beyond your own IR team and any retained external experts, a genuinely under-used layer of support is industry peers — including direct competitors — via sector ISACs, informal peer groups, and law enforcement/regulator relationships.
The right-hand panel lists field-tested practices agreed in calm conditions, not improvised under pressure: who can isolate a compromised system; the organisation's ransom-payment stance; a low-visibility coordination channel in case the corporate environment itself is compromised; a surge roster of people with IR-useful skills outside their normal job; regular tabletop exercises; and authorised external voices.
IR = Incident Response. ISAC = Information Sharing and Analysis Center — a sector-specific body for sharing threat intelligence between peer organisations. TTX = Tabletop Exercise.
Pillar 2 of 3 — Response
The Comms Plan Is the Highest-Leverage IR Asset
Uncoordinated, slow or contradictory communication can cause more financial, reputational and time damage than the threat actor's original action.
Who actually owns this: the comms plan is not solely a PR or marketing document. It needs named, authorised owners across IR, legal, HR, customer service and executive leadership — each accountable for their own audience above, and for knowing when to escalate to the others.
Tap an audience above to see what it needs from the plan.
This slide isolates one point deliberately, because it is arguably the single most important, and most consistently under-invested, element of incident response readiness: the communications plan.
When a real incident hits, the technical response is happening in parallel with an information vacuum. If there is no rehearsed, pre-agreed plan for who says what, to whom, on what cadence, and who approves it, that vacuum fills itself — with speculation, inconsistent internal messaging, and a slow or contradictory public position. In practice, this uncoordinated communication phase is very often where the largest reputational damage and some of the most painful financial consequences actually occur — frequently exceeding the direct cost of the technical disruption itself.
The nine audiences shown each need a distinct message, tone, timing, and approver — from employees and recovery teams through to regulators, media and the board.
The practical recommendation: this plan should be written down, role-assigned, and tested at least annually via a tabletop exercise, with the same rigor as a technical recovery plan.
IR = Incident Response.
Pillar 3 of 3 — Culture
Culture Decides Whether the Other Pillars Work
This is the Culture pillar, and probably the hardest of the three to change — because unlike Defence or Response, Culture is about daily behaviour at every level of the organisation, and it degrades quietly rather than failing all at once.
Left column: cultural failure exists at every level — leadership agrees security matters in the abstract but loses the argument when it costs revenue speed; managers push back with "we've always done it this way"; security gets engaged late and treated as a gate; people bypass controls rather than engage security; information is siloed instead of shared.
Right column: the fix is not a training slide deck. It is leadership visibly protecting the agreed risk appetite specifically in the moments when it is expensive to do so; timing and resourcing security into projects from the start; making escalation genuinely blameless and fast; leaders modelling secure behaviours themselves; and making InfoSec part of every function, at every level — the BISO/TISO model referenced on slide 1 is one concrete way organisations operationalize this.
Embedding also depends on a simple, often-skipped step: identifying, by name, exactly who is accountable for each security and continuity decision, and confirming directly with each of them that they know it is them.
BISO = Business Information Security Officer. TISO = Technical Information Security Officer.
What this actually costs
This Requires Sustained, Not One-Off, Investment
Sources: RH-ISAC, 2025 retail-sector benchmarking; IANS Research / Artico Search, cross-industry security-spend benchmark. Directional planning anchor only — size the real figure with your CISO and finance function.
Roughly double current retail-sector spend — sustained, year over year, as a standing cost of doing business.
Retail is a strategic target now (slide 4), and this budget must fund all three pillars — not just Defence tooling.
This investment devalues quickly: defences work, perceived risk falls, and budget gets quietly cut back — until the gap is wide enough to be hit. Spend has to keep rising just to hold pace with the threat.
This slide grounds the "significant, ongoing investment" message in real published data.
The data: retail-sector cybersecurity spend as a percentage of revenue rose from roughly 0.57% to 0.75% between 2024 and 2025 (RH-ISAC). The average across all industries in the same period was approximately 0.69% (IANS Research / Artico Search) — meaning retail, even after its recent increase, is still only at or slightly above the general cross-industry average, despite the sector-specific targeting argument made on slide 4.
The recommendation shown — roughly doubling the current retail benchmark, to approximately 1.5% of revenue — is deliberately above even the highest-spending sectors in general industry data, because retail is now a strategic target in its own right, and because this briefing's framework argues a meaningful share of this budget must fund Response and Culture, not just Defence tooling.
Framing for the board: this number is a directional planning anchor, not a precise formula. What should not be relitigated each year is the principle: this is a sustained, multi-year, standing cost of doing business — not a one-off project, and not the first thing cut in a difficult budget year.
The final point names a pattern worth watching for: investment reduces perceived risk, which makes the spend look trimmable, so it gets trimmed — and because the threat landscape keeps moving while the defences do not, the real risk quietly rises again. Any year-on-year reduction should be treated as a deliberate risk decision, made explicitly, not a routine cost-saving one.
ISAC = Information Sharing and Analysis Center, referenced in the RH-ISAC benchmark data source above. CISO = Chief Information Security Officer.
The building blocks, in priority order
Get These Foundations in Place, First
These are the minimum foundations every organisation needs — listed in the order to build them. Each layer depends on the one below it; skipping ahead is how the exercise at the bottom finds nothing useful. Track your own organisation's progress below — saved privately in this browser only.
This slide lists the foundational documents and exercises every organisation needs, deliberately ordered as a build sequence rather than a flat list — each layer depends on the one below it.
1) Comms Plan: the most immediately actionable and lowest-cost of the six. 2) Data & Process Map (built on a CMDB): you cannot protect, contain or recover what you have not mapped. 3) Business Continuity Plan: how the business keeps functioning while systems are down — a business document, owned by the business. 4) Disaster Recovery Plan: the technical mirror of the BCP. 5) Incident Response Plan: needs multiple variants, because different threat types are contained differently. 6) Cyber Incident Tabletop Exercise: only meaningful once the above five exist — it tests the whole stack across the entire business.
If presenting live: ask which of the six the room believes exists today, in a current, tested form — not in principle, not from three years ago.
CMDB = Configuration Management Database — the authoritative record of what systems and assets an organisation runs, and how they connect.
Closing
What This Means for You, Starting Now
None of this prevents the incident.
All of it determines how much it costs you when it happens.
INDEPENDENT CYBERSECURITY ADVISORY · consult@chatcpt.pro
This closing slide converts the entire briefing into a short, concrete list of commitments, deliberately written as actions a board or ELT can each personally own, rather than a summary of what was covered.
Each of the six ties directly back to earlier slides: the premise, the investment argument across all three pillars, two concrete time-bound Response commitments, the decision-rights point, and finally Culture — deliberately closing on leadership behaviour rather than a technology or budget point, because culture is ultimately what determines whether the other five commitments are real or nominal.
The closing line is the thesis of the entire briefing compressed to one sentence: this briefing does not claim to prevent an incident — nothing can promise that credibly. What it claims is that the six commitments above are what separate an incident that costs weeks and headlines from one that costs the business itself.
[Placeholder: insert your practice name and logo here before distributing.]
ELT = Executive Leadership Team.
Before you move on
Answer These Honestly — to Yourself, Not a Room
Tick each box once you've genuinely sat with the question. If any answer causes discomfort, that is the signal to revisit that pillar in more depth, and to raise it as a specific, named agenda item with your CISO or security leadership.
This is a hidden appendix — a private, honest-reflection checklist held in reserve, not part of the core flow. Bring it up if the room wants a more personal, individual gut-check after the main briefing, rather than the group-facing commitments on the closing slide.
This checklist is intentionally high-level and intended for private, honest reflection — not a group exercise to answer out loud, and not a compliance checklist to score. Its purpose is to convert everything covered so far into a personal gut-check: does genuine confidence exist here, or assumed confidence.
The six questions map loosely back to the three pillars and the earlier reframes, deliberately mixed rather than grouped: question 1 tests Response decision-rights; question 2 tests whether the comms plan is real or theoretical; question 3 tests Culture; question 4 tests whether the investment conversation is grounded in a real cost-of-downtime number; question 5 tests the "unexpected allies" point; question 6 tests the core premise of the whole briefing.
If any answer causes discomfort, that is the signal to revisit that pillar's material in more depth, and to raise it as a specific, named agenda item with the CISO or security leadership — not to let the discomfort pass unaddressed.
CISO = Chief Information Security Officer.