HomeSecurity6 Actions CEOs Should Take During a...

6 Actions CEOs Should Take During a Cyberattack

6 actions CEOs should take during a cyberattack

Cyberattack is one of the most significant threat scenarios for any company in today's digital world. CEOs must take decisive and immediate actions to address such incidents.

CEO

Below are six recommendations for CEOs (the example of Colonial Pipeline and the attack on it is often cited):

1. Be careful how you communicate with the audience.

Bank failures are classic examples of how public reaction and group psychology can exacerbate a crisis. The shortage of toilet paper during the Covid-19 pandemic and the fuel shortage at gas stations due to a ransomware attack are examples that show that this problem is not limited to financial institutions.

It is necessary to be careful about how and what we communicate to the public. This does not mean that we should avoid communicating with the public; on the contrary, it is a necessity. However, companies must take a thoughtful approach. As the Colonial Pipeline case shows, this includes companies that rarely have to deal with the public as part of their daily operations, but may have to do so unexpectedly from one day to the next.

2. Cooperate with the government.

Colonial Pipeline’s decision to shut down its pipeline system had to happen quickly, but there was arguably plenty of time to consult with U.S. government experts. Disconnecting the pipeline system meant that, regardless of whether it was contaminated, it would take days to restart, disrupting the actual supply of fuel with all the consequences that would require government action. Coordination with the government is key to avoiding a crisis from worsening.

3. Know who to contact.

To make informed decisions quickly and coordinate with the right people, CEOs need to know who in government is the right contact. Contacting NATO or the military, as some anecdotes over the years have suggested, is not the right answer.

That said, sometimes the government does not make it easy for external parties to identify the appropriate person or entity, so the government has a responsibility to provide clarity.

4. Create a plan and implement it.

This is perhaps the most critical point as it provides a means to achieve the rest. In addition to developing and implementing a plan – ideally under the supervision of the CEO – the plan should be practiced at least once a year. Regular exercises will help the company’s leadership and staff acquire the “memory” needed to respond effectively to a real crisis.

5. Know networks .

A CEO should ideally have a high-level understanding of how a company's business information technology (IT) and operational technology (OT) networks interact. If the systems are air-gapped, there is no reason to shut down the OT network if the breach is limited to the IT network.

The ransomware attack on Colonial Pipeline has proven that even crippling business IT networks can have significant impacts. If a company can no longer issue invoices, doesn’t know who its customers are, or how to contact them, the real-world impact can be just as disruptive as an actual production outage.

6. Be humble and seek help from experts.

Cybersecurity is a broad term that covers an extremely complex set of problems. While there are commonalities and some software is used across sectors, pipeline cybersecurity is very different from cybersecurity in the context of the financial sector, hospitals, schools or railways. A key idea after years of cyber incidents spanning sectors is to recognize the limits of everyone’s knowledge, including that of cybersecurity experts. Therefore, CEOs should not hesitate to seek outside help to help develop, test or improve a plan or review existing procedures and policies.

Beyond these high-level recommendations, there are many other resources, including guides and checklists for CEOs, board members, and CISOs that are more detailed. The U.S. government, namely the Cybersecurity and Infrastructure Security Agency (CISA), also provides Stopransomware.gov and Shields Up as resources designed for use by companies depending on their level of cybersecurity maturity.

Information source: hbr.org

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Teo Ehc
Teo Ehchttps://www.secnews.gr
Be the limited edition.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS