INSIGHT DETAIL

Beyond IT: Cyber Incident Response

Cyberattacks are not merely an IT issueConsider this scenario: Abnormal behavior is observed at a company outside of business hours—such as a significant volume of files being downloaded from an employee account or an unexpectedly large data transfer from corporate systems.

Back to Homepage
Back to Homepage

Cyberattacks are not merely an IT issue

Consider this scenario: Abnormal behavior is observed at a company outside of business hours—such as a significant volume of files being downloaded from an employee account or an unexpectedly large data transfer from corporate systems.

The instinctive reaction is often:

“Let the IT team handle it.”

However, the moment a real cyberattack begins, the situation quickly escalates beyond being just an IT problem. How the company responds becomes just as critical as whether the systems themselves are operational.

Should we simply shut down the system? Should customers be notified? What do we tell the employees?

Should the incident be reported to the authorities? Who will make the public statement on behalf of the company?

These are not decisions that the technical team can or should make alone.

The real problem often lies in confusion or an inability to reach a decision.

The technical team might be compelled to shut down a system to prevent the attack from spreading further. Yet, that very system might be powering the company’s payment processes, customer service, or daily operations.

Leaving the system running could trigger a potential vulnerability just when you feel secure. Shutting it down, however, could paralyze operations.

This is where the challenge extends far beyond cybersecurity.

The operations team must explain the system's criticality; the legal team needs to assess any obligations the company faces; and management must consider the impact on the business.

If you do not determine beforehand who makes the decision, everyone in the organization ends up waiting for approval to act. The time lost during a cyber incident gives the attacker more opportunity to remain within the systems. Even Early Intervention Is Not Enough

On the surface, this solution might seem quite simple.

Close the suspicious account. Disconnect the server. Disable the external service.

However, these interventions can also have side effects.

An important approval process could come to a halt when an account is closed. Consequently, disconnecting a server might stop or even limit the attack, but in doing so, it could also destroy critical evidence that helps explain how the incident occurred.

The idea, then, is not merely to act quickly. It is to act in a controlled and composed manner, involving the right, informed people.

Communication Is Half the Battle in a Crisis

Miscommunication can damage a company's reputation, even if an incident has been technically brought under control.

If employees are not kept informed, rumors persist. Such information may be unverified, and if passed on to customers, you might later have to retract or alter those statements. If you take too long to say something, people may assume your silence implies you are hiding something.

Therefore, the communications team should be involved from the very beginning, not after the process has already started. All communications must align with technical findings and legal assessments. The company must clearly distinguish between what it knows, what it has not yet verified, and the steps it is taking.

A Written Plan Alone Is Not Enough

Finally, consider the need for thorough preparation to ensure everyone is aligned. However, a plan may prove meaningless if it hasn't been tested against a real-world crisis scenario.

For instance, they might devise a scenario where a key service provider is hacked and customer data is potentially compromised.

Furthermore, it is not just the technical team's response that matters. This is where leadership, the legal department, the communications team, and the operations team become decisive.

In such exercises, issues regarding communication and authority often surface before technical shortcomings do.

The reality is that no organization can prevent all cyber incidents from occurring. The true differentiator lies in what happens after the incident begins.

Can the teams reach one another? Is it clear who makes which decisions? What will be halted, what will be disclosed, and how will the company continue to be managed?

An attack begins at a specific, often novel stage. However, its consequences can impact customers, employees, operations, and the reputation of any business.

Therefore, no cyber incident is merely an IT matter. It also tests how effectively and collaboratively the company can exercise its authority under pressure.

Disclaimer

The explanation provided above is for informational purposes only and should not be considered a substitute for professional cybersecurity, legal, or crisis management advice.