Cyber incidents expose leadership gaps, not just IT issues


Legal experts from BD&P are thought leaders on Digital Journal. The authors of this article are Mardi McNaughton, John Sanche, and Peter Ciechanowski.


Most boards understand that cybersecurity matters. What many underestimate, however, is the enormous risk that they are exposing themselves to by being unprepared for a cyber incident.

When a cyber incident or breach occurs, the organizations that respond best aren’t necessarily the ones with the most sophisticated tools. They are the ones that have planned for such an event. 

They can react quickly and effectively because they know who leads the charge internally, which external parties need to be engaged, what information must be communicated, and they can take appropriate action when pressure is at its highest. 

Failing to plan is a critical boardroom mistake

Many leadership teams focus on one question: “How do we prevent a cyber event?” An equally important question is “how will we respond when one occurs?”

No organization is immune from being the target of a cyber attack. Security incidents often begin with ordinary events like a phishing email, compromised password, third-party vendor issue, or vulnerability in a legacy system.

What begins as an isolated technical incident can quickly escalate into a significant operational, financial, and reputational risk for the organization.

Companies that fail to effectively plan for cyber incidents are often in the dark about what to do, taking longer to move into action, leaving their systems exposed and their risk multiplying for longer than those who can react quickly. 

The decisions that matter aren’t technical

As cyber incidents unfold, critical decisions must often be made before all of the facts are known around what exactly happened. 

Questions can quickly arise around the protection of sensitive information, business continuity, contractual commitments, customer and stakeholder communications, regulatory obligations, and internal investigations.

Many of these decisions will not necessarily be made by an IT team, but rather by a company’s leadership. They can have consequences long after systems are restored.

Cybersecurity should not be viewed solely through a technology lens. Legal, operational, and reputational considerations should be at the forefront of shaping any company’s response planning. 

Why compliance-based planning falls short

One of the most common mistakes organizations make is treating incident response planning as a document creation process, as opposed to a capacity-building exercise. 

Many organizations have a plan, but far fewer have a plan that executives can confidently rely on during a real-world disruption.

Plans often fail because they’re too technical or too generic, outdated, untested, or unknown to the people responsible for using them.

A useful response plan should help leaders answer practical questions quickly:

  • Who leads the response?
  • Who has decision-making authority?
  • When should external advisors be engaged?
  • How will communications be managed?
  • How will critical operations continue?

The goal is not simply to create a plan. It’s to build confidence that the organization can execute it under pressure.

The resilience advantage

Cybersecurity is ultimately about business resilience, not technical perfection.

Boards and executives should view cyber readiness as part of strategic planning alongside growth, digital transformation, governance, and risk management.

Leaders do not need to become cybersecurity experts, but they should be confident that in the event of a cyber incident or breach, their organization is prepared to:

  • Make informed decisions under pressure 
  • Manage legal and regulatory obligations 
  • Communicate effectively with stakeholders 
  • Restore operations quickly
  • Protect reputation and stakeholder trust

Cyber incidents are also a test of leadership.

When systems are compromised, facts are incomplete, and stakeholders are demanding answers, the organizations that respond most effectively are those that have prepared in advance. A current, practical, and tested incident response plan can mean the difference between a manageable disruption and a prolonged crisis.

For boards and executives, cyber readiness is a core component of business resilience and good governance.

For assistance in developing or strengthening your organization’s cyber incident response plan, please contact a member of our Cybersecurity group.



Cyber incidents expose leadership gaps, not just IT issues

#Cyber #incidents #expose #leadership #gaps #issues

Leave a Reply

Your email address will not be published. Required fields are marked *