
Friday, 18: 34h. The phone rings on the personal mobile of the CEO. Someone from the technical team, without Rodeos, tells him: «They have hacked us. They have access to customer data. They ask for a rescue. We have disconnected the system and there is already the technical team and the lawyers working, but there is a risk of leaks. How do we tell this?»
Break.
In that pause, customers, suppliers, employees and a possible sanction of the regulator are at stake. And, above all, travel a frustrating thought: «We could have trained or prepared before.»
In Spain, more than 45,000 cyber attacks are produced per day, according to a data report 101. And no, not all are aimed at large technological or critical infrastructure. More and more, the objectives are SMEs, B2B companies or family businesses with high data value, with technological and communication capacities not so sophisticated, but with the same digital exposure.
How much does it cost? The average cost of an attack exceeds € 200,000 for a medium -sized company according to Erni Spain data. But reputational damage can be much higher if it is not managed quickly and transparency. Because it’s not just about recovering the system. It’s about conserving trust. And that is not supported by Firewalls, but with clear leadership and communication.
Most of CIO, when they listen to the word «transparency» in these types of situations, they are put their hair. They imagine in newspaper covers, radio gatherings, memes on social networks … but that is not transparency. Transparency is not advertising. Transparency is to tell exactly the right people the exact information they need to know. Neither, no less.
A cyber attack is not only a technical incident. It is a crisis of trust. During the first 24 hours after a cyber attack, the company faces a silent trial that can have hard consequences among their audiences: customers wonder if their data is safe, employees who fear if they are working in a safe place, suppliers if you can trust, the regulator if it is complying with the regulations, investors question if they will recover their money … and everything occurs at the same time and with the risk of being filled in social networks and with the risk of social networks and with the risk of social networks and with the risk of social networks means
Is your company prepared to support this trial without chaos?
Simulate the disaster before it occurs: the training that makes a difference. Therefore, the new regulations (Nis 2 and Dora) put so much emphasis on the need for drills.
The best Formula 1 equipment not only train in circuit. They make fire drills, mechanical failures, accidents, human errors. Because? Because the reflexes are trained, they do not improvise. The same goes for companies before a cyber attack.
Crisis drills produced by cybersegos are increasingly common in companies with high digital exposure, sensitive operations or strong data dependence. Preparing the organization does not guess how exactly the cyber attack that we will suffer, but to test the answer: discover internal coordination failures between IT, legal, communication and business; anticipate what messages work and which generate more alarm; test the emotional resistance of the crisis committee; detect key roles without real coverage; and correct processes that only exist on paper, not in practice.
These exercises sometimes, most, reveal that the Management Committee has intuition and knowledge to solve it, but not structured, so speed and consistency are lost. In others, that the messages that had been designed as «safe» are cold, insensitive, incoherent or insufficient.
Preparing is much more profitable than reacting late. A drill should be seen as an investment. That not only prepares the team. Strengthens organizational culture, improves governance, reinforces Compliance’s strategy, and allows you to refine corporate narrative in borderline situations.
And above all: protects the most important intangible value of a company today: its reputation. The challenge is no longer to prevent the bad ones from stealing your data. The challenge is that they do not steal your credibility.