A featured contribution from Leadership Perspectives: a curated forum reserved for leaders nominated by our subscribers and vetted by the CIOReview Advisory Board.

Bouygues Group
Preparing For Cyber-Attacks


How can I write an article on what we CISOs are all looking for: the almost magic recipe for successful cyber crisis management?
The answer is very simple: I don't know how.
There is no ultimate recipe for success every time that would be too simple. We'd all keep it tucked away, ready to be used at the slightest opportunity.
What I can share with you is my experience of managing a cyber-crisis. Who am I? A CISO who has lived two lives: the first in which I knew full well that the right question was not if a cyber-attack could happen, but when. My second life as a CISO began the day that my company and I, along with it, fell victim to a crypto locker.
One of the first things to do in such a cyber-incident is to launch investigations: forensics.
Whether you've shut down your IS or not, whether your servers are encrypted or not, if you don't know what hit you or how they did it, you risk a relapse.
The only thing that matters at the moment is restarting your company's critical activities as quickly as possible; otherwise, your business could disappear. But you have to restart carefully, with an acceptable level of risk, to avoid any further attacks. There's nothing worse than telling your colleagues that you have to start from scratch because they've done it again.
"One of the first things to do in such a cyber-incident is to launch investigations: the forensics"
To get through this ordeal, you have to get organised, but you have to invent an organisation, a system that doesn't exist. Each attack and each crisis has its own specificities, and your organisation will have to adapt: local or global, destruction of the IS or compromise of administration accounts, theft of customer data or company data. Your organisation will adapt and evolve as the crisis progresses. At some point, you may no longer need to work 24 hours a day (and this is a very tiring system for night shifts!). Crisis meetings may become less frequent as rapid containment actions give way to long-term projects to strengthen your IS. The people involved in the crisis management system may also change functions (steering, handover, stream leader, etc.).
Whatever your organisation, you will need to define your priorities: my general management played its strategic role to the full. They decided which tenders were vital for the company and which strategic activities needed to be restarted. Within the operational crisis unit, our mission was to translate these priorities into application names, server numbers and back-ups to be restored.
Each team stayed in its role, and we had a single objective: to maintain or restart the company's vital functions to enable it to survive. Our teams were organised into streams: a single objective and the right experts in the team. When the project was delivered, the Stream was disbanded, and the members were dispatched to other teams. There was no hierarchy to validate deliverables: only the crisis unit decided, validated and reorganised.
In a cyber-crisis, you will always find the right tool to secure your system; you will almost always find the right consultants to strengthen you. But your colleagues: the men and women in the IT department and the business teams are invaluable. You need to take care of them: you can't do it alone, and without their commitment you won't solve the crisis.
On a lighter note, unlimited coffee and real hot meals are good for the stomach. Sharing encouraging messages from management is good for the spirit.
However, in a crisis organisation, all points of reference are swept away: no more team meetings, no more reviews of incidents or changes. You need to recreate a battle rhythm: organise new rituals during the day and new points of reference: the moment for sharing progress on streams, the moment to request exemption from new cybersecurity rules. Your colleagues will know what to do, how to do it and when to do it!
To sum up, if you want to be in a position to manage a cyber-crisis situation effectively:
1. Practice and be ready to react. You won't be able to prepare for every eventuality, but you know how to organise yourself to deal with it.
2. Be agile and ready to change: you will undoubtedly make mistakes, so adapt.
3. Don't go it alone. Cyber is a team sport, and this is even truer in times of crisis.
4. Take care of others and take care of yourself! Everyone is useful and necessary in cyber crisis management!