Versuchen GOLD - Frei

The CEO's Cyber Resilience Playbook

MIT Sloan Management Review

|

Summer 2024

What do CEOs who led through a serious cyberattack regret? Use this guide to learn from their experiences and take smarter actions before, during, and after an attack.

- Manuel Hepfer, Rashmy Chatterjee, and Michael Smets

The CEO's Cyber Resilience Playbook

ON MAY 7, 2021, EXECUTIVES AT Colonial Pipeline discovered that cybercriminals had launched a ransomware attack on its IT systems. To prevent the malware from spreading further, the company took its computer systems offline, disabling 5,500 miles of pipeline that supplied 45% of the fuel consumed on the U.S. East Coast. The disruption lasted nearly a week, resulting in panic buying and fuel shortages. In a controversial decision, Colonial Pipeline paid a ransom of nearly $4.4 million in exchange for the decryption keys to get its systems back online. One month later, with recovery efforts and investigations ongoing, Colonial Pipeline CEO Joseph Blount defended that decision before the U.S. Senate, testifying,

“We were in a harrowing situation and had to make difficult choices that no company ever wants to face.”

Blount’s testimony echoes the experiences of many of the CEOs we have interviewed as part of our research into how leaders manage cybersecurity risk and attacks.¹ These CEOs shared with us similarly painful accounts of having to make existential decisions based on imperfect information, under enormous pressure, in an area where they had relatively little expertise. Serious cyberattacks thrust CEOs into the public eye, scrutinized by the media, shareholders, regulators, and other stakeholders.

We conducted 37 in-depth interviews with the chief executives of large enterprises (with average revenues of $12 billion) in the United States, Europe, and Asia. Nine of them had led their company through a serious cyberattack, which allowed us to compare their battle-tested views with those of CEOs who had not yet suffered such an attack. This article outlines strategies, based on their lessons, to help your organization stop over-relying on cybersecurity and start building cyber resilience as a strategic opportunity.

WEITERE GESCHICHTEN VON MIT Sloan Management Review

MIT Sloan Management Review

MIT Sloan Management Review

Assess What Is Certain in a Sea of Unknowns

Understanding what won't change clarifies what might — and strengthens decision-making in volatile times.

time to read

13 mins

winter 2026

MIT Sloan Management Review

MIT Sloan Management Review

Ask Sanyin: Why Is It So Hard to Pull the Plug on a Project?

We're finding it difficult to wind down projects that no longer serve our priorities.

time to read

2 mins

winter 2026

MIT Sloan Management Review

MIT Sloan Management Review

Integrate Sustainability and Innovation to Find New Opportunities

Five common innovation practices can help leaders pursue sustainability as a growth strategy.

time to read

12 mins

winter 2026

MIT Sloan Management Review

MIT Sloan Management Review

The Case for Quiet Corporate Activism

Leaders concerned that they will be penalized for championing sustainability and diversity can still sustain their commitments.

time to read

11 mins

winter 2026

MIT Sloan Management Review

MIT Sloan Management Review

The Perils of Algorithmic Pricing

Some revenue management systems based on algorithms may lead to unintended collusion and antitrust violations.

time to read

9 mins

winter 2026

MIT Sloan Management Review

MIT Sloan Management Review

Broadening Future Perspectives at the Bank of England

Leaders at the U.K’s central bank sought to broaden their thinking about future risks and opportunities. Here’s how they built longer-term horizon-scanning capabilities and what they learned along the way.

time to read

9 mins

winter 2026

MIT Sloan Management Review

MIT Sloan Management Review

How Nesting Changes Platform Strategy

Should your platform host another platform — or be hosted by one? Here's how to think through the choices.

time to read

14 mins

winter 2026

MIT Sloan Management Review

Are You an Authentic Leader or an Authentic Jerk?

Leaders who are true to their values can inspire trust and respect, but not if \"being yourself\" becomes the problem.

time to read

13 mins

winter 2026

MIT Sloan Management Review

MIT Sloan Management Review

How to Make Scenario Planning Stick

Developing future scenarios can deepen leaders’ strategic insights. Establishing scenario planning as an ongoing capability and reaping its full benefits require linking it to other processes.

time to read

16 mins

winter 2026

MIT Sloan Management Review

MIT Sloan Management Review

A Faster Way to Build Future Scenarios

This streamlined approach to scenario planning incorporates AI and helps managers navigate future uncertainties more efficiently.

time to read

13 mins

winter 2026

Listen

Translate

Share

-
+

Change font size