Gå ubegrenset med Magzter GOLD

Gå ubegrenset med Magzter GOLD

Få ubegrenset tilgang til over 9000 magasiner, aviser og premiumhistorier for bare

$149.99
 
$74.99/År

Prøve GULL - Gratis

The CEO's Cyber Resilience Playbook

MIT Sloan Management Review

|

Summer 2024

What do CEOs who led through a serious cyberattack regret? Use this guide to learn from their experiences and take smarter actions before, during, and after an attack.

- Manuel Hepfer, Rashmy Chatterjee, and Michael Smets

The CEO's Cyber Resilience Playbook

ON MAY 7, 2021, EXECUTIVES AT Colonial Pipeline discovered that cybercriminals had launched a ransomware attack on its IT systems. To prevent the malware from spreading further, the company took its computer systems offline, disabling 5,500 miles of pipeline that supplied 45% of the fuel consumed on the U.S. East Coast. The disruption lasted nearly a week, resulting in panic buying and fuel shortages. In a controversial decision, Colonial Pipeline paid a ransom of nearly $4.4 million in exchange for the decryption keys to get its systems back online. One month later, with recovery efforts and investigations ongoing, Colonial Pipeline CEO Joseph Blount defended that decision before the U.S. Senate, testifying,

“We were in a harrowing situation and had to make difficult choices that no company ever wants to face.”

Blount’s testimony echoes the experiences of many of the CEOs we have interviewed as part of our research into how leaders manage cybersecurity risk and attacks.¹ These CEOs shared with us similarly painful accounts of having to make existential decisions based on imperfect information, under enormous pressure, in an area where they had relatively little expertise. Serious cyberattacks thrust CEOs into the public eye, scrutinized by the media, shareholders, regulators, and other stakeholders.

We conducted 37 in-depth interviews with the chief executives of large enterprises (with average revenues of $12 billion) in the United States, Europe, and Asia. Nine of them had led their company through a serious cyberattack, which allowed us to compare their battle-tested views with those of CEOs who had not yet suffered such an attack. This article outlines strategies, based on their lessons, to help your organization stop over-relying on cybersecurity and start building cyber resilience as a strategic opportunity.

FLERE HISTORIER FRA MIT Sloan Management Review

MIT Sloan Management Review

MIT Sloan Management Review

Formalize Escalation Procedures to Improve Decision-Making

Conflict is inevitable. A systematic approach to escalation helps organizations manage disagreements efficiently and make better decisions.

time to read

11 mins

Fall 2025

MIT Sloan Management Review

MIT Sloan Management Review

A New Method for Assessing Circular Business Cases

Conventional business analysis overlooks the costs and new revenue sources found in circular approaches.

time to read

11 mins

Fall 2025

MIT Sloan Management Review

MIT Sloan Management Review

Building Innovation Teams Across National Borders

Restrictive immigration policies are forcing multinational enterprises to rethink their R&D strategies. Here are four approaches to maintain innovation excellence with geographically dispersed teams.

time to read

14 mins

Fall 2025

MIT Sloan Management Review

MIT Sloan Management Review

Strategic Alignment Reconciles Purpose and Profitability

Sustained performance requires a company purpose that is validated in the market.

time to read

10 mins

Fall 2025

MIT Sloan Management Review

MIT Sloan Management Review

The Hidden Costs of Coding With Generative Al

Generative Al can boost coding productivity, but careless deployment creates technical debt that cripples scalability and destabilizes systems.

time to read

6 mins

Fall 2025

MIT Sloan Management Review

Aligning Strategy and Skills

\"DO WE HAVE THE PEOPLE WE need to successfully execute our strategic plan?” That’s a perennial middle-of-the-night worry for business leaders.

time to read

1 mins

Fall 2025

MIT Sloan Management Review

MIT Sloan Management Review

Should You Recruit New People, or Upskill Your Workforce?

I worry that we don't have the skills in-house that we need to seize future opportunities.

time to read

2 mins

Fall 2025

MIT Sloan Management Review

MIT Sloan Management Review

The High Cost of Executives' Intellectual Property Blind Spots

Strategic business decisions often involve intellectual property, but senior managers' understanding of salient issues is often limited.

time to read

10 mins

Fall 2025

MIT Sloan Management Review

MIT Sloan Management Review

How the EU's Taxonomy Combats Greenwashing

The European Union's criteria for identifying green activities can be a better guide than standard ESG measures.

time to read

7 mins

Fall 2025

MIT Sloan Management Review

MIT Sloan Management Review

A Data-Driven Approach to Advancing Meritocracy

Instead of simply relying on best practices, employers should adopt a talent management strategy that addresses bias and inequity while ensuring efficient, fair, and merit-based decisions.

time to read

16 mins

Fall 2025

Listen

Translate

Share

-
+

Change font size