What I learnt from 70 days in crisis by Joseph Graceffa
Aug 29, 2026

I’m the CISO at a family office. One morning, I received a call informing me that one of the holding company’s subsidiaries had been attacked. I was asked to get in touch with the CEO, which I did straight away.
He said to me: “I don’t know who you are, but bring your mates round. I think we’ve got a real problem and we’re going to need some help.”
We hung up. The call lasted two minutes; I would spend 70 days dealing with it.
In my previous column (link), I talked about what we prepare: mapping, clauses, the right profile. However, prevention cannot do everything. Crises are inevitable. I have been through several during my career. Here are the lessons I wish I’d known before facing them.
The three stages
I’m simplifying, but a major cyberattack is generally handled in three stages:
Isolate. Restrict internet access, regain control of the systems. We don’t systematically shut them down because they sometimes hold the keys to resolving the crisis. That said, we send teams home without their equipment so we can regain control. This isn’t a technical reflex; it’s a business decision. The trade-offs are business-related: who should be furloughed? How can we ensure that shops continue to sell?
Understand. Investigate whilst preserving evidence — this will be requested by both the legal authorities and the insurer, and it cannot be retrieved retrospectively. Identify the point of entry: a poorly secured network infrastructure, an exposed machine, often a third-party service.
Rebuild. Gradually bring the branches back online, under controlled conditions. Nothing is brought back online all at once.
These three stages are generally well known. What determines their success lies elsewhere.
Pacing is a management tool
Here is what I hadn’t anticipated until I experienced it: the pace of communication within a crisis unit is a tool for managing it.
The key lies in scheduling regular, progressively less frequent synchronisation points.
Initially, these points may take place every 2 hours, then every 4 hours, then every 8 hours, until they are reduced to once a day once the routine is established. The simple act of moving from every 2 hours to every 4 hours sends a message to all the teams involved: the board, the operational teams and the business units. It conveys the message that the situation is stabilising.
During these updates, be disciplined. Make a point of systematically stating what is known, what is not yet known, and what is being done.
It is wise not to downplay the situation, but equally not to exaggerate it.
This rigour avoids two things that prove costly in a crisis: irreversible decisions taken in a panic, and the constant, exhausting need for everyone to know where we stand.
Support functions and human limits
This second lesson is so obvious that it is consistently overlooked.
An inescapable law of crisis: you will never get further than your teams allow you to. Looking after them is at the very heart of the operation.
Logistics is therefore no mere detail. Meals, rest areas: these must be planned, just as a communications plan is.
The intensity and duration of these crises distort everything. Fatigue ceases to be merely a source of discomfort; it becomes a risk factor. After a few days of teams working round the clock, it leads to mistakes, and in the midst of an investigation, a mistake comes at a high price. You miss a lead, close off a line of inquiry too quickly, or reopen a line of inquiry that still needed monitoring.
The temptation to keep everyone on their toes is strong.
However, I would recommend returning as quickly as possible to a 9 am to 7 pm schedule, even if the crisis is not over. This decision will need to be reassessed daily, but it will help to spare the frontline staff and preserve the quality of their judgement.
Allies, and battles not worth fighting
A crisis unit cannot operate in isolation. Your best allies at such times are the operations, legal and communications teams, along with a few trusted partners who can be mobilised in ‘commando’ mode.
Such partners are rarely found at the eleventh hour. For example, it’s rare to discover a good incident response provider whilst the incident is actually happening.
I like to think of this crisis committee as a project that is built calmly, thoughtfully and with careful preparation.
These are relationships in which you invest so that you can collaborate seamlessly when the time comes.
Having established this climate of trust should, in particular, help you avoid one of the most common pitfalls in a crisis: immediately looking for someone to blame. Apart from the fact that this does not advance the investigation, it damages a team that, in many cases, will need to hold out for weeks to come.
Cultivate kindness and pragmatism. Avoid another common pitfall: the urge to analyse everything perfectly before taking action. This is simply ‘zero risk’ by another name, and it proves even more costly in a crisis than in normal times.
At such times, decisions must be made based on what we know, not on what we wish we knew.
What 70 days have taught us
It wasn’t the technical aspects that mattered most. It was the pace, the organisation, and the clarity about what we would never know perfectly.
A crisis does not reward perfection. It rewards what had been decided beforehand — ready-made contractual models, identified partners, and priorities that had already been set.
Conscious risk rather than zero risk: in my previous column, it was a stance. In a crisis unit, it becomes a method of operational survival.
—
If these topics interest you, we’ll have the opportunity to discuss them on 30 September at 10.00 am with six other experts in supplier risk. Free registration.