BY CARLOS CANEDO

Operations Manager at Avertium

It's 9:15 on a Tuesday morning.

Your plant is running. Your call center is taking calls. Someone is closing the month. Someone else is in a meeting arguing about next quarter's budget.

Everything works, or at least, it looks like it does.

Fourteen days ago, someone got in. They didn't break anything. They didn't shut anything down. They didn't ask for money. They just got in - and stayed. Since then, they've been watching: learning who approves payments, where the backups are, which system can't be stopped, and how your CEO writes his emails.

The uncomfortable part isn't how dramatic that scenario is. It's how ordinary it is. According to Mandiant's M-Trends 2026, fourteen days is the global median time between intrusion and detection, and that number got worse, not better, from the year before. Median means half of all cases take longer.

I've spent more than a decade looking at that gap from both sides. For ten years, I ran penetration tests, breaking into companies with their permission to show them exactly how it happens. Today, I run operations for a security center that monitors organizations around the clock.

What both sides taught me is simple: almost no serious incident I've seen was an unsolvable technical problem. Almost all of them were business decisions nobody made in time.

 

 

 

nobody attacks your company. they attack an account.

The story almost always starts the same way, and it rarely looks dramatic.

An email arrives from a real supplier your company has worked with for years. The account is legitimate; it's just no longer controlled by the supplier. The message says what these messages always say: there’s an outstanding invoice, and the document is ready to view. No spelling errors. No manufactured urgency. Someone in accounts payable signs in, gets an error, assumes “the system is down again,” and moves on with the day.

That person wasn't negligent. She did what she does forty times a day. Verizon's 2026 Data Breach Investigations Report found that 62% of breaches involved the human element, not because people are careless, but because attacks no longer look like attacks.

From there, the path is painfully simple: account → access → information → critical systems → operations. The attacker reads the mailbox and finds what lives in every mailbox, a password someone shared “just this once,” a link to a department drive, credentials a vendor emailed when the new system went live. He finds an administrator account created four years ago for a project nobody turned off. And with that, he reaches the ERP.

And he reaches the backups.

That's the part many executives don't have in their mental model. A professional attacker's first move today usually isn't encryption. It's making sure you can't recover. He destroys or encrypts your backups first, then encrypts your operations, because he understands something many boards don't: your backup isn't a file. It's your negotiating position.

Between the first step and the last, there is no magic. There is time, patience, and permissions nobody reviewed.

Which is why the question that matters isn't how do we stop people from clicking? Statistically, that battle is already lost. The question is: when someone clicks, how far can the attacker get?

 

what shows up on an invoice is not what you pay

When a company totals up an incident, it usually counts what fits neatly on an invoice: the ransom if it was paid, the fine if there was one, forensic consultants, replacement hardware, and IT overtime.

Below that line is everything that actually determines the damage. Days not operating. Revenue that never gets billed. Two hundred people working at half output with paper, spreadsheets, and phone calls. Customers who don't complain, but simply stop asking for quotes. Contracts that don't get renewed. Your CEO, CFO, and general counsel spending three weeks on this instead of the business.

None of that will ever appear in a line item labeled "cybersecurity."

Sophos's State of Ransomware 2026, based on 2,158 organizations that were actually attacked, puts the average recovery cost at USD 1.7 million, excluding the ransom, up 11% year over year. And 66% of those who got their data back did so from backups, not by paying. A tested backup remains the single best financial defense available.

I emphasize tested.

 

three questions you should be able to answer today

None of these questions is technical. None requires knowing how a firewall works. All three reveal, in under a minute, how prepared an organization really is.

1. If we lose our critical systems tomorrow, how many hours until we're operating again?

Not “do we have backups?” Everyone says yes to that. How many hours? Which systems are genuinely critical? If the list has 40 systems, it's an inventory, not a priority list. Has one of those backups ever been restored with a stopwatch running? What does your cloud or ERP provider actually commit to?

2. If a privileged account is compromised tomorrow, do we detect it and stop it?

Detecting and stopping are different capabilities, and many organizations only have the first. An alert nobody acts on until Monday is the same as no alert.

Here's the figure that should reframe this conversation at your next leadership meeting: Sophos found that 97% of victims whose attack began with stolen credentials did have multi-factor authentication, just not everywhere. It was on email, because email is easy. It wasn't on the VPN, the firewall console, or the legacy system that “doesn't support it.” That's where the attackers came in.

So don't ask whether you have MFA. Ask where you don't have it, and why. That exceptions list is your real risk map and it fits on one page.

3. If an incident happens tomorrow, who decides during the first hour?

A name, not a department. Who declares this a crisis? Who authorizes disconnecting a revenue-producing system? Who speaks to customers? Who do you call outside the company, and are those numbers written down somewhere outside the systems that may be encrypted?

When that authority isn't assigned, an on-call engineer decides alone at 2 a.m. whether it's worth waking an executive. He usually decides it isn't. That's where the first six hours go.

If you can't answer these three questions today, you don't have a technical problem. You have a pending business decision.

 

the ninety minute exercise

If you do only one thing after reading this, make it this. It costs nothing.

Put your leadership team in a room for ninety minutes. No laptops, no vendors, no presentation. Put one sentence on the table:

"It's 9:15 a.m. We've just discovered that several critical systems are encrypted and there's a note demanding a ransom. What do we do?"

Then be quiet.

Work through six questions: Who declares this a crisis? What do we shut down, what do we isolate, and who authorizes it? Can we keep operating manually, and for how long? What do we tell customers, and when? Who do we call outside the company? And the uncomfortable one: under what conditions would we consider paying, and who makes that call?

Two rules. The executive team has to be in the room. If only IT attends, the exercise is pointless, because the decisions that matter aren't technical. And nobody may say “that's IT's job,” because on the day it happens, nobody will be able to say that either.

The deliverable isn't a report. It's one page listing the decisions the room couldn't make, each with an owner and a close date.

Run it twice a year. The second time always goes better, and that improvement — measured honestly — is a far better maturity indicator than any certificate on the wall.

 

the decision is already yours

The question is no longer whether your organization will be attacked. Someone will get in. That's arithmetic, not pessimism.

The question is what it will cost you not to have decided beforehand.

Because the cost of an incident isn't determined on incident day. It's determined months earlier, in decisions that seem small and boring at the time: testing a restore, closing an MFA exception, writing a name on a card.

None of that is urgent on the day you decide it. All of it is the only thing that matters on the day it happens.

Cybersecurity doesn't begin when the incident happens. It begins with the decisions we make before it does.

 

 

about avertium 

Avertium is an AI security and compliance leader, delivering comprehensive solutions to mid-market and enterprise customers. Our unique “Assess, Design, Protect” approach addresses and improves security strategy, reduces attack surface risk, strengthens compliance, and provides continuous threat protection. Avertium maximizes customer security investments and enables customers to focus on growth, innovation, and business outcomes, while assuring that their security infrastructure is resilient and adaptive to evolving threats. That’s why customers trust Avertium to deliver better security, improved compliance, and greater ROI.

Avertium CFC

The Avertium Cyber Fusion Center (CFC) helps organizations build detection and response capabilities designed for the realities of today’s threat landscape, including the assumption that trusted enterprise tools will be targeted. To learn more about how we approach managed security in multi-vendor environments, reach out to our team.

 

You might also enjoy...

 

CISO cybersecurity cybersecurity investment Business of cybersecurity Advocating for Cybersecurity MFA Cybersecurity Landscape Thought Leadership Blog