The CEO's Cyber Resilience Playbook
MIT Sloan Management Review|Summer 2024
What do CEOs who led through a serious cyberattack regret? Use this guide to learn from their experiences and take smarter actions before, during, and after an attack.
Manuel Hepfer, Rashmy Chatterjee, and Michael Smets
The CEO's Cyber Resilience Playbook

ON MAY 7, 2021, EXECUTIVES AT Colonial Pipeline discovered that cybercriminals had launched a ransomware attack on its IT systems. To prevent the malware from spreading further, the company took its computer systems offline, disabling 5,500 miles of pipeline that supplied 45% of the fuel consumed on the U.S. East Coast. The disruption lasted nearly a week, resulting in panic buying and fuel shortages. In a controversial decision, Colonial Pipeline paid a ransom of nearly $4.4 million in exchange for the decryption keys to get its systems back online. One month later, with recovery efforts and investigations ongoing, Colonial Pipeline CEO Joseph Blount defended that decision before the U.S. Senate, testifying,

“We were in a harrowing situation and had to make difficult choices that no company ever wants to face.”

Blount’s testimony echoes the experiences of many of the CEOs we have interviewed as part of our research into how leaders manage cybersecurity risk and attacks.¹ These CEOs shared with us similarly painful accounts of having to make existential decisions based on imperfect information, under enormous pressure, in an area where they had relatively little expertise. Serious cyberattacks thrust CEOs into the public eye, scrutinized by the media, shareholders, regulators, and other stakeholders.

We conducted 37 in-depth interviews with the chief executives of large enterprises (with average revenues of $12 billion) in the United States, Europe, and Asia. Nine of them had led their company through a serious cyberattack, which allowed us to compare their battle-tested views with those of CEOs who had not yet suffered such an attack. This article outlines strategies, based on their lessons, to help your organization stop over-relying on cybersecurity and start building cyber resilience as a strategic opportunity.

Denne historien er fra Summer 2024-utgaven av MIT Sloan Management Review.

Start din 7-dagers gratis prøveperiode på Magzter GOLD for å få tilgang til tusenvis av utvalgte premiumhistorier og 9000+ magasiner og aviser.

Denne historien er fra Summer 2024-utgaven av MIT Sloan Management Review.

Start din 7-dagers gratis prøveperiode på Magzter GOLD for å få tilgang til tusenvis av utvalgte premiumhistorier og 9000+ magasiner og aviser.

FLERE HISTORIER FRA MIT SLOAN MANAGEMENT REVIEWSe alt
Ask Sanyin: How Do You Build for an Unpredictable Future?
MIT Sloan Management Review

Ask Sanyin: How Do You Build for an Unpredictable Future?

While the pandemic was a wild ride of uncertainty for me and many of my peers in leadership, it feels like we never regained our footing.

time-read
2 mins  |
Winter 2025
What You Still Can't Say at Work
MIT Sloan Management Review

What You Still Can't Say at Work

Most people know what can’t be said in their organization. But leaders can apply these techniques to break through the unwritten rules that make people self-censor.

time-read
7 mins  |
Winter 2025
Make Character Count in Hiring and Promoting
MIT Sloan Management Review

Make Character Count in Hiring and Promoting

Most managers focus on competencies when evaluating candidates but it’s character that will transform the DNA of the organization. Here’s how to assess it.

time-read
10+ mins  |
Winter 2025
Why Influence Is a Two-Way Street
MIT Sloan Management Review

Why Influence Is a Two-Way Street

Managers achieve better outcomes when they prioritize collaborative decision-making over powers of persuasion.

time-read
10 mins  |
Winter 2025
Know Your Data to Harness Federated Machine Learning
MIT Sloan Management Review

Know Your Data to Harness Federated Machine Learning

A collaborative approach to training AI models can yield better results, but it requires finding partners with data that complements your own.

time-read
9 mins  |
Winter 2025
How Integrating DEI Into Strategy Lifts Performance
MIT Sloan Management Review

How Integrating DEI Into Strategy Lifts Performance

Incorporating diversity, equity, and inclusion practices into core business planning can provide a competitive edge.

time-read
9 mins  |
Winter 2025
The Myth of the Sustainable Consumer
MIT Sloan Management Review

The Myth of the Sustainable Consumer

Companies that understand the different kinds of consumers for sustainable products can market to them more effectively.

time-read
10+ mins  |
Winter 2025
A Practical Guide to Gaining Value From LLMs
MIT Sloan Management Review

A Practical Guide to Gaining Value From LLMs

Getting a return from generative AI investments requires a systematic approach to analyzing appropriate use cases.

time-read
10+ mins  |
Winter 2025
Improve Workflows by Managing Bottlenecks
MIT Sloan Management Review

Improve Workflows by Managing Bottlenecks

Understand whether process or resource constraints are stalling work.

time-read
10+ mins  |
Winter 2025
Craft Schedules That Work for Everyone
MIT Sloan Management Review

Craft Schedules That Work for Everyone

Business leaders can improve retention and business performance with schedules that make sense for workers’ lives.

time-read
10+ mins  |
Winter 2025