I’d like to share a few topics that you may want to keep in mind as a leader of teams and people during a catastrophic cybersecurity event, and I’m going to offer you the first support you’re going to need during that crisis. Hopefully, I’ll be the person you forget, but the voice you remember; the voice that pops into your head when you need it most.
On a daily basis, it isn’t hard to be a leader. You’ve spent the time cultivating your team, they’re empowered and aside from the occasional customer issue or internal struggle, the team trucks along pretty smoothly. You may not even think about what it’s like being a leader during these times, you may just go along with it, be bored by it, or be excited by it. Your biggest pain is some person in the Excel forum asking the question you have and posting later that they figured it out but didn’t share how. But those times when things are going smoothly, aren’t the times you’re being tested as a leader. Someday, when – not if, you’re going to face something terrible, more terrible than you, your team, your senior leadership, or anyone else in your company wants to imagine, you’re going to be breached or worse, you’re going to become a victim of ransomware. Are you prepared to lead during these dark times? Are you the leader your team needs during that sort of event? Are you the kind of leader that can help pull your company from the brink of destruction into the shining new era post cyberattack? Will you be the leader all others are judged against? Let me help.
First – Get your head right before you step in to try to help others get their heads right. Put your oxygen mask on before helping others don theirs. Wait what? What does this mean? Come to terms with what happened and get your emotion out of the equation as quickly as possible. Your role as a leader immediately becomes being the calming logical voice. You’re about to start dealing with people worried about their careers, their money, their reputations, and any other thing that pops into an emotionally stressed mind. So, get right and be ready to face upset and stressed people. It will be your job to help others get out of the emotion zone as quickly as possible and start making decisions based on logic, not fear. Your goal is to get as many people as possible responding to the incident opposed to reacting to it. Emotion cannot interfere with the equation of rationale.
Second – Now that you’ve got your head in the right space, take ownership. Ownership means taking the initiative and being proactive. In the case of a cybersecurity event, own it like you own the company. Care about all the details, there is no place for “good enough” when you’re resolving a cybersecurity event. A part of ownership is to listen to the ideas of others and voicing your own. A cybersecurity event isn’t just a single thread, it’s a tapestry of events, including events that can lead to a better posture for the future of your company. An event can and should lead to some degree of growth for the organization and your teams. Owning the event and being accountable for its resolution and the ideas that come of it, is your obligation as a leader. You define how the company, and you, look after the event. Did you shine? Or was it lackluster? Is it a roadmap of ways to grow? Or is it a wasteland that’s been ravished by a lack of ideas and ownership? It’s on you, you have the power to decide.
Third – If normal business is sunny with a slight breeze, a cybersecurity event is the surprise category 5 hurricane sweeping through the town. Pay attention to your people. You cannot get through a major incident on willpower alone, you can only get through it with careful planning, thoughtful resource management, and careful decisions. You may have a team of energized amazing people, but if you run them night and day for a week, or even longer, you’ve blown that spark out and once it’s gone, it’s really hard to get back. So, listen, and watch. Few people are going to openly tell you they are just unable to do the work, especially if your team is a high performing team, they want to show what they are made of, they’re going to be like a bull on ice, all that power with no place to apply it, and they’re going to burnout fast getting nowhere. Focus on wellbeing and the care of your teams. Make sure their lives aren’t completely engulfed by the whirlwind. Make sure they’re getting needed rest, make sure they’re getting breaks. Unrested teams and people make mistakes, giving the team time to breath is as good for them as it is for the event.
It’s too easy to forget what makes you a successful leader, it’s your people. Without empowered and energized people, you’re not going to maximize your teams success. Ensure they get what they need when they need it. Watch to make sure their tasks are useful and not wasting precious cycles sitting on a 2-hour call “just in case”. If you never stood up for your team before, be ready to protect them now.
Fourth – Be prepared to say “No”. Wait I just told you to take ownership and help where you can? Do I even know what I’m writing about? I do. Be prepared to say “no” to wearing your teams out, be ready to say “no” to the idea that everything can be done in a quarter of the time it’s actually going to take. Be prepared to say “no” to the emotions of people interfering with the resolution. You weren’t made a leader because of your looks; you were made a leader because of your potential in helping the company get to its goals. Be that leader, be the warrior standing on the cliff overlooking the troops, knowing they are looking up to you and ready to follow your lead; or whatever other cool analogy you want to use. Whatever you chose, stand as the pillar for your team, your peers, and your leaders to look at as inspiration. And the best way to do that is to use “no” with surgical precision not only for your team but others as well. You’re a leader, you aren’t tied to being one just for your team, help other leaders that are still getting their heads right, help other team members from running on ice full speed and not getting anywhere. Say “no” when you need to.
Fifth – Comm.Un.Ic.Ate. On a normal day, communication channels have been formed and nearly everyone knows who to call and when, based on why. This isn’t a normal day, thank goodness, and it’s not just one day, it’s most likely going to be many: it’s more like a micro-apocalypse and it’s happening in your company. Thinking your normal communication channels will suffice is an absolute farce. Your normal communication channels are old and designed for a certain rhythm, not the rhythm you’re living in right now; your old channels may even be compromised. Hopefully, you and your company have an Incident Response Plan and are executing it from day zero. But if you don’t, someone needs to decide how the event information moves through your company channels, and who gets to see it and or contribute to it. Any takers? You! Good on you for owning the communications challenge. Get the chain established and any repositories you may need set up. Get the proper audience added so they can access everything without asking. Own it like the success of your company depends on it because it does.
Communication may be the fifth point I made, but that does not mean that’s where it lies in priority. You can’t get anything done if you aren’t communicating with the response team, upward, and downward, horizontal, vertical, and diagonalwise (is this a word?), anyway you get the point, poignant precise communication where it needs to go. You want to control the audience of your event communications but you want them to have what they need at their fingertips. It will actually save you a lot of time as well; you don’t have to take a call or a meeting every time someone has a question about progress. If you don’t know who you can talk to or when, reach out to counsel and let them guide you. If you don’t know who you’re talking to, you probably shouldn’t be talking to them without guidance.
All humor and informality aside, an incident is a defining moment for leadership and the company. Studies have shown that how a company handles the incident, defines how they are viewed afterward. Will you be in a shining light of how to handle an incident, or will you be in the annuals of how not to handle an incident?



