Dynamic Business Logo

Let’s Talk: What cyber incident response steps should businesses have ready?

For a lot of small business owners, cybersecurity only becomes a priority once something has already gone wrong, by then, the damage is usually done.

Ransomware, phishing scams and data breaches can hit without warning, and the businesses that recover fastest are almost always the ones with a plan already in place before the incident happens. That means knowing who to call, what to lock down, and how to keep operating while the issue gets sorted.

In this week’s Let’s Talk, we put that question to our panel of experts: what cyber incident response steps should every business have ready, before something goes wrong.

Let’s Talk!

Vikas Tatwani, VP, Cloud, Infrastructure and Security Services, Infosys

“Most organisations discover gaps in their incident response plan during the incident itself, the most expensive time to learn them. A mature readiness posture starts well before any alert fires. It requires a documented and tested response plan with clear severity tiers, a named response team across technical, communications, legal and executive leadership, pre-approved playbooks for scenarios such as ransomware, data exfiltration and business email compromise, and an out-of-band communication channel if primary systems are compromised.

Equally critical is knowing whether detection and containment capabilities are ready in practice, including log retention, EDR coverage, network segmentation options and backup integrity, and validating them through regular tabletop exercises, not simply documenting them.

The organisations that recover fastest treat incident response as a muscle, not a document. That means quarterly simulations, pre-negotiated relationships with forensics and legal partners, and a communications plan for regulators, customers and the board.

After an incident, a genuine lessons-learned process, not a blame exercise, closes the loop and feeds improvements back into the plan.

Readiness is not about eliminating risk; it is about compressing the time between detection and controlled recovery, a leadership discipline as much as a technical one.”

Harshvendra Soin, President – Asia Pacific and Japan Business, Tech Mahindra

“Every leader I speak with across APAC and Japan asks the same question after an incident: “Could we have been readier?” The honest answer is almost always yes, and the gap is preparation.

“Scams no longer announce themselves. They arrive through a convincing invoice, a spoofed executive voice, a moment of trust exploited at speed. By the time an alert fires, the decisions that matter most are already made, or left unmade. Cyber Scam Awareness Week reminds us that resilience is not built in the middle of a crisis; it’s built in the quiet before one.

“So, what should every organisation have ready before something goes wrong?

“A decision map, not just a plan. Know who has the authority to contain, notify and speak before the clock is running.

“Rehearsed muscle memory. Plans tested through tabletop exercises, with business leaders in the room, not only technical teams, become instinct.

“A communication line already open. Internally and with regulators and customers, because silence reads as concealment.

“Restoration you have actually proven. Because a backup you have never recovered from is a hope, not a control.

“A culture where reporting a mistake is rewarded. Your people notice incidents before your systems do.”

Kumar Mitra, Commercial Leader, Greater Asia Pacific, Lenovo

“Cyber resilience starts long before an incident occurs. Organisations that recover fastest treat security as a business priority, with clear response plans, resilient technology and defined decision-making in place.

•       An effective incident response plan should be established before an attack. Organisations need a documented playbook defining roles, escalation paths, communication protocols and decision-making responsibilities. Regular tabletop exercises ensure teams can respond quickly and effectively under pressure.

•       A proactive security posture is equally important. This includes adopting Zero Trust principles, enforcing strong identity and access controls, maintaining continuous monitoring and logging, and regularly patching critical systems. Robust backup and recovery processes minimise downtime, while employee awareness helps reduce risks such as phishing and social engineering.

•       As AI becomes more embedded across the enterprise, security and response frameworks must evolve alongside it. Organisations need to understand where AI is used, protect the data and identities underpinning it, and extend security controls across the technology environment.

Ultimately, security should be embedded by design across the technology lifecycle, from infrastructure and applications to data, AI and the supply chain. This builds resilience, enabling organisations to detect threats earlier, respond faster, recover effectively and maintain business continuity as the threat landscape evolves.”

Dominic Del Guidice, Managing Director, Iron Mountain A/NZ

“Cyber threats are a reality for every organisation, which is why a well-tested incident response plan is essential. But effective response starts well before an incident occurs. Leaders need to understand what information and systems are most critical to the business, where that information resides, who is accountable for it, and how operations will be restored if access is disrupted.

Cyber resilience cannot sit with IT alone. Leaders across risk, operations, legal, communications and information management need a shared understanding of their roles, decision-making authority and the dependencies that could affect recovery.

Information-sharing across these teams is equally important. When people can quickly access trusted information and have clear escalation paths, they can make better decisions under pressure, prioritise recovery and communicate consistently with customers, partners and employees.

At Iron Mountain, we believe information resilience needs to be treated as a business capability, not simply a technology or security issue. Organisations that prepare their people, information and processes before an incident are better positioned to contain disruption, recover critical information and maintain business continuity.

Ultimately, the goal isn’t simply to respond to a cyber incident. It’s to build the resilience and confidence to keep the business operating when something goes wrong.”

Reuben Koh, Director of Security Technology & Strategy, APJ, Akamai Technologies

“During a cyber incident surge, whether a massive volumetric DDoS attack, a sophisticated API breach, or rapid ransomware propagation, the speed of your recovery depends entirely on the architectural foundations laid prior.

The Asia Pacific region alone has recorded the highest rise in bot activity and targeted API attacks, up 63% in 2025, driven by Agentic AI, resulting in a surge of these attacks over 30% year-over-year.

Businesses that recover fastest are usually those best prepared well before an attack occurs, with a security strategy grounded in their architecture.

Akamai recommends organisations to start with these 3 areas:

•       Continuous Discovery: Automatically map every web application, API endpoint, and digital asset across your estate to ensure exposed vectors are identified, analysed, and hardened before adversaries exploit them.

•       Assume Breach: Rapidly identify lateral movement exposure, isolate critical workloads and instantly contain compromised endpoints to stop lateral attack spread.

•       Secure AI Interactions: One of the fastest growing risks now is controlling how your employees use AI and how your own AI is being used. Attaining visibility and enforcing governance is a must.

Effective security foundations like the ones above can help organisations prevent a breach from turning into a crisis.”

Merlin Luck, Regional Director – Commercial, ANZ, Datadog

“Incident response should be viewed as a discipline you build before anything can go wrong.

Too many businesses treat incident response as something to figure out in the moment. The security industry has spent years watching the scoreboard while attackers learned to play the whole game. That’s precisely when things fall apart.

With AI-driven attacks now moving across entire systems in seconds, the old model of chasing individual threats no longer holds. Teams need a clear and live story of what’s unfolding – a unified, real-time view across logs, metrics, and traces. That single pane of glass is the difference between identifying a threat in minutes and discovering it days later, long after the damage is done.

Threats rarely announce themselves loudly. Subtle anomalies like unusual authentication patterns, unexpected network behaviour, and incremental changes in system performance are often the earliest signals. Without dynamic baselines understanding how systems normally behave, those signals get lost in the noise until it’s too late.

Visibility built before an incident provides the context to act decisively in the moment. For SMEs operating with lean teams and limited resources, understanding system behaviour, not just faster alerts or more detection rules, could be the difference between a contained incident and a catastrophic one.”

Scott Ellis, Regional Sales Engineering Manager, Check Point Software Technologies

“Today’s threat landscape has changed the question from if you’ll face an incident to when. Organisations that recover fastest are those that prepared before the alarm sounded, so:

•       Know your exposure first. Effective exposure management should provide a unified view across networks, cloud environments, endpoints, identities, SaaS applications and emerging AI workloads. Security teams need risk prioritisation based on real-world exploitability.

•       Have a tested playbook. Define roles, decision-makers and escalation paths, with constant rehearsals. In a live incident, hesitation could kill.

•       Assume AI is in the attacker’s toolkit. With AI part of both offensive and defensive operations, organisations need security controls capable of learning from global threat intelligence, identifying anomalous behaviour and preventing attacks.

•       Prevent, don’t just detect. Prioritise security controls that stop threats at multiple points in the attack chain like preventing initial compromise, blocking lateral movement and automatically containing malicious activity.

•       Prioritise platform consolidation and unified management. Seek integrated security operations, centralised visibility and consistent policy enforcement across network, cloud, endpoint and user environments.

•       Prepare your communications early. Have holding statements and stakeholder messaging ready, for customers, partners, regulators and suppliers.

The best incident response begins long before the incident.”

Mathew Graham, Chief Security Officer APAC, Okta

“The most effective incident response starts before there’s an incident to respond to. It starts with preparation.

Today’s organisations operate across multiple cloud platforms, applications and identity providers, with employees, contractors and increasingly AI agents accessing critical systems. That complexity creates more opportunities for security gaps and makes it harder to respond quickly if you don’t have visibility into who, or what, has access.

Before something goes wrong, organisations should understand who and what has access to critical systems, remove unnecessary access, strengthen phishing-resistant authentication where possible, build a culture where employees understand the role they play in protecting the organisation, and regularly test their response plans.

As AI becomes embedded across everyday business operations, organisations also need visibility into where AI agents are operating, what they can access, and confidence that the right identity and governance controls are in place throughout their lifecycle.

The organisations that realise the greatest value from AI will be those that build identity into their AI strategy from the outset. They’ll also be the ones best prepared to detect, contain and respond confidently when incidents occur.”

James Eagleton, Managing Director ANZ, Cohesity

“The most effective incident response plans start long before a cyber event occurs. While cybersecurity measures are essential for mitigating the risk of an attack, cyber resilience enables a business to withstand disruption and recover quickly when an incident does occur.

“Organisations recover best when they have prepared, tested, and practiced in advance. An effective incident-readiness plan should address five key areas:

•       “Map critical data locations across on-premises, cloud, and SaaS environments, including AI systems

•       “Fortify backup data with multi-factor authentication, role-based access, immutability, and isolated copies to ensure recoverability

•       “Detect and investigate threats early, including scanning backups automatically, as the usual security tools might be down during an attack

•       “Practise application resilience by rehearsing response and recovery processes for infrastructure, data, and applications, including the sequence for restoring critical services

•       “Optimise data risk by identifying where sensitive data resides and eliminate exposures such as unsecured credentials or storage.

“An incident response plan should clearly outline responsibilities, escalation paths, communication processes, and how critical systems and data will be restored after a disruption. The main challenge after a major incident is prioritising safe restoration by determining what must come first and what can be trusted. It’s not enough to assume backups will work when needed. Regularly testing response plans is essential for minimising disruption, maintaining customer trust, and ensuring businesses can operate with confidence.”

Robin Long, Regional CTO, APAC, Rapid7

“The best time to plan your response is before you need it. For SMBs, cyber incident readiness comes down to a few practical things you can put in place now.

First, have a written incident response plan – and test it. A plan that has never left the drawer can quickly fall apart under real pressure. Run a tabletop exercise with the people who would actually be involved: not just IT, but legal, communications/PR and leadership. That’s where you discover the gaps, such as who has the authority to take systems offline or how you’ll communicate if your usual email and chat systems are unavailable.

Second, be realistic about your internal capabilities. Most SMBs don’t have dedicated incident responders on staff, and the middle of a breach is the worst time to start looking for one. Arrange support in advance – whether through an incident response retainer, a managed detection and response (MDR) provider or another trusted security partner – so you have someone to call who is already familiar with your environment.

Finally, document your key contacts, escalation paths and notification obligations, including those under Australia’s Notifiable Data Breaches scheme, and make sure that information is accessible offline. If you’re locked out of your systems during an attack, you don’t want your response plan and critical contact details locked away with them.”

Daniel Garcia, Vice President and General Manager for APAC, Kaseya

“For Australian SMBs, surviving a cyber attack comes down to what you do before a breach happens. According to Kaseya’s 2026 Cybersecurity Outlook: Trends, threats & readiness report, 27% of organisations have an incident response plan but have never tested it, while a further 24% lack a formal plan entirely. A document that doesn’t exist cannot save your operations.

To avoid a prolonged operational freeze, you must have four fundamental steps ready to execute:

•       Prepare: Establish an incident response plan, including clear technical roles. Maintain offline contact lists, and prepare communication templates so your lean team is not improvising during a live crisis.

•       Detect & analyse: Deploy automated monitoring tools that quickly identify an active threat and accurately determine the scope of the compromise.

•       Contain & recover: Sequence your actions carefully by stopping the spread and eradicating the threat entirely before restoring data from clean, tested backups.

•       Review: Document the breach details and take preventative measures where the point of vulnerability was.

Without these structured steps, the response becomes disorganised chaos. If you have not built and run a simulated fire drill of this sequence, your business is operating under a false sense of resilience that could prove terminal in the worst instances.”

Robert Collins, Regional Solutions Architect APJ, SentinelOne

“ACSC received more than 84,700 cybercrime reports last year, roughly one every six minutes. For an Australian business, the first hour after a serious incident is usually crowded with partial information, operational pressure and questions from customers, regulators and staff.

Preparation buys options here. Decide who can isolate a device, suspend compromised accounts and engage the cyber insurer, forensic responders, legal counsel and communications advisers. Keep those contacts current, identify the systems and suppliers the business depends on, then rehearse the plan with the people expected to act.

Keep printed copies of the incident plan, key contacts and critical asset inventory as well. These materials are usually digital, and may be unavailable when systems have been encrypted or access has been cut off.

Investigators also need evidence to establish what happened. Maintain current asset records and logs, and keep protected, tested backups outside everyday administrator access. Avoid wiping or rebuilding a potentially compromised device before the relevant evidence has been captured.

Restoration should follow a clear view of how the attacker entered, what they reached and whether their access has been removed. Without that, a business can resume operations while the attacker still has a way back.”

Sean Nikkel, Team Lead, Cyber Threat Intelligence, Bitdefender

“Before an incident, the basics matter most: know where your important data lives, where the backups are, who has access to it, and what software is actually running in your environment. Have an asset inventory that captures dependencies, so you know what breaks when one system goes offline. Turn logging on and keep it running. Create an incident response plan and practice it with key stakeholders, ensuring they know their roles and responsibilities.

It’s also critical to know what “normal” looks like on your network. Attackers frequently use legitimate software and admin tools because they blend in with day-to-day operations, so without a baseline it is extremely difficult to spot an anomaly.

Two failures tend to show up repeatedly: backups that don’t restore, and no clear answer on who to call. Test your restores regularly, because a backup job completing successfully isn’t proof the data will come back. Keep a current contact list: internal decision-makers, your IT provider, legal, your insurer, and whoever you’re obliged to notify. The first time you test a restore or figure out who to call shouldn’t be during a real incident.”

Steve Hunter, Director Engineering – APAC, Arctic Wolf

“In a crisis, speed and coordination matter, and uncertainty can significantly increase the impact of an attack. Our new 2026 AI & Cybersecurity Trends Report found that more than 70% of ANZ SMEs have experienced a significant cyber incident, with many facing productivity losses lasting up to three weeks.

Before a cyber incident occurs, SMEs should have the following five steps in place:

•       Create and test an incident response plan so teams know who is responsible, how incidents are escalated, and what actions need to be taken.

•       Ensure 24/7 threat monitoring and response capabilities, either internally or through a trusted security partner. Our research found only 23% use an external partner for 24/7 monitoring and response.

•       Validate backup and recovery processes to minimise downtime and restore operations quickly following an attack.

•       Combine AI with human expertise. While 80% of ANZ SMEs believe AI improves threat detection, trust remains a challenge. The strongest security outcomes come from AI-powered insights backed by experienced analysts.

•       Prioritise operational resilience, not just compliance. Strong compliance does not automatically prevent disruption. Organisations need the ability to detect, respond, and recover effectively.

Preparation won’t prevent every cyberattack, but it can dramatically improve resilience, minimise disruption and accelerate recovery.”

Matt Caffrey, Senior Solutions Architect, Barracuda Networks

“The first step is to have the incident response plan written down before you need it. This document should clearly define team roles and responsibilities, with a cross-functional team that ties in members from IT, legal, communications and other groups within the business. Then identify potential security incidents your business may face and classify them based on severity, impact and likelihood to occur. It’s at this point where detection and response methods need to be documented alongside your communication strategy, covering the technology, processes and messaging required at each stage. Communication is where most plans fall short. Prepare holding statements for each scenario, talking points for spokespeople, and contact lists segmented by stakeholder group. And don’t forget to test the plan. Run simulated exercises for the scenarios most likely to occur, and for the ones that would hurt your business most.

Any incident response plan should be underpinned with consistent multifactor authentication and access controls, a robust approach to patch management and data protection, and regular cybersecurity awareness training for employees. Add a comprehensive, managed security platform and 24/7 managed XDR that integrates network, endpoint, server, cloud and email security, supported by a fully autonomous SOC. As attackers start to leverage agentic AI, the speed, scale and consistency of attacks will increase. Long-term security lies in cyber resilience.”

Andrew Kay, APJ Director of Systems Engineering, Illumio

“This is perhaps the most critical question every SME should be asking right now. Frontier AI is making it easier to perpetrate cybercrime at a scale and speed few organisations are prepared for. So much so that Australia’s cyber security agencies have warned organisations to assume breaches will occur and focus on fast containment and recovery. This advice represents an important shift, prioritising planning for what happens when attackers inevitably get inside.

Incident response plans should be designed around containment, with detection and recovery as key components. Strong controls over who or what can access critical systems, visibility into connections across the environment, and network segmentation help prevent attackers from moving freely from a compromised device or account to more critical systems. This means businesses need proactive lateral movement controls and clear processes for identifying and rapidly isolating compromised assets. Recent Illumio research found that while 95% of businesses can detect unauthorised access, only 17% can isolate a compromised system quickly. This gap is where the real danger lies and where a simple breach can escalate into a major incident.

The goal is to ensure that one compromised laptop, account, or application does not become a business-disrupting event. SMEs must put controls in place to limit what attackers can reach, isolate compromised systems quickly, and keep the business operating even when a breach occurs.”

Anthony Daniel, Managing Director, ANZ and the Pacific Islands, WatchGuard Technologies

“An incident response plan should be treated as a living document, one that’s reviewed and adjusted regularly. At a minimum, it needs to name who makes decisions when something goes wrong, how affected systems get isolated, who needs to be told, whether staff, customers, or regulators, and in what order.

The first hour of an incident is typically the most critical. Without a clear plan, teams lose valuable time working out roles and next steps instead of acting on them, and that delay often prolongs the issue, and in some cases, widens its scope. The Australian Signals Directorate’s latest Annual Cyber Threat Report found ASD’s ACSC responded to more than 1,200 cyber security incidents in FY2024-25, with the average reported cost to businesses up 50% to $80,850. Preparation is often the deciding factor in which side of that average a business lands on.

Employee security habits determine how effectively an organisation responds to a cyber incident. WatchGuard’s 2026 Cybersecurity Hygiene Report found 76% of employees reuse passwords and 50% access corporate resources without VPN protection. Practices such as multi-factor authentication and least-privilege access can reduce the number of entry points available to attackers and limit how far an incident can spread.

A practical starting point is to document the following key components: who leads the response, how systems get contained without guesswork, and a communication template ready to adapt under pressure. Most importantly, test the plan regularly. The first time a team works through its incident response process should never be during a real attack.”

Takanori Nishiyama, Senior Vice President, APAC, and Japan Country Manager, Keeper Security

“Effective incident response depends on preparation carried out long before anything goes wrong. When a cybersecurity breach unfolds, organisations that maintain clear control over who and what can access their systems respond faster and limit how far the damage spreads.

Preparation starts with hardening privileges and credentials. Enforce least-privilege access so every user, application and non-human identity holds only the permissions it needs, and replace standing administrative access with just-in-time elevation. Store and rotate privileged credentials in a secure vault to ensure a stolen password cannot become a persistent foothold.

Second, prepare for containment at machine speed. Armed with agentic AI, cybercriminals move laterally within minutes. Response plans should include automated controls that revoke credentials, terminate sessions and isolate compromised accounts the moment risky behavior is detected, rather than waiting for manual review.

Finally, unify visibility and control. Fragmented tools slow response because teams lose critical time pinpointing which identities can access which systems. A single point of control over identities, privileges and sessions gives responders an immediate, auditable picture and shortens containment from hours to minutes.

Organisations that treat identity and access as the foundation of incident response will contain incidents faster and limit damage when breaches occur.”

MJ Robotham, Director, APAC, NinjaOne

“The worst time to work out how your organisation will respond to a cyber incident is when systems are already going down. How quickly you respond depends on the preparation your team has done beforehand.

Start with visibility. IT and security teams need an accurate view of the devices, applications and systems across the organisation. If you don’t know what is connected to your environment, it becomes much harder to understand the scope of an incident or contain it quickly.

Businesses should establish clear responsibilities and escalation processes. Who needs to be notified? Who can isolate a compromised device? Which systems need to be restored first? Keeping systems patched can reduce exposure to known vulnerabilities, while reliable backups and tested recovery processes can help restore operations if systems or data are compromised.

Test run your plan. Running through different scenarios can expose gaps in responsibilities, access or recovery processes before they become real problems.

Cyber incidents can move quickly. Giving IT and security teams visibility, clear processes and the ability to act puts your business in a much stronger position to isolate the incident and recover.”

Chris Ellis, Director Solution Engineering, Nintex

“A breach is rarely what destroys a business. It’s chaos during response and recovery that truly cripples a business.

Without a well-defined process, the natural human reaction immediately after an attack can be to scramble, to rush, or to panic.

None of these reactions are helpful.

Each incident response stage – evidence preservation, internal escalation, stakeholder communication, regulatory notification, recovery – needs to be a robust, owned process with clear tasks and timelines. Processes need to be followed to ensure a cyber event doesn’t become catastrophe.

Communicating with stakeholders and notifying regulators are among the most critical steps. Whether it is customers, partners, or employees, each stakeholder requires clear and concise information to assure them you’re taking the appropriate steps to keep their information safe.

Regulators will require timely and consistent notifications. The last thing a business needs after a breach is to run afoul of compliance obligations.

Before a breach occurs, organisations should map out their incident response processes, clearly define ownership of each step, and automate key processes to ensure the necessary rules and governance procedures are followed.

After such a devastating event, the organisation cannot afford chaos. Process mapping and workflow automation can help ensure cool heads prevail.”

Jay Patel, Founder & CEO, Vrinsoft Technology

“A cyber incident may become visible when an alert appears, but the conditions that allowed it to happen may have existed for months. When that alert finally comes in, there is little value in debating what should happen next. The business needs to know how it will contain the problem, protect its most important data, understand what has been affected, and start getting key operations back on track. Those decisions are much easier to make when they have already been discussed and agreed.

Communication is just as important. During an incident, information can quickly become scattered across calls, messages, and different teams. I believe there should be one clear record of what is happening and what decisions have been made, with regular updates for the people who need to know. This allows the technical team to focus on dealing with the incident while the wider business stays informed, particularly when the situation requires external cybersecurity support.”

Craig Stockdale, ANZ Country Managing Director, Wasabi Technologies

“Unfortunately today it’s not a matter of if, but when organisations will face a cyberattack so it’s never been more important to make sure you’re ready to counter and recover from one, when it happens. The best time to act is now. Recent research we have conducted suggests only 45% of ANZ organisations are actually confident they can keep their data operational and unaltered after a cyberattack – a worrying preparation gap. Organisations need to be able to act swiftly and effectively as ransomware attacks rise, and cybercriminals increasingly target backups. The first thing you can do to combat this is to establish an off-site, secure immutable copy of the critical business data. Meaning preventing your data from being changed, deleted or modified, through a feature called Object Lock, which protects it from malicious activity or ransomware attack. And you can go one step further, by establishing this copy of critical data hidden and isolated from normal access, because after-all, a cyber-criminal can’t touch what they can’t see.

Pairing this with multi-user authentication adds another protective layer. Setting up multiple trusted administrators to approve access to critical data is especially important if one account becomes compromised, as it stops the hacked account from accessing the backups. Once you have these features in place, testing your recovery and rate of efficiency is just as important as the implementation and organisations need to account for this in their BC plan.

The true mark of an organisation’s cyber resilience is dependent on its ability to not just identify an attack but to contain it quickly and effectively before further compromise. Then if compromised, to restore quickly from a safe, secure and off-site protected copy of the critical business data.”

Geoff Schomburgk, Vice President for Asia Pacific and Japan, Yubico

“The worst time to design your cyber incident response plan is when an attacker is already inside the business.

Every organisation should have a simple, tested playbook that clearly defines who makes decisions, who communicates with employees, customers and regulators and how critical systems will be contained and restored.

But what to do before something goes wrong? The best place to start is with identity. Compromised credentials remain one of the fastest ways attackers gain access. Phishing-resistant MFA, such as passkeys or hardware security keys like YubiKeys, should be deployed to protect not only administrators but all high-risk users before an incident occurs.

Businesses should also maintain secure, tested backups and establish alternative communication channels in case email, collaboration platforms or corporate devices are unavailable.

Importantly, incident response cannot simply be a document stored somewhere in IT. Run exercises that simulate ransomware, phishing or account takeover so executives understand their roles and gaps are identified early.

Cyber resilience is ultimately about preparation. The organisations that recover fastest are usually those that have already decided what they will do when something goes wrong.”

Darren Hopkins, Partner, McGrathNicol

“Having assisted organisations with hundreds of cyber incidents each year, I’ve learned that effective incident response starts long before an attack occurs. Every SME should have a documented response plan, tested backups, clear lines of decision-making and access to trusted technical, legal and insurance advisers. Regular tabletop exercises are equally important, allowing leaders to rehearse their response in a low-pressure environment and identify gaps before a real incident occurs. While no organisation can eliminate cyber risk entirely, those that invest in preparation are generally able to respond faster, minimise disruption and recover with greater confidence when an incident arises.”

Michael Cossetto, Partner, Corporate and Commercial, Bartier Perry

“Cyber incident response is not something an SME should invent in the first hour of a crisis. Before anything goes wrong, business leaders should approve a simple, tested response plan that identifies who leads, who communicates, who makes legal and commercial decisions, and which IT, legal, forensic, insurer and communications advisers can be called immediately. This is consistent with the recommendations of the Australian Signals Directorate, a Commonwealth Government organisation which provides information and resources about national security, including cyber security.

Small businesses should also get the basics right in advance including multi-factor authentication, software updates, reliable backups, staff awareness, an emergency plan, and a clear understanding of critical data and systems. The plan should anticipate containment, evidence collection, recovery from clean backups, stakeholder communications and post-incident review, so decisions are made calmly and consistently.

In Australia, SMEs that handle personal information should know whether the Privacy Act and Notifiable Data Breaches scheme apply. If they do, the cyber incident response plan should include a triage process to determine if the breach is likely to cause serious harm and the steps to notify (if required) affected individuals and the OAIC (Office of the Australian Information Commissioner).”

Allan James Waddell, Founder & Co-CEO, Kablamo

“The thing that catches people out is accountability. When an incident starts, everyone assumes someone else owns the problem, and you burn the first hour working out who is actually in charge.

“So before anything goes wrong, work out which systems and data the business really depends on, and name the people who need to be in the room when one of them is compromised. Settle in advance where one provider’s responsibility ends, and the next one starts.

“AI has made that harder, and I don’t think most companies have caught up yet. A lot of AI has arrived inside software businesses already use, including agents that can hold real credentials and act on your behalf. Most incident plans were written with human actions in mind, but an agent can do a lot in ninety seconds.

“Then test it. Start with small, nimble teams. Run a drill on an AI scenario, such as an agent taking an action nobody approved, or company data ending up inside a model where it should not be. One bad rehearsal teaches you more than a very good document.

“It comes back to accountability. You own the outcome even when a model made the call.”

Richard Valente, Vice President Customer Experience Strategy, TP

“Cyber incidents are no longer a question of “if” but “when”, so businesses need a response plan in place before the pressure hits.

The first step is knowing exactly who is responsible for what. Have a clear incident response team, defined roles and escalation processes, so there’s no confusion about who makes decisions when something goes wrong.

Businesses should also have a clear Business Continuity Plan (BCP) ready. That means knowing how you will communicate with employees, customers, partners and regulators, and who is authorised to speak on behalf of the organisation.

I’d also recommend regularly testing your response plan. A plan that sits in a drawer isn’t much use during a crisis. Run simulations to identify gaps and make sure your people understand what they need to do.

Finally, don’t overlook the customer experience. During a cyber incident, customers can quickly lose trust. Clear, timely and empathetic communication can make the difference between a difficult incident and lasting reputational damage.

Preparation is ultimately about reducing uncertainty. The better prepared you are, the faster and more confidently you can respond.”

Amanda Lacey, Director, Popcom

“The biggest mistake businesses make with cyber incidents is treating them purely as an IT issue. A cyber incident can very quickly become a business continuity, communications and reputation crisis.

Preparation means knowing exactly which systems matter most; POS, customer data, email and social accounts — and having a contact list ready for IT support, hosting providers, banks, insurers and key advisers. You don’t want to be searching for this information mid-crisis.

When something happens, the priority is containment: secure compromised accounts and systems while preserving evidence of what occurred. At the same time, activate a clear response team covering leadership, IT/cyber, legal and communications.

Businesses should also know in advance who has authority to communicate and how employees, customers and other stakeholders will be reached if normal systems are unavailable. This information should all be at hand in a crisis response plan.

From there, notify affected parties and relevant organisations quickly, including banks where payments are involved and government reporting channels such as ReportCyber.

You won’t have every answer immediately. What matters is responding quickly, communicating clearly and demonstrating that the organisation has control of the situation.”

Vanessa Emilio, Principal Lawyer and Founder, Legal123

“Cyber response planning is usually treated as an IT job, but half of it is legal, and the legal half has statutory deadlines.

Under Australia’s Notifiable Data Breaches scheme, once you suspect personal information has been compromised, you have 30 days to assess it, and if serious harm is likely, you must notify the OAIC and the affected individuals.

So before anything goes wrong, have four things ready.

First, a one-page response plan that names who makes decisions, who contacts your lawyer, insurer, and IT support, and who communicates with clients.

Second, a current map of where customer data actually lives, including the third-party tools holding it.

Third, check your client agreements and privacy policy: many business contracts now require you to notify clients of a breach within days, and your policy must match what you actually do.

Fourth, if you hold cyber insurance, read the conditions now, because insurers routinely deny claims when basic safeguards weren’t in place.

The owners who recover fastest made these decisions calmly in advance, not at midnight during the breach.”

Michael Russell, Managing Director, Finwave Finance

“Most SMEs think about cyber incidents the way most people think about estate planning. They know they should have something in place, they intend to get around to it, and they do not until it becomes urgent. By then the cost is already running.

The preparation that matters most is not technical. It is operational. When something goes wrong, people in your business need to know three things immediately, who makes decisions, who gets called, and what stops now.

Start with a one page response document stored somewhere other than your network. If your systems are compromised, a plan stored only on those systems is inaccessible when you need it. That document should list your IT contact, your cyber insurance policy number and claims line, your legal contact, and the personal mobile numbers of people who need to be notified.

Next, containment before communication. The instinct to notify customers or post publicly is understandable but often premature. Isolate affected systems first, preserve evidence, and get advice before making any external statement. Premature disclosure without facts creates a second problem on top of the first.

Run a basic tabletop exercise once a year. Sit your key people down, describe a breach scenario, and walk through what each person does. The gaps that exercise exposes are exactly what your plan needs to cover.

Preparation is not about preventing every incident. It is about not losing a week of your business when one happens.”

James Finlay, Lead Director of Incident Response, APJ, Coveware by Veeam

“Before an incident happens, the real test isn’t whether you think you’re prepared, it’s whether you can prove it. Backups are the starting point: three copies of your data, on two different media types, with one stored offsite and one kept immutable or air-gapped. Just as importantly, those backups need to be tested regularly so you know they can actually be restored when needed.

Beyond backups, there are a few decisions that should be made well before a crisis. Know what data you have, where it lives, and how quickly you can recover it. Be clear on who has the authority to make decisions around ransom demands, communications, and operational shutdowns. And run a tabletop exercise, preferably with leadership involved, using a scenario the team hasn’t already practised.

From what we see at Coveware in incident response engagements, organisations that invest time in this preparation tend to make better decisions and recover more effectively under pressure. Staff training also matters because recognising the early signs of ransomware can make a significant difference. Finally, don’t wait until an incident to figure out who to call. Having forensic, negotiation, and legal support lined up in advance can save valuable time when every hour counts.”

Pam McKean, Director, AB Health Group

“This is not a hypothetical warning, it’s literally something I helped a client deal with last week.

A cyber incident had occurred, so I helped the client take immediate control of the situation. We appointed the person responsible for leading the response, contacted their IT provider, identified which systems and accounts needed to be shut down or isolated, and determined which employees and clients needed to be informed. We also worked through whether the incident needed to be reported to their insurer, legal advisers or relevant regulators.

That is not the time to start creating your response plan.

Every business should already know who will take charge, who needs to be contacted, where sensitive information is stored and how affected systems will be isolated. Critical data should be backed up securely, those backups should be tested, and employees need to know how to report suspicious activity immediately and without fear of blame.

Most importantly, practise the plan. When something goes wrong, speed, clear responsibilities and calm communication can be the difference between a contained incident and a much larger business crisis.”

Gareth Cox, Vice President Sales, Asia Pacific and Japan, Horizon3

“Before an incident, organisations should prepare to answer five questions: What matters most? How could an attacker get in? Would our controls detect and stop them? Who owns each response decision? Can we recover and prove the attack path is closed?

That means maintaining an accurate inventory of critical assets and identities; defining escalation, communications, legal, customer and regulator contacts; protecting offline backups; and rehearsing scenarios such as compromised credentials, ransomware, cloud-account takeover and loss of remote access. Exercises should test decisions and handoffs, not just technical playbooks.

Continuous Threat Exposure Management strengthens this readiness by turning preparation into a continuous operating cycle: scope the attack surface, discover exposures, prioritise based on business impact and threat relevance, validate what is actually exploitable, and mobilise remediation. Horizon3.ai’s NodeZero helps by safely emulating real attack techniques across infrastructure, identity and cloud environments, showing attack paths and whether controls work. After fixes, teams can retest to verify that the path is closed—not simply that a ticket is marked complete. That evidence helps security, IT and leadership focus on the risks most likely to affect the business and improve response plans before an incident occurs.”

Michael Mastrodimos, Founder & Creative Director, Peanut Productions

“Any form of Cyber incident will never arrive with a convenient warning. Whether it’s a compromised email account, ransomware, stolen data or an employee clicking the wrong link, how an individual and then the broader business responds in those first few hours can make a huge difference.

We have a simple Cyber Incident Response Plan that addresses four key questions:

•       Who takes charge?

•       Who needs to be contacted?

•       How do we contain the problem?

•       How do we keep the business and/or individual operating?

We have key individuals who form a small response team who deal directly with our IT Team who then work with the rest of the team to ensure we’re all protected and informed while the incident is being worked through and resolved.

We clearly understand and are mindfully aware of how our critical data is stored, maintain secure backups and regularly test that we can actually restore them. Just as importantly, establishing how we communicate with our team, customers and other stakeholders if normal channels are compromised is openly discussed and documented.

You simply can’t anticipate every possible scenario but you can have a clear and tested plan that helps your team respond quickly, calmly and confidently when something unexpected happens… because at some point, it will!”

Martin Creighan, Vice President for APAC, Commvault

“New findings from Commvault’s State of Data Resilience ANZ 2026 report reveal a persistent gap between business expectations and operational reality. While executives increasingly expect their organisations to return to operation within just a few days after a cyber incident, the reality is that recovery often takes weeks.

For Australian organisations navigating an increasingly complex threat landscape, the best cyber incident response plan starts long before an attack happens. Organisations should have a well-documented, regularly tested recovery strategy that goes beyond backups to validate the entire recovery process. That means bringing IT infrastructure and security teams together to define clear roles, responsibilities and communication pathways before an incident occurs.

Detailed runbooks and playbooks are equally important, especially for recovering complex workloads such as identity systems. These provide repeatable, tested procedures that reduce uncertainty and help teams respond with confidence under pressure.

Finally, organisations should regularly test recovery in an isolated cleanroom environment. Cleanrooms provide a safe, cost-effective way to simulate cyber incidents, check recovery plans and identify gaps without disrupting business systems. When recovery is practised as often as response, organisations can significantly reduce downtime, restore trusted operations faster and build greater cyber resilience when the unexpected happens.”

Dmitry Volkov, CEO, Group-IB

“Incident response is reactive by definition. Making it faster with AI does not solve the problem. If attackers and defenders both operate at machine speed, we risk the same growth in incidents at greater speed and scale. To change the game, organisations need to move from reactive response to prediction-first. That means doing the work before an incident happens. Organisations need to continuously convert internal and external signals into predictive threat intelligence, attribute threats to the adversaries behind them, and anticipate their next move.

“This also requires Cyber-Fraud Fusion: bringing cybersecurity and anti-fraud intelligence, signals and investigations together. Combining both gives organisations a stronger ability to understand an adversary and act before financial or operational impact. But no organisation can predict and prevent everything. Senior management must be ready to decide under pressure — who has authority, when to isolate or shut down systems, how to communicate, when to involve law enforcement, and how to keep the business operating.

“These decisions cannot be learned during an incident. Management needs to practice them through realistic exercises. The objective isn’t simply to respond faster. It’s to predict and prevent what we can and prepare for what we cannot.”

Marc Beder, General Manager APAC, 11:11 Systems

“A cyber incident can quickly escalate into a business crisis. Organisations that respond effectively are those that make critical decisions and preparations before an attack occurs.

First, establish clear roles, escalation paths and decision-making authority across technical response, communications, legal and regulatory obligations. Have backup communication methods ready if normal systems are compromised.

Identify critical systems, applications and data, and determine restoration priorities. Fast identification and containment can limit an attacker’s dwell time and reduce operational damage.

Backups are a critical line of defence for data retention, compliance and recovery. They should be protected, immutable or air-gapped, supported by documented restoration processes and regularly tested. Recovery should, where possible, occur in an isolated environment to validate data before returning systems to production.

Recovery speed is also critical. With downtime costing an average of $150,000+ per hour, relying solely on backups can leave organisations exposed to significant revenue loss, customer churn, SLA penalties and reputational damage. Working with an expert recovery services provider is the best way to minimise downtime.

Finally, regularly practise the incident response plan through tabletop exercises and review lessons learned after incidents.

The goal is to reduce uncertainty, accelerate recovery and turn incident response from a reactive scramble into a structured business process.”

Christopher Rule, General Manager of Defence, GME

“Cyber incident response needs to be planned well before an attack occurs. Every organisation should have a clear, regularly tested response plan that defines who is responsible for identifying, containing and recovering from an incident, and when to engage external cyber specialists, law enforcement and regulators. Businesses should also design and implement a network architecture that protects the ‘crown jewels’, minimising the damage when crisis strikes.

Consider ‘Zero Trust principles’ when building and operating information networks: know where critical data and systems reside, segment networks, maintain secure offline backups, control access, and establish procedures to isolate compromised environments quickly. Just as importantly, communications protocols should be prepared in advance so employees, customers and stakeholders receive accurate, timely information if a breach occurs.

Attackers increasingly use phishing, social engineering and ransomware to access sensitive operational data, intellectual property and personal information. When an incident happens, uncertainty compounds the damage. Preparation is key to minimising damage. Design networks to optimise prevention and support recovery. Regular simulations and tabletop exercises help identify gaps, clarify decision-making and ensure teams respond quickly. Cyber resilience is about prevention, response and recovery: be ready for the attack, contain its impact, and restore operations safely.”

Samuel Spencer, CEO and Co-Founder, Aristotle Metadata

“A cyber incident response plan is only useful if your team knows how to use it before something goes wrong. Start by having a clear, documented plan that sets out the steps people need to follow to recover from an incident, such as a system failure.

It’s also important to know who is responsible for responding. This shouldn’t sit with just one person — establish a rotating schedule so there is always someone ready to respond. At Aristotle, our planned updates and incident responses have two key roles: the operator, who performs the recovery steps, and the spotter, who observes the operator and documents any deviations from the plan. This keeps the operator focused on resolution while ensuring there is a reliable record of what happened.

Finally, practice. If your first recovery attempt happens during a real incident, the pressure can make an already difficult situation harder. Regular drills help your team build familiarity with the process, identify gaps and respond with greater confidence when something goes wrong.”

Evangeline Bassett, Strategic Communications Associate, Sally Branson Consulting Group

“Most businesses plan for the technical side of a cyber incident and forget the human side. You can have the best IT response in the world and still come out of it looking unprepared. That’s because nobody planned what to say, when to say it, and who should say it.

Any company should prepare three things before anything goes wrong. First, a communications plan that sits alongside your IT response plan, not after it. Decide now who speaks for the business, who signs off on external statements, and who talks to staff, customers, regulators, and the media.

Second, pre-drafted holding statements. You won’t have all the facts in the first hours, and you shouldn’t pretend otherwise. A ready template can acknowledge the issue and commit to updates without speculating on cause or scale.

Third, a clear internal approval chain. A breach or outage is damaging enough on its own, but the fallout is worse when a business goes quiet and leaves customers and stakeholders in the dark, as we have seen with Optus in recent years. Speed and consistency in the response won’t undo the incident, but they make rebuilding trust easier.”

Jamie Norton, Vice Chair, ISACA Board, ISACA

“The worst time to figure out your cyber incident response plan is during a cyberattack. Preparation is what separates a manageable disruption from a business crisis.

ISACA’s State of Cybersecurity 2025 found that while 50% of Australian cybersecurity professionals believe an attack on their organisation was likely in the next year, only 35% were confident in their team’s incident response capabilities.

Every business should have a documented incident response plan that clearly defines roles, escalation paths and communication responsibilities for employees, customers, suppliers and regulators.

Maintain secure, offline backups of critical systems and regularly test that they can be restored. Many organisations only discover their backups are incomplete or unusable when they need them most.

Know who you’ll call before an incident occurs. Establish relationships with your IT provider, cyber insurer, legal advisers and forensic specialists so support can be activated immediately.

Finally, don’t let your response plan gather dust. Test it regularly through tabletop exercises to identify gaps, build confidence and ensure your team can act swiftly under pressure.

Cyber resilience means being ready to respond quickly, minimise disruption and recover when something does go wrong.”

Nirlep Adhikari, Founder & Director, Mount Mindforce

“Most businesses prepare for a cyber incident the same way they prepare for a fire. They don’t, until there’s smoke.

Here’s the minimum you need before something goes wrong.

First, know what you actually have. You cannot protect what you haven’t mapped. Document every system, every integration, and every place customer data lives. If you can’t answer that in ten minutes, that’s your first problem.

Second, know who makes the call. When something breaks at 2am, there should be one person with the authority to isolate systems, notify stakeholders, and engage your incident response team. Committees don’t work in a crisis.

Third, know your notification obligations before you need them. If personal information is involved, Australian businesses may have to notify the OAIC and affected customers, and the clock starts the moment you become aware. Decide now who assesses that and who drafts the comms, because working it out mid-incident is how businesses turn a bad day into a legal problem.

Fourth, test it. An incident response plan that’s never been stress-tested is just a document. Run a tabletop exercise. Find the gaps before an attacker does.

The businesses that recover fastest aren’t the ones with the most sophisticated security. They’re the ones who knew exactly what to do before it happened.”

Beth Hall, Workplace Culture Expert and Founder, Culture Edge

“It isn’t enough to simply have a cyber policy, risk register and mandatory annual cyber training. If your organisation is serious about limiting the damage from a cyber incident, it also needs to build a response culture.

A response culture is one where employees feel safe and empowered to speak up immediately when something doesn’t look right – even if they clicked the link, shared the information or made the mistake.

Employees learn over time what happens when people make mistakes, admit an error or raise a concern. If mistakes are punished, blame is assigned quickly or people are rewarded for appearing competent at all costs, employees are far more likely to hesitate or try to fix the problem themselves.

In a cyber incident, those lost minutes or hours matter.

So alongside asking whether your incident response plan is ready, leaders should ask: have we created a culture where people will speak up immediately when they notice something isn’t right, even when they’re the cause of the problem?”

Jojo Lao, Co-founder, AIBUILD

“The worst time to work out your cyber incident response process is after an attack has already started. Businesses need to prepare their people as carefully as their systems.

Start with clear verification and escalation habits. Requests to move money, change bank details or reset credentials should be confirmed through a secondary trusted channel, and staff should feel empowered to slow down even an urgent request from senior leadership if something does not look right.

Businesses should also have one simple reporting path so employees know exactly where to raise a concern, without worrying about being blamed for a false alarm. Early reporting can make a significant difference to how quickly an incident is contained.

Behind that, organisations need a tested response plan: clear decision owners, secure backups, documented critical systems, alternative communication channels and regular incident simulations.

It is also increasingly important to understand which AI and cloud tools employees are actually using; you cannot contain an incident in a system you did not know existed.

Ultimately, cyber resilience is as much about culture and preparation as it is about technology.”

Kathryn Giudes, Managing Director, ORCA Opti

“Governance has to move beyond policies that only come out when an auditor arrives. It needs to operate in real time, embedded into everyday decisions. Whether someone is accessing sensitive information, using AI tools or responding to a potential security event, organisations need confidence that policies are being applied consistently, activity is being recorded automatically, and the evidence to support decisions is available when it’s needed. Months later during a compliance review is not enough. When governance becomes operational rather than procedural, responding to incidents is faster, more informed and far less disruptive.

Modern policies also need to recognise that AI has become part of the cyber risk landscape. For many organisations, the greatest risk is not the AI they have approved, it is the public AI tools employees are already using without visibility or control. ORCA Opti Assist provides employees with a secure, Australian-hosted AI assistant where governance is built into every interaction, helping organisations reduce shadow AI, protect sensitive information and create the evidence needed to support stronger cyber resilience and future compliance.

Finally, do not wait for a crisis to discover whether your plan works. Monthly tabletop exercises, informed by the latest trends, tested backups and continuous monitoring build the organisational muscle memory needed to respond quickly and confidently.

The first step does not have to be complex. ORCA Opti Assist Free gives organisations a governed, Australian-hosted AI assistant that helps replace unmanaged public AI tools with a secure, policy-controlled alternative. Reduce shadow AI while building the evidence and governance needed for future compliance.”

Bobby Haeri, Director, Acquisition House

“Having built and sold a much larger business before starting Acquisition House, one lesson I’ve carried with me is not waiting until you reach a certain size to put proper controls in place.

Our clients trust us with sensitive financial information while we help them make significant investment decisions. That comes with a responsibility to protect it.

For us, that means having the basics in place before something goes wrong: two-factor authentication, appropriate access controls, secure backups, knowing what sensitive information we hold and where, and having a clear response plan. You should know who takes charge, which technical and legal specialists to call, and how you communicate with anyone affected.

As a business owner, you don’t need to be the cyber expert in the room, but you do need to know who to bring into it before something goes wrong. The technical response can be handled by specialists, but the responsibility to be prepared cannot be outsourced.”

Bharat Joshi, Founder, Core Communications

“At the moment an incident unfolds, the CEO is asking what to say, legal is deciding what cannot be said, and the communications lead has 40 minutes before a journalist calls. At that point, the security team’s technical capability is only part of what determines the outcome.

The bigger question is whether those conversations happened before the incident. In a cyber incident, people rarely remember the forensic details. They remember how the business communicated and that gap can become a crisis multiplier.

Along with a technical response plan, an organisation needs a shared communications playbook that gives every stakeholder a common point of reference. That’s where the ASCERTAIN framework comes in. It starts by putting the right people and decisions in place before the pressure arrives: appointing communications lead early, map how regulators, customers, staff, investors and media will need information, prepare holding statements, establish a single source of truth, test secure backup channels, track regulatory obligations across jurisdictions, and regularly bring communications, legal, technical teams and executives together for simulation exercises. When those foundations already exist, the response becomes coordinated instead of reactive.

This preparation should extend beyond the incident response team. The board should already understand the organisation’s cyber risk posture and communication approach before a crisis, and media relationships should be built long before they’re tested. Both these stakeholders makes it easier to make decisions, communicate with confidence, and maintain credibility under pressure.”

Maxime Cousseau, CEO, OutsourcedCISO

“The worst time to decide how your business will respond to a cyber incident is when one is already unfolding. Preparation should focus on removing as many avoidable decisions as possible before the pressure hits.

Start by identifying your critical systems, sensitive data, backups and key credentials. Then make sure your Incident Response Plan is current and accessible, even if your normal systems are unavailable. Define who leads the response, who makes technical and business decisions and who approves communications.

You should also know exactly who to call, including IT, legal, cyber insurance, forensic specialists, communications advisers and relevant regulators. Understand your notification obligations, agree on recovery priorities and have alternative communication channels ready if email or collaboration platforms are compromised.

Just as importantly, test the plan through regular tabletop exercises. Maintain clear decision and action logs and plan for incidents that may last days, including staff rotations and welfare.

The objective is not to predict every scenario. A strong response plan provides structure, accountability and clear principles while allowing the business to adapt as new facts emerge.”

Monique Haylen, Founder, MINT PR

“A cyber incident response plan shouldn’t stop at the technical response. It also needs to prepare the people who will make the decisions when something goes wrong.

Before an incident, I recommend building a simple leadership response flow into the plan, agreeing on three things in advance: who has the authority to make critical decisions; how information will flow from technical teams to leadership; and who communicates with employees, customers and other stakeholders, and when.

Having worked with organisations across industries, from airlines to technology companies, when things haven’t gone to plan, I’ve seen how quickly a situation can move. You don’t want to be figuring out who makes the call, chasing information or debating what can be said when you’re already in the middle of it.

This isn’t about scripting every possible response. It’s about giving leaders a framework to make good decisions quickly, communicate clearly and adapt as the situation changes.

Technology will help contain and recover from a cyber incident. But how an organisation responds will shape the confidence and trust of its customers, employees and other stakeholders long after the systems are back online.”

Keep up to date with our stories on LinkedInTwitterFacebook and Instagram.

Yajush Gupta

Yajush Gupta

Yajush writes for Dynamic Business and previously covered business news at Reuters.

View all posts