Complete Coverage
Comprehensive analysis and operational guidance.
The chief information security officer of a Fortune 500 financial services company presented his crisis preparedness framework to the board. It was a comprehensive document: 47 pages covering threat intelligence, penetration testing results, security operations center metrics, incident response procedures, and a business continuity plan organized around a tiered recovery priority matrix.
The board approved a $40 million budget increase for the following year. Three months later, a critical system failure — not a security breach, but a database corruption caused by a firmware bug in a storage array — took down the company's primary customer transaction system for 11 hours. During those 11 hours, the company could not process transactions for its largest clients. The financial impact was measured in hundreds of millions of dollars. The CISO's framework had not identified this failure mode. The board had approved $40 million for threats that were not the actual threat.
This is the central failure of enterprise crisis preparedness as currently practiced: the frameworks are built around the threats that are easiest to describe and measure, not the threats that are most likely to cause harm.
The Gap Between Frameworks and Reality
The enterprise crisis preparedness industry — the consulting firms, the standards bodies, the compliance frameworks — has built an elaborate structure of best practices, certification programs, and audit checklists. Most of it is not wrong. The practices it describes are sensible. The frameworks are internally consistent. They are based on real incidents and real failures.
The problem is that they describe the last crisis, not the next one. The standards are developed by analyzing what failed in previous events — a data breach at a major retailer led to requirements for point-to-point encryption, a ransomware attack at a healthcare system led to air-gapped backup requirements, a DDoS attack at a financial institution led to CDN requirements. Each control is a response to something that happened, not a prediction of what will happen.
The actual threats facing enterprise technology systems are more mundane and more dangerous than the sophisticated attack scenarios in the typical crisis preparedness framework. The most common cause of enterprise system failures is not nation-state attackers or zero-day exploits. It is configuration errors. It is failed storage arrays. It is network partitions that split a distributed database into isolated partitions that diverge in state. It is cascading failures where the primary failure was manageable but the backup systems did not fail over correctly.
These failure modes are not glamorous. They do not appear in threat intelligence reports. They are not what boards imagine when they approve a cybersecurity budget. They are, however, the actual events that disable enterprise systems and damage enterprise brands.
What Crisis Preparedness Actually Requires
The crisis preparedness framework I build for enterprise clients has four components. None of them are novel. All of them are consistently missing from the frameworks that enterprises currently operate under.
Component one is a failure mode inventory. Before the organization can prepare for crises, it must understand specifically what can fail. Not in the abstract — not "our systems can be compromised" — but in the specific: which systems, under what conditions, with what consequences, and with what probability. This inventory must be maintained current, updated with every significant architectural change, and reviewed by the leadership team that owns the risk.
This sounds like a straightforward exercise. I have done it for dozens of enterprises. The typical finding is that the organization has a much less complete understanding of its failure modes than it believed, and the failure modes it has identified are not the ones that actually cause the most harm.