What to do in the first 12 hours

    of a Cyber Attack?

The CIO felt honoured when he              keynotes unique, clear and precise in      Prof Marco Gercke is an
         received the invitation to speak  analysing the status quo, entertaining,    entrepreneur, global thinker,
         at a closed event. When his       illustrative and at the same time full of  writer and advisor who
limousine arrived at the conference        “actionable” information.                  focuses on top management
venue where he was supposed to give                                                   issues related to
his keynote he had to pass through a       Speaking about “actionable”                Cybersecurity, such as cyber
security check with a metal detector.      information – the question about           threats, crisis response,
What he did not realize was that when      what decision makers should focus          risk management and
his phone went through scanning            on during the first day, week and          decision making. Over the
it was opened and an interception          month of an attack is among the most       last 15 years he has worked
device was installed.                      frequently raised. Mainly because          as an expert for various
                                           the challenges for those who need          international organisations
After months of successful                 to go through risk management              such as the United Nations
interception the whole case                processes and ultimately take              and advised governments
was investigated and it turned out         decisions fundamentally differ from        and government experts
that the “conference” was organized        procedures applied with regard to          from over 100 countries as
by criminals with the sole aim to          usual threats. Usually the first days      well as the top management
manipulate the CIO’s phone.                are required to collect the basic facts.   of Fortune 500 companies.
The story clearly underlines that top      Decision making during this time           The Cybercrime Research
management moved into the focus of         might feel necessary however it is the     Institute that he founded
offenders.                                 time period where most fundamental         is today one of the best
                                           mistakes are made. Consequently it         connected independent think
After the Target CEO lost his job          is the period where most guidance is       tanks dealing with this topic.
due to a devastating cyber-attack,         required. n                                Here he speaks about the
decision makers started to wonder                                                     role of top management in
what role they needed to play in this            “Challenges                          crisis handling.
highly technical environment. And if           from a cyber-
there is a role to play – what are the          attack differ
industry best practices?                     fundamentally

Marco has been in the room as advisor              from other
when top managers or ministers                         threats.”
were confronted with an attack
and had to take decisions. His rich
experience of advising some of the
most influential decision makers
in politics and business make his

