In the second of a series of Festive Stories, Chief Consultant Lawrie Abercrombie takes us through a journey of cyber security discovery through the lens of Charles Dickens.
In A Christmas Carol, Scrooge is warned by Marley’s ghost to change his ways before it’s too late. Many boards and executives today ignore similar warnings about cyber resilience, until the Ghost of Breaches Past arrives in the form of a catastrophic incident. The question isn’t if your organisation will face a cyber incident; it’s when. And when it happens, the speed and clarity of your response will determine whether you emerge stronger or suffer lasting damage.
Incident Response matters because cyber incidents are no longer rare shocks, they are becoming routine crises. As Robert Davis, author of ‘Cyber Security 101: Mastering the Fundamentals of Cybersecurity’ puts it:
“Effective incident response relies on two things: information and organization”.
Without a tested plan, chaos reigns. Delays in decision-making amplify any financial loss, increase reputational harm and likely regulatory penalties. The UK government’s own guidance stresses that developing and rehearsing an incident response plan is critical to resilience. If you’re looking for ‘Lessons from the Ghost of Breaches Past’, consider these real-world UK examples of where an effective incident response plan would have saved more than a few blushes. Stéphane Nappo, Global CISO, reminds us:
“It takes 20 years to build a reputation and a few minutes of a cyber-incident to ruin it.”
In 2023, a single unprotected remote access server allowed attackers into the British Library’s IT systems after the implementation of multi-factor authentication had been delayed for “practical reasons”. The result? 600GB of sensitive data stolen, servers destroyed and systems offline for months. Recovery costs soared because legacy systems wouldn’t run on the new infrastructure. Also in 2023, a malicious file sat unquarantined on Capita’s network for 58 hours despite numerous alerts. Attackers subsequently gained admin access and exfiltrated nearly a terabyte of sensitive data. The ICO fined Capita £14 million, citing poor incident response and lack of escalation. Earlier this year, despite an £800M IT contract, inadequate vendor risk controls and delayed MFA implementation led to the UK’s costliest cyber incident when Jaguar Land Rover was breached. The damage? Current estimates are a £1.9 billion cost to the UK economy. These cases echo Marley’s warning: neglect today, pay tomorrow. Lavonne Burke from Dell, adds:
“Rapport isn’t built in a crisis. CISOs need to engage the board before an attack happens, educating them and establishing trust.”
According to the NCSC and UK Cyber Security frameworks, a Good Incident Response Plan should include:
- Clear Roles & Escalation Paths: Who decides what and when?
- Communication Playbooks: Internal and external messaging, including regulators and customers.
- Technical Response Steps: Isolation, containment, forensic evidence capture.
- Legal & Regulatory Triggers: GDPR/DPA18 reporting timelines (72 hours).
- Regular Testing: Tabletop exercises and simulations to rehearse under pressure.
- And have them available in hard copy!
And finally for a Dickensian Closing Thought, don’t wait for the Ghost of Breaches Past to rattle its chains at your door. Build resilience now, so when the Ghost of Breaches Yet to Come appears, your organisation can say: “We kept Christmas well, and our data safer still.”
Read more from Arcanum’s Festive Stories series: