arrow Back

The Academician’s View of Being Breach Ready.

A breach isn’t the real test. What happens next reveals how prepared you really are.

In this episode of Breach Ready Dialogues, ColorTokens’ Agnidipta Sarkar sits down with cybersecurity professor and author Dr. Dave Chatterjee to unpack what real breach readiness looks like.

They explore the Commitment–Preparedness–Discipline (CPD) framework, why cybersecurity tools alone aren’t enough, and how leaders can engineer resilience before an attack happens.

From real-world security drills and threat modeling to survivability and the “minimum viable digital enterprise,” this conversation challenges organizations to rethink cyber resilience.

The goal? Not simply saying, “We were attacked.” It’s being able to say: “We were attacked and we’re still operational.”

Watch now to learn how leadership, preparation, and discipline can turn breach readiness into business resilience.

Agnidipta Sarkar: So good morning, good afternoon, and good evening, everybody. I’m back with a new guest. We are talking, we are in the Breach Ready Dialogues the podcast that primarily focuses on what should you be doing should there be a breach, and how should we, how should you be preparing for it. The question is no longer when you will be breached.

We’ve crossed the time when if you will be breached. We are now in the era of when you’ll be breached, but the question is, when you come out on the other side, do you come out winning, becoming better than what you were earlier, or are you going to take the pressure on and face situations that you did not want?

There is material impact. There’s a whole lot of other things, but I’m happy to talk to Dr. Dave Chatterjee who’s probably the only other person that I am aware of who’s got a body of work behind breach readiness. And I’m especially fascinated about the commitment preparedness discipline framework that he talks about, the CPD framework.

He has been a lot of things, but I’ll leave it to him to take on and explain to us and tell us his experience and in breach readiness and in general. So Dave, over to you.

Dave Chatterjee: Thank you very much, Agni. It’s truly a pleasure to be on your podcast. I’ve enjoyed our interactions prior to the recording today.

I’m delighted to be talking to your listeners as well. So briefly about myself. I’m a professor at Duke University, an adjunct associate professor in the School of Engineering. I teach in their cybersecurity program. Besides being a professor I’ve also authored books and articles. I serve as editor for journals.

I get to deliver talks, keynote addresses moderate CISO roundtables and keynote panels. And then as we were talking the other day, I have a cybersecurity readiness podcast series, which is in 128 countries the last time I checked. And that’s been going very well, and it’s been very popular, and I’ve been able to convert some of the episodes into teaching cases which are published through Ivy Publishing, and that makes me feel very good being an educator, that students are able to learn from the real-world experiences associated with breach and recovering from the breach.

And finally, last but not the least, I also serve as a consultant and advisor to many for-profit and non-profit organizations. But I’ll stop there and pass it back to Agni. Agni, it’s all yours again.

Agnidipta Sarkar: No, thank you. Thank you. And like we discussed the other day, breaches don’t really have any books in as of now.

There are people who are writing books But there are no– unlike cybersecurity, which is so well practiced, there is a whole CIA framework. There are so many stuff there, and not many people have delved in depth. It’s still experiential. People get into a breach and then figure out, “Oh, this is so stressful,” and the things that go after that are quite challenging.

But in the end what it matters when you think of investment, you are trying to invest in cybersecurity because one day your investment will stand up good against a cyber attacker and not let the cyber attack- attacker do the damage that you cannot afford. Given that background, tell us a little bit about your CPD framework.

Dave Chatterjee: Absolutely. So the CPD Framework, it stands for Commitment Preparedness Discipline Framework. That came out of my first book, which I published in 2021. Sage is, was the publisher. And essentially, I was motivated by what I was seeing out there, that organizations were falling victim to attacks. The number of incidents kept increasing despite the growing investments in cybersecurity tools, the growing pr-proliferation of cybersecurity frameworks and best practices.

So I really wanted to get, get into the phenomenon try to understand why companies are not doing better than they should, given all the help they are getting. So that led to a lot of research where I conducted extensive interviews with subject matter experts case studies. It was about two to three years of work, body of work.

And then the data, I analyzed the data conducted qualitative analysis, and the three pillars that came out, the three dimensions of the framework that came through were commitment, preparedness, and discipline. And each of these pillars are associated with a set of success factors, which have also been empirically validated.

The key distinctive aspect of the framework is it’s a holistic governance framework. It goes beyond the technical and takes into con-consideration the significance of robust processes, strong governance, committed leadership. And also, in fact, probably the one overarching theme underlying this framework is to help organizations create and sustain a high performance information security culture.

Agni, given your extensive experience in industry, and you have served in the capacity of CISO and other leadership capacities, you know very well that- For a company to stay at a, an appropriate cybersecurity readiness trajectory or to achieve and sustain a certain posture, there has to be a certain level of commitment to be made in whether it’s cybersecurity investments, cybersecurity initiatives.

But what I have seen from my experience that often whoever is leading the cybersecurity charge, whether it’s a CISO or a CFO or a CTO, the kind of credibility they have with the C-level, say the CEO, often determines the kind of traction security gets in the organization. Like in some organizations, they are emphatic that cybersecurity is part of our strategic value proposition.

Whereas in many others, cybersecurity is the cost of doing business, is associated with compliance. Let’s somehow get done with it, let’s keep the regulators happy, let’s achieve our compliance certificate so we can do our business. So the mindset varies from organizations to organizations. However, I felt that at least if I can provide them with a framework that is easy to understand, it doesn’t get too complicated, unlike NIST, which has hundred controls and, more power to NIST.

It’s a great framework, and we need that level of detail. But I’ve also heard from many practitioners that they get overwhelmed trying to keep up with all the details of a framework. So I’ve tried to keep it at a level that people can understand, and then I have a questionnaire that comes with it that allows organizations to do a self-assessment, and then from there on, we talk about recommendations.

So at a high level, that’s what a CPD framework is it’s a holistic cybersecurity governance framework designed to guide organizations in achieving and sustaining a high-performance information security culture.

Agnidipta Sarkar: And no that, that’s enlightening. I’m going to repeat what you usually…

what I’ve heard you say at other times. At the end of the day, customers don’t judge you by whether you got breached or not. They also judge you on how you responded. That made a huge difference between how two organizations respond to a cyberattack. Some respond very positively because they were prepared, and that’s so market-focused because the markets change on the basis of how you respond.

So that automatically takes us to the point that enterprises need to exercise, need to practice whatever pra- whatever program that they build to become ready for the breach. And one of the foundational capabilities that I believe CISOs must have is to take complete charge of the underlying ecosystem, the entire network, the applications, and and the systems underneath and how they behave.

But like you said, people get overwhelmed with standards, expectations from regulations, and then they get down to stuff that’s absolutely technical, and they forget about the fact that when an attacker attacks it’s just not a single attack. It’s a collection of many factors. As of now, I see that people are worried about the speed of Mythos.

There’s a huge amount of talk about it. But speed is just one element. A smart guy with that kind of capability… And I’m not saying with Mythos, I’m saying there are other people who are developing this kind of capability. If one of those becomes the tool of a cyber attacker, it’ll do far more damage because enterprises today are not prepared.

Would you agree?

Dave Chatterjee: Absolutely. You’re spot on. In fact, I often say this, that organizations are not failing because they lack tools. Just like you said, they’re failing because they lack accountability, they lack strategic alignment, they lack preparedness, they lack execution discipline under pressure.

Whether we talk about MITRE today or something else tomorrow, the attacks are going to get sophisticated, and there’s nothing new about it. That’s the whole industry there. People are making a living launching these attacks, so they have to– they will continue to keep advancing, innovating, and they also have access to AI, just like the good guys do.

So then, under those circumstances, what do organizations do? And as we were talking during our planning session, and I mentioned, that organizations are not formed to deal with cyberattacks. Especially if it’s not a cybersecurity company.

That’s not the focus of an organization. You have aerospace companies, you have energy companies, you have retails a-and many others.

They are formed with other goals in mind. However, cybersecurity is an integral part of the value proposition because if you don’t operate in a secure manner, the consequences can be heavy once you get attacked. And as you very aptly said at the be-at the beginning of the podcast, it’s not a question of- If you will get breached, but it’s a question of when you will get breached.

So that’s where the preparedness aspect comes into play. That’s where the proactiveness aspect comes into play. That’s where, a person like myself and yourself, you’re constantly advising organizations or recommending organizations that you have to look ahead. You have to be proactive.

So again, coming back to my framework when I talk about commitment I’m talking about leadership commitment, the C-level. And we’re talking about actively being involved, serving on cybersecurity governance committee in some capacity, staying aware, staying informed of the strengths of the organization, the weaknesses.

And I’m also talking about commitment across the board. As you would agree, cybersecurity issues will not be resolved if you simply have a strong cybersecurity team. That’s an important part of the defense, but everyone will have to do their part. Every individual organizational member, as well as the vendors that the client organization connects with, they all have a role to play.

There’s a reason why we often hear that phrase that cybersecurity readiness is everyone’s business. It’s not just the cybersecurity team, it’s everybody. So how do you create that culture? How do you mobilize organization-wide support where every person across functional units recognizes that, yes, I need to perform the activities, the operations that I’ve been hired for, but I also need to make sure that I’m performing them in as secure a manner as possible.

So that’s the commitment aspect. Preparedness is when you get into the nuts and bolts and make sure you’re using the relevant technologies, your processes are robust, and so on and so forth, and I won’t get into the details right away. And finally, discipline, which is very critical. It’s just like brushing your teeth in the morning.

It’s a hygiene that you have to have in place, and you have to sustain it. Similarly, what are some of the fundamentals, the basics of cybersecurity hygiene? Making sure your systems are patched, making sure you’re not only logging the intelligence you’re receiving, but you’re also acting on the intelligence and also logging what decisions did you take based on the intelligence you received.

If you choose not to act- Based on the intelligence you received, that’s perfectly fine as long as you provide a justification. Maintaining such detailed logs has come in so handy for many organizations who have had to go to the court of law and plead their case against accusations of gross negligence.

But then when they are able to show documents which shows that they have gone above and beyond, they have been substantive in their approach to cybersecurity readiness, they have gone beyond just checking the box. They’ve been truly committed. When that comes through to the judge and the jury, the organization looks a lot better.

The organization looks a lot better even in front of the media, the general public. Coming back to the fundamentals, it’s really about recognizing this threat is not going to go away, and the way to deal with it is not to just pass it on to somebody else or to some team, but to deal with it head-on and take a very comprehensive, deliberate, and a substantive approach.

That’s what I keep harping. This is not rocket science. Even a person who has no technical background, no computer science background, no cybersecurity back- background, but is interested in getting to the bottom of the problem, the bottom of the situation, asking the right questions, they can very well do a great job in ensuring their organization is operating in as secure a manner as possible.

Agnidipta Sarkar: In fact since you bring it out A-and you’re absolutely right. People, process, and technology have to be completely hand in glove if we have to stand up to cyber attacks. But a-as I said, in twenty twenty-six, this comment is very relevant because I’m trying to… I’m now trying to go back to a CISA guideline that came up a month ago, I think, and that talked about survivability.

It’s not about responding to a cyber attack, it’s about survivability. And one of the key things that I believe that people have been struggling with for quite some time is material impact. People think about it differently, and I think the question is, how much disruption can we actually absorb before the organization suffers an unacceptable business harm?

And that is a decision that the CXOs and the leaders must take before they, they get– be-before, especially if they’re not in the cybersecurity world, if they are, let’s say, oil and gas or they’re healthcare, they’re hospitals, they are manufacturing anything. Because material impact is not a cybersecurity metric.

It’s an indicator of how much survivability someone has. There could be thresholds for how long will you tolerate downtime how much of production degradation is acceptable, or maybe patient… or maybe interruption in patient care. Stryker a medical company, medical manufacturing company, provides beds digital, connected beds.

They were disrupted and that became big news. Then how much revenue loss are you willing to take? How much of logistics disruption or maybe expo- the exposure of the safety systems? How much of, A-and if somebody is in the business of data how much of or finance, how much of corruption can you handle there in terms of data corruption?

And then there is, of course, the supply chain, the regulatory exposure, and the most important part is recovery. We’ve been trained to think of business continuity as a solution to a breach. But I don’t think that’s all. I- at the end, the breach, whole concept of breach readiness is to make sure that, The cyber resilience boundary of an organization is never breached.

So you create unaffected digital systems because at this time and in, in this, a- and this period when people are moving away from ransomware to wiperware, this is absolutely critical. Breach readiness is not about something you think tomorrow or plan for the next year. It’s something that you must be planning as of yesterday.

Would you agree on that?

Dave Chatterjee: Yeah, totally agree. In fact, I want to reiterate a couple of things you, you mentioned. One of, one of which is s- cyber threat modeling. I like to use this phrase, destroy your business ana-s- analysis, or destroy your business initiative. It was first at least I read about it for the first time in a case study, and Jack Welch introduced this concept when e-commerce was– had just started happening, and he wanted his executives to become very familiar with e-commerce.

And so at every operational meeting, he would require the senior VPs to talk about what– under what condition scenarios would their business be totally destroyed, and then what are they doing about it? So I took that idea, and I applied it in the context of cybersecurity, and I’ve recommended organizations that you all need to sit down when you’re doing cybersecurity strategy planning, you all need to do this threat scenario analysis.

That what are the different types of threats that organizations are likely to face? What are the consequences? And what steps have you taken or will you be ta-taking? When an organization does that, it’s especially valuable for the senior leadership because they are immediately able to connect the dots between the consequences and the top line and the bottom line.

Otherwise, what happens? Oftentimes, the security implications are discussed in technical terms, which doesn’t hit home with many of these non-technical senior leaders. So you have to speak to them in the language they understand best, whether it’s in finance terms, in reputation terms, in the loss of life terms.

Talking about loss of lives, you very correctly share the spectrum of consequences that organizations, individuals, communities are likely to face. And the pandemic comes back to mind. We, as a global community, were not prepared for the pandemic, despite having some global organizations designed to protect us from these kinds of global disasters.

For, again, it’s a-an opinion, don’t want to get political here, but for my personal opinion is those organizations failed. We were caught napping. And so therefore, I also like to re-recommend to organizations that, you know- We are at that point where our systems are all so connected, so integrated, that let’s hope that there is no such major breach that could cause a catastrophe like the pandemic.

Whether it’s a nuclear catastrophe, whether it’s the contamination of water supply, whether it’s your electricity grid gets completely neutralized. All kinds of possibilities are there. And I– You know, the reason I mention that is more and more organizations, more and more countries are engaging in digital war- warfare.

That’s where they are trying to outwit, out-compete other nations, and the consequences of that could be existential threats. Now, the purpose of this podcast is not to engage in fear-mongering. Absolutely correct. However, it’s also important for organizations to recognize that you have to be proactive, to use your words You have to ask yourself the question, you means the organization, that if I’m breached of this, at this magnitude, how quickly and smoothly and effectively can I recover?

What is my level of resilience? That needs to be constantly checked, and when we are talking about checking, we are talking about conducting re- not tabletop exercises, going beyond tabletop exercises. Conducting exercises which simulate breach scenarios as best as possible.

Because the more you practice, the more you rehearse, the more you see the problems or shortcomings in your disaster recovery plan or in your incident response plan. Unless you practice, those documents never get validated. So you don’t want these plans to sit idle in a document, looking nice and pretty, impressing the auditors.

You want them to be truly effective, and you have to test them out on a regular basis. I have been an auditor in my first profession as a chartered accountant from India. I understand audits, but we are in the days of real-time cybersecurity audits. We are in the days of real-time security drills. In organizations that I’m familiar with, including mine, we have fire drills on a regular basis, which I think is great.

And I’ve often wondered, why don’t we have security drills, ransomware attack drills, denial-of-service attack drills, phishing attack drills? We need to have organization-wide drills to see how organizations respond, and that’s critical. But that’s the level of awareness, the level of recognition that needs to happen, and it needs to happen at the C-suite level because they set the tone.

They set the ball rolling to create the right kind of culture, and that’s why these discussions are so important, so critical.

Agnidipta Sarkar: Absolutely. In fact, I couldn’t have laid it out more lucidly in terms of what you said. I’m just going back to whatever what you mentioned, and I’m just going to expand that.

I think organizations need to ensure that not all systems, but the critical business systems required for organizational survival, and that they can define in any way that they want, they remain uncompromised, they remain reachable, re- recoverable, and operational even during active attack conditions.

And this, the statement that I just made, is not, was not originally designed for cyberattacks. It was actually designed for active shooter scenarios. But it’s so relevant because a- as you correctly said practicing your organizational response to a catastrophic cyber incident or a breach is absolutely crucial for the survival of an organization.

‘Cause, and I’m going back to what you wrote i- in, in, in earlier, organizations are not measured only by how well did they respond to a cyberattack- They are… whether they got breached or not, but how they respond, that’s the key thing. And that’s so very much important. I’m aware that we have talked for a very long time and I really want to go on.

I would sug- I would actually plan for another session between you and me because there is, there’s a lot of work that you are doing that is relevant for the world to know, especially for people who are following the Breach Ready Dialogues. Because the focus of this discussion is not about whether you bought the next EDR, whether your SIEM is important or all of that.

Our focus is to make sure that organizations understand how they’re going to prepare for and stand in front of the world and say, “Look, there was a cyber attack.” A- and this is what I told somebody I met in the morning. Typical responses after a cyber attack in the media are, “We had an unprecedented cyber attack, and as a precautionary mea- measure, we’ve shut down the organization to protect stakeholder interests.”

So I’m saying that in the future, if we follow whatever we talked about, then the responses would be, “We had an unprecedented cyber attack, and we have cybersecurity experts who are dealing with it. However, we are operational. We continue to serve organizations to serve our customers as best as we can.

Some services might get affected for a small period of time, but to be fair, we are working.” That should be the message. But today’s message is very different. With that let me thank you once again for your thoughts, e- especially the ones that you talked about leadership. I think whatever we just discussed addresses the top leadership of every company.

They should be thinking commitment, preparation, and discipline, and they should be thinking about breach readiness Thank you.

Dave Chatterjee: Thank you very much. Thanks for the opportunity to come on your podcast.

A breach isn’t the real test. What happens next reveals how prepared you really are.

In this episode of Breach Ready Dialogues, ColorTokens’ Agnidipta Sarkar sits down with cybersecurity professor and author Dr. Dave Chatterjee to unpack what real breach readiness looks like.

They explore the Commitment–Preparedness–Discipline (CPD) framework, why cybersecurity tools alone aren’t enough, and how leaders can engineer resilience before an attack happens.

From real-world security drills and threat modeling to survivability and the “minimum viable digital enterprise,” this conversation challenges organizations to rethink cyber resilience.

The goal? Not simply saying, “We were attacked.” It’s being able to say: “We were attacked and we’re still operational.”

Watch now to learn how leadership, preparation, and discipline can turn breach readiness into business resilience.

Agnidipta Sarkar: So good morning, good afternoon, and good evening, everybody. I’m back with a new guest. We are talking, we are in the Breach Ready Dialogues the podcast that primarily focuses on what should you be doing should there be a breach, and how should we, how should you be preparing for it. The question is no longer when you will be breached.

We’ve crossed the time when if you will be breached. We are now in the era of when you’ll be breached, but the question is, when you come out on the other side, do you come out winning, becoming better than what you were earlier, or are you going to take the pressure on and face situations that you did not want?

There is material impact. There’s a whole lot of other things, but I’m happy to talk to Dr. Dave Chatterjee who’s probably the only other person that I am aware of who’s got a body of work behind breach readiness. And I’m especially fascinated about the commitment preparedness discipline framework that he talks about, the CPD framework.

He has been a lot of things, but I’ll leave it to him to take on and explain to us and tell us his experience and in breach readiness and in general. So Dave, over to you.

Dave Chatterjee: Thank you very much, Agni. It’s truly a pleasure to be on your podcast. I’ve enjoyed our interactions prior to the recording today.

I’m delighted to be talking to your listeners as well. So briefly about myself. I’m a professor at Duke University, an adjunct associate professor in the School of Engineering. I teach in their cybersecurity program. Besides being a professor I’ve also authored books and articles. I serve as editor for journals.

I get to deliver talks, keynote addresses moderate CISO roundtables and keynote panels. And then as we were talking the other day, I have a cybersecurity readiness podcast series, which is in 128 countries the last time I checked. And that’s been going very well, and it’s been very popular, and I’ve been able to convert some of the episodes into teaching cases which are published through Ivy Publishing, and that makes me feel very good being an educator, that students are able to learn from the real-world experiences associated with breach and recovering from the breach.

And finally, last but not the least, I also serve as a consultant and advisor to many for-profit and non-profit organizations. But I’ll stop there and pass it back to Agni. Agni, it’s all yours again.

Agnidipta Sarkar: No, thank you. Thank you. And like we discussed the other day, breaches don’t really have any books in as of now.

There are people who are writing books But there are no– unlike cybersecurity, which is so well practiced, there is a whole CIA framework. There are so many stuff there, and not many people have delved in depth. It’s still experiential. People get into a breach and then figure out, “Oh, this is so stressful,” and the things that go after that are quite challenging.

But in the end what it matters when you think of investment, you are trying to invest in cybersecurity because one day your investment will stand up good against a cyber attacker and not let the cyber attack- attacker do the damage that you cannot afford. Given that background, tell us a little bit about your CPD framework.

Dave Chatterjee: Absolutely. So the CPD Framework, it stands for Commitment Preparedness Discipline Framework. That came out of my first book, which I published in 2021. Sage is, was the publisher. And essentially, I was motivated by what I was seeing out there, that organizations were falling victim to attacks. The number of incidents kept increasing despite the growing investments in cybersecurity tools, the growing pr-proliferation of cybersecurity frameworks and best practices.

So I really wanted to get, get into the phenomenon try to understand why companies are not doing better than they should, given all the help they are getting. So that led to a lot of research where I conducted extensive interviews with subject matter experts case studies. It was about two to three years of work, body of work.

And then the data, I analyzed the data conducted qualitative analysis, and the three pillars that came out, the three dimensions of the framework that came through were commitment, preparedness, and discipline. And each of these pillars are associated with a set of success factors, which have also been empirically validated.

The key distinctive aspect of the framework is it’s a holistic governance framework. It goes beyond the technical and takes into con-consideration the significance of robust processes, strong governance, committed leadership. And also, in fact, probably the one overarching theme underlying this framework is to help organizations create and sustain a high performance information security culture.

Agni, given your extensive experience in industry, and you have served in the capacity of CISO and other leadership capacities, you know very well that- For a company to stay at a, an appropriate cybersecurity readiness trajectory or to achieve and sustain a certain posture, there has to be a certain level of commitment to be made in whether it’s cybersecurity investments, cybersecurity initiatives.

But what I have seen from my experience that often whoever is leading the cybersecurity charge, whether it’s a CISO or a CFO or a CTO, the kind of credibility they have with the C-level, say the CEO, often determines the kind of traction security gets in the organization. Like in some organizations, they are emphatic that cybersecurity is part of our strategic value proposition.

Whereas in many others, cybersecurity is the cost of doing business, is associated with compliance. Let’s somehow get done with it, let’s keep the regulators happy, let’s achieve our compliance certificate so we can do our business. So the mindset varies from organizations to organizations. However, I felt that at least if I can provide them with a framework that is easy to understand, it doesn’t get too complicated, unlike NIST, which has hundred controls and, more power to NIST.

It’s a great framework, and we need that level of detail. But I’ve also heard from many practitioners that they get overwhelmed trying to keep up with all the details of a framework. So I’ve tried to keep it at a level that people can understand, and then I have a questionnaire that comes with it that allows organizations to do a self-assessment, and then from there on, we talk about recommendations.

So at a high level, that’s what a CPD framework is it’s a holistic cybersecurity governance framework designed to guide organizations in achieving and sustaining a high-performance information security culture.

Agnidipta Sarkar: And no that, that’s enlightening. I’m going to repeat what you usually…

what I’ve heard you say at other times. At the end of the day, customers don’t judge you by whether you got breached or not. They also judge you on how you responded. That made a huge difference between how two organizations respond to a cyberattack. Some respond very positively because they were prepared, and that’s so market-focused because the markets change on the basis of how you respond.

So that automatically takes us to the point that enterprises need to exercise, need to practice whatever pra- whatever program that they build to become ready for the breach. And one of the foundational capabilities that I believe CISOs must have is to take complete charge of the underlying ecosystem, the entire network, the applications, and and the systems underneath and how they behave.

But like you said, people get overwhelmed with standards, expectations from regulations, and then they get down to stuff that’s absolutely technical, and they forget about the fact that when an attacker attacks it’s just not a single attack. It’s a collection of many factors. As of now, I see that people are worried about the speed of Mythos.

There’s a huge amount of talk about it. But speed is just one element. A smart guy with that kind of capability… And I’m not saying with Mythos, I’m saying there are other people who are developing this kind of capability. If one of those becomes the tool of a cyber attacker, it’ll do far more damage because enterprises today are not prepared.

Would you agree?

Dave Chatterjee: Absolutely. You’re spot on. In fact, I often say this, that organizations are not failing because they lack tools. Just like you said, they’re failing because they lack accountability, they lack strategic alignment, they lack preparedness, they lack execution discipline under pressure.

Whether we talk about MITRE today or something else tomorrow, the attacks are going to get sophisticated, and there’s nothing new about it. That’s the whole industry there. People are making a living launching these attacks, so they have to– they will continue to keep advancing, innovating, and they also have access to AI, just like the good guys do.

So then, under those circumstances, what do organizations do? And as we were talking during our planning session, and I mentioned, that organizations are not formed to deal with cyberattacks. Especially if it’s not a cybersecurity company.

That’s not the focus of an organization. You have aerospace companies, you have energy companies, you have retails a-and many others.

They are formed with other goals in mind. However, cybersecurity is an integral part of the value proposition because if you don’t operate in a secure manner, the consequences can be heavy once you get attacked. And as you very aptly said at the be-at the beginning of the podcast, it’s not a question of- If you will get breached, but it’s a question of when you will get breached.

So that’s where the preparedness aspect comes into play. That’s where the proactiveness aspect comes into play. That’s where, a person like myself and yourself, you’re constantly advising organizations or recommending organizations that you have to look ahead. You have to be proactive.

So again, coming back to my framework when I talk about commitment I’m talking about leadership commitment, the C-level. And we’re talking about actively being involved, serving on cybersecurity governance committee in some capacity, staying aware, staying informed of the strengths of the organization, the weaknesses.

And I’m also talking about commitment across the board. As you would agree, cybersecurity issues will not be resolved if you simply have a strong cybersecurity team. That’s an important part of the defense, but everyone will have to do their part. Every individual organizational member, as well as the vendors that the client organization connects with, they all have a role to play.

There’s a reason why we often hear that phrase that cybersecurity readiness is everyone’s business. It’s not just the cybersecurity team, it’s everybody. So how do you create that culture? How do you mobilize organization-wide support where every person across functional units recognizes that, yes, I need to perform the activities, the operations that I’ve been hired for, but I also need to make sure that I’m performing them in as secure a manner as possible.

So that’s the commitment aspect. Preparedness is when you get into the nuts and bolts and make sure you’re using the relevant technologies, your processes are robust, and so on and so forth, and I won’t get into the details right away. And finally, discipline, which is very critical. It’s just like brushing your teeth in the morning.

It’s a hygiene that you have to have in place, and you have to sustain it. Similarly, what are some of the fundamentals, the basics of cybersecurity hygiene? Making sure your systems are patched, making sure you’re not only logging the intelligence you’re receiving, but you’re also acting on the intelligence and also logging what decisions did you take based on the intelligence you received.

If you choose not to act- Based on the intelligence you received, that’s perfectly fine as long as you provide a justification. Maintaining such detailed logs has come in so handy for many organizations who have had to go to the court of law and plead their case against accusations of gross negligence.

But then when they are able to show documents which shows that they have gone above and beyond, they have been substantive in their approach to cybersecurity readiness, they have gone beyond just checking the box. They’ve been truly committed. When that comes through to the judge and the jury, the organization looks a lot better.

The organization looks a lot better even in front of the media, the general public. Coming back to the fundamentals, it’s really about recognizing this threat is not going to go away, and the way to deal with it is not to just pass it on to somebody else or to some team, but to deal with it head-on and take a very comprehensive, deliberate, and a substantive approach.

That’s what I keep harping. This is not rocket science. Even a person who has no technical background, no computer science background, no cybersecurity back- background, but is interested in getting to the bottom of the problem, the bottom of the situation, asking the right questions, they can very well do a great job in ensuring their organization is operating in as secure a manner as possible.

Agnidipta Sarkar: In fact since you bring it out A-and you’re absolutely right. People, process, and technology have to be completely hand in glove if we have to stand up to cyber attacks. But a-as I said, in twenty twenty-six, this comment is very relevant because I’m trying to… I’m now trying to go back to a CISA guideline that came up a month ago, I think, and that talked about survivability.

It’s not about responding to a cyber attack, it’s about survivability. And one of the key things that I believe that people have been struggling with for quite some time is material impact. People think about it differently, and I think the question is, how much disruption can we actually absorb before the organization suffers an unacceptable business harm?

And that is a decision that the CXOs and the leaders must take before they, they get– be-before, especially if they’re not in the cybersecurity world, if they are, let’s say, oil and gas or they’re healthcare, they’re hospitals, they are manufacturing anything. Because material impact is not a cybersecurity metric.

It’s an indicator of how much survivability someone has. There could be thresholds for how long will you tolerate downtime how much of production degradation is acceptable, or maybe patient… or maybe interruption in patient care. Stryker a medical company, medical manufacturing company, provides beds digital, connected beds.

They were disrupted and that became big news. Then how much revenue loss are you willing to take? How much of logistics disruption or maybe expo- the exposure of the safety systems? How much of, A-and if somebody is in the business of data how much of or finance, how much of corruption can you handle there in terms of data corruption?

And then there is, of course, the supply chain, the regulatory exposure, and the most important part is recovery. We’ve been trained to think of business continuity as a solution to a breach. But I don’t think that’s all. I- at the end, the breach, whole concept of breach readiness is to make sure that, The cyber resilience boundary of an organization is never breached.

So you create unaffected digital systems because at this time and in, in this, a- and this period when people are moving away from ransomware to wiperware, this is absolutely critical. Breach readiness is not about something you think tomorrow or plan for the next year. It’s something that you must be planning as of yesterday.

Would you agree on that?

Dave Chatterjee: Yeah, totally agree. In fact, I want to reiterate a couple of things you, you mentioned. One of, one of which is s- cyber threat modeling. I like to use this phrase, destroy your business ana-s- analysis, or destroy your business initiative. It was first at least I read about it for the first time in a case study, and Jack Welch introduced this concept when e-commerce was– had just started happening, and he wanted his executives to become very familiar with e-commerce.

And so at every operational meeting, he would require the senior VPs to talk about what– under what condition scenarios would their business be totally destroyed, and then what are they doing about it? So I took that idea, and I applied it in the context of cybersecurity, and I’ve recommended organizations that you all need to sit down when you’re doing cybersecurity strategy planning, you all need to do this threat scenario analysis.

That what are the different types of threats that organizations are likely to face? What are the consequences? And what steps have you taken or will you be ta-taking? When an organization does that, it’s especially valuable for the senior leadership because they are immediately able to connect the dots between the consequences and the top line and the bottom line.

Otherwise, what happens? Oftentimes, the security implications are discussed in technical terms, which doesn’t hit home with many of these non-technical senior leaders. So you have to speak to them in the language they understand best, whether it’s in finance terms, in reputation terms, in the loss of life terms.

Talking about loss of lives, you very correctly share the spectrum of consequences that organizations, individuals, communities are likely to face. And the pandemic comes back to mind. We, as a global community, were not prepared for the pandemic, despite having some global organizations designed to protect us from these kinds of global disasters.

For, again, it’s a-an opinion, don’t want to get political here, but for my personal opinion is those organizations failed. We were caught napping. And so therefore, I also like to re-recommend to organizations that, you know- We are at that point where our systems are all so connected, so integrated, that let’s hope that there is no such major breach that could cause a catastrophe like the pandemic.

Whether it’s a nuclear catastrophe, whether it’s the contamination of water supply, whether it’s your electricity grid gets completely neutralized. All kinds of possibilities are there. And I– You know, the reason I mention that is more and more organizations, more and more countries are engaging in digital war- warfare.

That’s where they are trying to outwit, out-compete other nations, and the consequences of that could be existential threats. Now, the purpose of this podcast is not to engage in fear-mongering. Absolutely correct. However, it’s also important for organizations to recognize that you have to be proactive, to use your words You have to ask yourself the question, you means the organization, that if I’m breached of this, at this magnitude, how quickly and smoothly and effectively can I recover?

What is my level of resilience? That needs to be constantly checked, and when we are talking about checking, we are talking about conducting re- not tabletop exercises, going beyond tabletop exercises. Conducting exercises which simulate breach scenarios as best as possible.

Because the more you practice, the more you rehearse, the more you see the problems or shortcomings in your disaster recovery plan or in your incident response plan. Unless you practice, those documents never get validated. So you don’t want these plans to sit idle in a document, looking nice and pretty, impressing the auditors.

You want them to be truly effective, and you have to test them out on a regular basis. I have been an auditor in my first profession as a chartered accountant from India. I understand audits, but we are in the days of real-time cybersecurity audits. We are in the days of real-time security drills. In organizations that I’m familiar with, including mine, we have fire drills on a regular basis, which I think is great.

And I’ve often wondered, why don’t we have security drills, ransomware attack drills, denial-of-service attack drills, phishing attack drills? We need to have organization-wide drills to see how organizations respond, and that’s critical. But that’s the level of awareness, the level of recognition that needs to happen, and it needs to happen at the C-suite level because they set the tone.

They set the ball rolling to create the right kind of culture, and that’s why these discussions are so important, so critical.

Agnidipta Sarkar: Absolutely. In fact, I couldn’t have laid it out more lucidly in terms of what you said. I’m just going back to whatever what you mentioned, and I’m just going to expand that.

I think organizations need to ensure that not all systems, but the critical business systems required for organizational survival, and that they can define in any way that they want, they remain uncompromised, they remain reachable, re- recoverable, and operational even during active attack conditions.

And this, the statement that I just made, is not, was not originally designed for cyberattacks. It was actually designed for active shooter scenarios. But it’s so relevant because a- as you correctly said practicing your organizational response to a catastrophic cyber incident or a breach is absolutely crucial for the survival of an organization.

‘Cause, and I’m going back to what you wrote i- in, in, in earlier, organizations are not measured only by how well did they respond to a cyberattack- They are… whether they got breached or not, but how they respond, that’s the key thing. And that’s so very much important. I’m aware that we have talked for a very long time and I really want to go on.

I would sug- I would actually plan for another session between you and me because there is, there’s a lot of work that you are doing that is relevant for the world to know, especially for people who are following the Breach Ready Dialogues. Because the focus of this discussion is not about whether you bought the next EDR, whether your SIEM is important or all of that.

Our focus is to make sure that organizations understand how they’re going to prepare for and stand in front of the world and say, “Look, there was a cyber attack.” A- and this is what I told somebody I met in the morning. Typical responses after a cyber attack in the media are, “We had an unprecedented cyber attack, and as a precautionary mea- measure, we’ve shut down the organization to protect stakeholder interests.”

So I’m saying that in the future, if we follow whatever we talked about, then the responses would be, “We had an unprecedented cyber attack, and we have cybersecurity experts who are dealing with it. However, we are operational. We continue to serve organizations to serve our customers as best as we can.

Some services might get affected for a small period of time, but to be fair, we are working.” That should be the message. But today’s message is very different. With that let me thank you once again for your thoughts, e- especially the ones that you talked about leadership. I think whatever we just discussed addresses the top leadership of every company.

They should be thinking commitment, preparation, and discipline, and they should be thinking about breach readiness Thank you.

Dave Chatterjee: Thank you very much. Thanks for the opportunity to come on your podcast.