The fire extinguisher on the wall does not make you feel safer. It looks boring. It gathers dust. Visitors barely notice it. Yet when smoke fills the corridor, that small red cylinder suddenly becomes the most valuable asset in the building.
Cyber preparedness is the same kind of object. It does not impress boards. It does not photograph well for annual reports. It produces no revenue line. And because nothing dramatic happens when it is working, executives quietly downgrade its importance. Until the day it works. Or worse, until the day it was needed and was not there.
This is the truth most leaders avoid: the companies that survive cyberattacks do not win because they have better technology. They win because they prepared for boredom.
Let me start with a case I have seen repeatedly, with details changed only to protect the embarrassed.
A mid-sized organisation with a strong brand and competent leadership experiences a “minor” incident. A staff member clicks a link. Credentials are harvested, no alarms go off, and systems keep running.
Two weeks later, suppliers start calling about strange payment requests. Finance assumes it is a misunderstanding. IT resets a few passwords. Life continues.
Then the real damage surfaces. Mailbox rules were altered quietly, Audit logs were overwritten, backups ran faithfully, copying compromised data every night. By the time leadership convenes a meeting, the attacker has already left.
The investigation report is thin. Insurance asks hard questions. Regulators ask harder ones. The organisation did not collapse but it bled credibility, money, and time. Quietly.
The board’s question is always the same: “How did this happen to a well-run organisation?”
The answer is simpler than people want to admit. Preparedness was treated as a compliance exercise, not as a leadership discipline.
Most cyber strategies are built for noise. They focus on detection dashboards, threat intelligence feeds, and vendor presentations full of red arrows and skull icons.
That is the theatre. Real preparedness is deliberately dull. It sits in decisions no one wants to debate because they feel restrictive.
Cyber resilience is not primarily an IT problem but an executive attention problem.
Consider everyday life example. In many towns, the most dangerous roads are not the highways. They are the quiet streets near schools.
Drivers relax, children assume safety, speed creeps up unnoticed and accidents happen precisely where people feel most comfortable.
Cyber risk behaves the same way. The greatest damage rarely comes from sophisticated nation-state attacks. It comes from ordinary systems running normally, trusted users doing routine work, and leaders assuming “someone is handling it.” Comfort is the risk multiplier.
Preparedness, in contrast, feels inconvenient. It forces trade-offs leaders dislike. Prepared organisations accept that not everyone should have access, even if it slows work.
They accept that logs must be kept longer than is comfortable for storage budgets. They accept that incident drills will interrupt operations and annoy senior managers. They accept that some systems must be deliberately boring and stable, not endlessly optimised.
Unprepared organisations optimise for speed, cost, and convenience. They call it efficiency. Attackers call it opportunity.
Let us look closely at what actually distinguishes prepared organisations when an attack occurs.
First, preparedness shows up in time, not tools. When something goes wrong, prepared organisations do not argue about whether it is an “incident.” They know. Thresholds are defined, and authority is clear.
The first hour is used to contain, preserve evidence, and stabilize operations. In unprepared organisations, the first hour is spent reassuring each other that it is probably nothing. That delay is often the entire breach.
Second, preparedness is visible in evidence discipline. Prepared organisations assume scrutiny will come. Logs are intact, access records exist, backups are segmented and chain of custody is preserved. This is not paranoia. It is realism.
Cyber incidents are not just technical events; they are legal and regulatory events. If you cannot explain what happened with evidence, you lose control of the narrative. Silence fills the gap, and silence is expensive.
Third, preparedness lives in decision rights, not policies. Many companies have thick incident response manuals. Very few have tested who can shut down a system, disconnect a vendor, or override a business head in real time.
During an attack, hierarchy collapses unless authority is explicit. Prepared organisations have rehearsed this discomfort. Unprepared ones negotiate while damage spreads.
Fourth, preparedness respects human behaviour. Phishing works because people are human, not stupid. Prepared organisations design controls that assume mistakes will happen.
They limit blast radius. They monitor quietly. They do not rely on annual training slides to save them. Unprepared organisations moralise after the fact and call it awareness.
Now consider the boardroom reality. Boards love strategy. They tolerate risk frameworks and get impatient with preparedness because it has no visible payoff.
The returns are invisible until the day they are existential. This creates a governance blind spot. Preparedness is underfunded precisely because it works best when nothing happens.
Here is the uncomfortable question every board should ask: if we were breached tomorrow, could we prove what happened, contain it quickly, and continue operating without guessing?
If the honest answer is “we think so,” you are not prepared. A second case, this time with a different ending.
A regional organisation experiences a ransomware attempt. Credentials are compromised and lateral movement begins but something dull happens. Access is segmented.
Logs are monitored and anomalies trigger escalation. Within hours, systems are isolated. Backups are restored cleanly.
Customers notice a brief delay. Regulators are informed with evidence. The attacker leaves empty-handed. There is no headline, no drama, no applause just continuity.
That is what preparedness buys you: the ability to disappoint attackers quietly.
The strategic mistake leaders make is treating cyber preparedness as an insurance policy. It is not. Insurance pays after loss.
Preparedness prevents loss from becoming existential. One transfers risk. The other contains it.
For executives and boards, the practical shift is this. Stop asking, “Are we secure?” Start asking, “Are we ready to be breached?”
Stop funding tools that impress. Start funding boring capabilities: logging, segmentation, drills, evidence handling, and authority clarity.
Stop measuring preparedness by documents. Measure it by time to detect, time to decide, time to contain, and ability to explain.
Preparedness is quiet work. It does not flatter leadership. It rarely gets credit. But when cyberattacks arrive, as they always do, preparedness is the difference between a bad week and a strategic crisis.
The irony is cruel but consistent. The organisations that look calm during cyber incidents earned that calm through years of unglamorous decisions no one applauded at the time. That is the work. And that is the point.
Copyright Summit Consulting Limited, 2026. All rights reserved.
