Boards often recognise an availability emergency: “The system is down.”
Integrity incidents are harder. The lights stay on. The dashboard stays green. People keep working.
What if the system is running, but nobody can trust:
- Account balances?
- Payment instructions?
- Customer identities?
- Production parameters?
- Board reports?
- Recovery backups?
A functioning system producing manipulated data can be more dangerous than a visible outage. People continue making decisions, approving transactions and communicating with customers—using information that may be wrong.
That is why a cyber emergency is not only “we cannot log in.” It can be “we can log in, and we should not believe what we see.”
Availability Is the Easy Picture
A downed service forces a conversation. Customers call. The status page goes red. Someone has to say whether this is urgent inconvenience or a critical service in failure.
Integrity does not send the same invitation. The organisation can look busy, competent and in control while it is processing poison. Incorrect information can be more dangerous than no information. Controllers would rather lose a feed than fly on a lying one. Boards should be at least as adult.
DORA’s definition of an ICT-related incident covers adverse effects on availability, authenticity, integrity and confidentiality—not availability alone. The regulation is not being literary. It is describing the attacks that do not look like outages.
What Emergency Plans Must Answer
Cyber emergency plans that only measure restoration speed are half-built. They must also answer:
- How will trusted data be identified?
- Who can suspend transactions or decisions?
- How will the scope of manipulation be established?
- Which independent records can support reconciliation?
- What evidence must be preserved?
- Who decides that operations are safe to resume?
“Everything is green on the dashboard” is not assurance if the dashboard itself cannot be trusted. Recovery that restores a compromised backup is not recovery. It is a replay.
The board does not need to become a forensics team. It needs to refuse a restart story that only proves the servers ping. Critical capabilities are those whose failure—or whose quiet corruption—produces unacceptable harm. The emergency is the situation in which you can no longer rely on them, including when they appear to be up.
Board question: Can management prove not only that our systems can restart, but that their data can be trusted after an attack?
Relevant Sources
- Regulation (EU) 2022/2554 (DORA), Article 3 — EUR-Lex — https://eur-lex.europa.eu/eli/reg/2022/2554/oj
- Regulation (EU) 2022/2554 (DORA), Article 17 — EUR-Lex — https://eur-lex.europa.eu/eli/reg/2022/2554/oj
- Cybersecurity Incident — NIST CSRC Glossary — https://csrc.nist.gov/glossary/term/cybersecurity_incident
If your incident plan only covers “systems down,” you are rehearsing the visible failure and skipping the expensive one. I work with boards on integrity as a first-class emergency. Contact me.
