Cybersecurity guide for your company
How to prepare your company before, during and after a cyberattack
- AI
- Prevention
- Response
- Continuity
- Risk transfer
Cybersecurity is no longer just a technical issue. European regulation, digital dependency, and the expansion of artificial intelligence have made it a management issue. This guide translates cyber risk into business decisions: what to protect, how to respond, how much a shutdown might cost, and how to prepare for recovery.
Written for those who decide
It does not turn management into cybersecurity specialists. It helps them formulate the right questions, understand the risk, and prepare decisions before an incident occurs. By the end, the board and management should be able to answer four questions.
- Which part of the business cannot stop?
- Who decides when a crisis begins?
- How much could a shutdown cost us?
- Can we recover activity without improvising?
Preparing beforehand changes what happens afterwards.
Four stages, from exposure to recovery
- Before the attackKnow the exposure before the incident occursWhich part of the business cannot afford to stop, where an attacker could get in today, and where the personal ends and the corporate risk begins: shared mobiles, remote working, personal clouds and unauthorised AI tools.
- Before the attackFraud, third parties and risk governanceHow to verify an instruction when the message, voice or image seems real; which suppliers could bring activity to a halt; and what NIS2, DORA, the AI Act, the Cyber Resilience Act and the GDPR require of the management body.
- Emerging riskAI changes the rules, not the nature of the impactAI from the outside, as the attacker's tool, and from the inside, when an agent with excessive permissions generates costs and interruptions without any cybercriminal involved. Two documented cases and six questions for governing an AI agent.
- During the attackThe first 24 hours: deciding under pressureAn hour-by-hour timeline of simultaneous decisions: whether to isolate systems or not, who to inform and in what order, whether to pay a ransom or not, who speaks when a journalist calls.
- ImpactHow much an incident can really costDowntime, revenue, response, legal and data, reputation and automation: the components of the economic impact, and the question the CEO and the CFO should be able to answer.
- Transfer the riskCyber insurance: response, services and financial protectionWhat to review in the policy before the incident: business interruption, fixed costs, excesses, waiting periods and sublimits; what triggers each cover and who has the phone number to notify a claim in the small hours.
- RecoverResilience: returning to operation without improvisingIsolated backups, real restoration tests, recovery time objectives, drills with management and the subsequent analysis that turns the incident into learning.
- ChecklistTen actions to review tomorrow in the companyA checklist for sharing out responsibilities. They do not need to be resolved today; what matters is knowing who should do it.
ENISA identifies phishing as the main initial vector in approximately 60% of the cases analysed in its Threat Landscape 2025. The exploitation of vulnerabilities accounted for around 21.3%.
Source: ENISA, Threat Landscape 2025Ten actions to review tomorrow
The guide ends with a checklist that summarises all of the above into ten concrete decisions. These are the ten; the details of each are in the document.
Receive the guide- Identify which part of the business cannot stop.
- Review the main exposure routes.
- Define where personal and professional use mix.
- Establish verification mechanisms against fraud and impersonation.
- Identify which third parties can compromise the business.
- Clarify who governs cyber and AI risk.
- Define who decides during the first 24 hours.
- Work out how much a shutdown could cost.
- Review what the cyber insurance covers and how to activate it.
- Ensure that activity can be resumed without improvising.
Would you like to review your company's cyber exposure?
A broker's work does not begin by looking for a policy. We help identify the exposure, work on prevention, quantify the impact and decide which part of the risk to retain and which to transfer. And we are there when a loss occurs.
- Identify
- Prevent
- Quantify
- Transfer
- Accompany
Anatomy of a ransomware claim: the seventy-two hours that determine the cost
The ransom is almost never the most expensive item. The costly part is the downtime, the reconstruction of the environment, and the notifications that must be made against the clock.
8 min de lecturaActualidad normativaNIS2: which companies it affects and what changes in their cyber risk policy
The directive greatly expands the number of obligated entities and introduces personal liability for management. What it implies for insurance.
6 min de lecturaActualidad normativaDORA: what it requires from financial entities and their technology providers
The European regulation on digital operational resilience also applies to those providing ICT services to the financial sector. Many providers still do not know this.
6 min de lectura

