A major breach can stretch leadership capacity for weeks while recovery and trust rebuilding continue for years.

Drawing on his experience leading Medibank through its 2022 public breach, Alex Loizou, Cyber Security Leader and Managing Director at Intrinsic Security, shows why incident response has to protect decision quality, communicate uncertainty clearly, and sustain the people carrying the response at Security Edge.

Key takeaways:

  • Protect responders as part of incident control: Build rotations, trusted deputies, rest, and emotional support into the response before fatigue starts degrading judgement.
  • Communicate what is known and unknown with precision: Boards, executives, customers, and media need clear facts without technical reality being diluted or uncertainty being disguised.
  • Treat recovery as a multi-year trust exercise: Separate immediate remediation from deeper architectural work and build assurance into every stage so stakeholders can see that material change has occurred.

Responder endurance protects decision quality

Major incidents require teams to make difficult decisions for sustained periods under pressure.

Exhaustion, isolation, and guilt can erode judgement at the same time organisations need people to solve unfamiliar problems.

Alex treated workforce endurance as part of the incident response itself.

He established a 24/7 leadership rotation, brought in a trusted twin CISO, used buddy systems, and actively sent people offline to rest.

Keeping responders functional protects the organisation’s ability to think clearly as the incident evolves.

Precise communication gives leaders better decisions

Crisis communication needs to distinguish evidence from uncertainty.

Sugarcoating information can leave decision-makers with a false sense of certainty, while imprecise language can create confusion when new evidence changes the picture.

Alex used established cyber terminology, supported it with practical analogies, and worked closely with communications teams to explain exactly what phrases such as “no evidence” did and did not mean.

Clear language helps boards and executives understand the actual state of the incident without stripping away the technical detail needed to make sound decisions.

Recovery has to rebuild trust as well as systems

Containment closes one phase of a breach. Customer, regulator, board, and internal confidence can remain damaged much longer.

Alex describes the timeline as weeks for the incident, months for soul-searching, and years for recovery.

That requires organisations to run immediate fixes and deeper architectural remediation at different speeds, while building assurance and traceability into the work.

Stakeholders need evidence that the organisation has changed materially, rather than simply restored the systems affected by the incident.

The lasting lesson from Alex’s experience is that keeping people supported and capable of making good decisions is itself a business-continuity strategy.

Contributors
Alex Loizou Cybersecurity Leader at Intrinsic Security
Alex Loizou is a seasoned cybersecurity leader with a proven track record of building and leading high-performing security teams. He has extensive... More Less
security leadership culture