Usynlig Fjende | Usynlig Fjende
NEW Invisible Enemy is now available in English. Order single copies or bulk for your organisation.

⚠ For boards and executive leadership

Your organisation is already under attack.
The only question is whether you know it.

On average, attackers are inside a network for 21 days before they are detected. The breach you don't know about is the dangerous one. For leadership, the real question is not whether it will happen, but what you do in the first 72 hours when you find out.

€4,5M
Average cost per incident in Europe
IBM 2024
€10M
Max. personal fine for boards under NIS2
NIS2 artikel 20
73%
Of boards feel unprepared for a cyberattack
KPMG Board Survey 2024
Test your preparedness Book a lecture

Jan Kaastrup · 200+ ransomware cases investigated · Europol EC3 Advisory Board 2013–18

The Real Cost of a Cyberattack

📋 Sources: IBM Cost of a Data Breach Report 2024 · Verizon DBIR 2024 · Coveware Ransomware Report Q4 2024 · ENISA Threat Landscape 2024 · CFCS Trusselsrapport 2024

22 days
Average downtime after ransomware
📋 Coveware Q4 2024
277 days
To identify and contain a breach
📋 IBM Cost of a Data Breach 2024
300%
Higher chance of paying ransom without a crisis plan
📋 Coveware 2024
kr. 2,8M
Average ransom demand, Danish companies
📋 CFCS Trusselsrapport 2024
1 in 4
SMEs close within 6 months of a serious attack
📋 ENISA 2024

Legal exposure

Under NIS2, the board is personally accountable

NIS2 Article 20 requires that management bodies approve cybersecurity measures and oversee their implementation. Non-compliance can result in personal liability and fines of up to €10M or 2% of global turnover.

€10M
Max. NIS2 fine

5 Questions Your Board Should Be Able to Answer

Answer honestly. Most boards cannot answer all five.

Could not answer all five? You are not alone — and it is fixable.

Book a lecture

What Cybercriminals Actually Say About Their Victims

The following are real quotes from leaked internal communications of four ransomware groups — Conti, Black Basta, LockBit and TheGentlemen. They reveal how attackers think about the organisations they target.

Black Basta — internal chat, 2024

"There is revenue — so we go."

An operator confirming a target after looking up the company's annual revenue on ZoomInfo. Victim selection is a business decision.

For leadership: Your public revenue figures are used to assess whether you are worth attacking.

Conti — internal chat, 2021

"Set up the CRM. Enter companies continuously with employee contacts — name, title, position. Then build scripts. Split into departments: warm-up, action, follow-up."

An operator describing how to build a systematic phone-based social engineering operation targeting employees — using spoofed numbers from IT colleagues and managers.

For leadership: Attackers build structured call-centre operations to deceive your employees. They know names, titles and phone numbers.

LockBit — negotiation panel, 2025

"Don't go to the police or the FBI for help and don't tell anyone that we attacked you. They will forbid you from paying the ransom and will not help you in any way — your business will die."

Standard message sent to every victim when their systems are encrypted. Deliberate isolation of the leadership from outside help.

For leadership: Isolation is a tactic. Organisations without a pre-defined crisis protocol are most vulnerable.

LockBit — negotiation panel, 2025

"Some pay, some don't. We won't be upset. But offer too little — and we got upset."

Response to a victim's CEO attempting to negotiate by explaining the company cannot afford to pay. The attackers had already reviewed the company's financials.

For leadership: Negotiation happens on the attackers' terms. They have done it hundreds of times. Your leadership team has not.

TheGentlemen — internal data, 2026

"Sector: software. Revenue: 5M. [IP address and access point noted.]"

Entry in a structured target database — compiled months before any attack. Companies are catalogued by IP, sector and revenue before a single line of malicious code is executed.

For leadership: You may already be on a list. The question is your priority on it.

Read the full analyses from all four leaks →

What Smart Organisations Do Differently

Based on 200+ investigated attack cases, with a focus on leadership priorities, not technical checklists.

01
Know your crown jewels

Which data or systems would cripple the business if encrypted or published? Those are the ones to protect first, not everything at once.

02
Rehearse the scenario before it happens

Organisations that handle attacks best have practised. Not necessarily technical drills, but the decision process: who decides what, when, and who is contacted?

03
A backup is not enough — test it

An untested backup is not a backup. Attackers know this. They often wait to encrypt until they know the backup system is compromised.

04
Payment is a business decision, not an IT decision

The ransom decision involves legal, insurance and ethical dimensions. It belongs on the board agenda, not a helpdesk ticket.

05
Communication is underestimated

What do you tell customers, media and authorities? And when? In many cases, poor communication causes more damage than the attack itself.

06
Your supply chain is your attack surface

Many attacks happen via suppliers with lower security levels. NIS2 requires attention here, and it is simply good business to know the risk.

Book a lecture

Why traditional awareness training fails

Employees click through slides, pass the quiz and forget everything within weeks. Not because they are inattentive, but because a PowerPoint has never been able to replace a story from the real world.

82%
of breaches involve a human element
(Verizon DBIR 2024)
68%
of employees forget training content within a week
(Research avg.)
€4.5M
average cost of a data breach in Europe
(IBM 2024)

A lecture from the front line

Jan Kaastrup has investigated 200+ real cyberattacks. Michael Sjøberg has negotiated with hackers on behalf of companies. Together they bring the cyber threat to life through real stories, not slides.

  • Real ransomware cases from Danish companies
  • How hacker groups operate, and how they are stopped
  • What management and boards must be able to decide
  • NIS2, DORA and ISO 27001: documenting your awareness efforts
  • The book as take-home reference for every participant
Book now
Jan Kaastrup Michael Sjøberg
Regulatory requirements
NIS2 Article 21: security awareness for all staff
DORA Article 13: ICT security training requirements
ISO 27001:2022 A.6.3: information security awareness
Our programme documents your compliance

NIS2, DORA & ISO 27001

Under NIS2 and DORA, organisations must demonstrate active cybersecurity awareness measures. Our programme provides documented, structured training that satisfies regulatory requirements and actually works.

READY TO GET STARTED?

Whether it is employee awareness, leadership crisis training or an author evening, send an enquiry and we will tailor a programme for your organisation.

Book a lecture See all lecture formats

We respond within 1–2 business days.