⚠ For boards and executive leadership
On average, attackers are inside a network for 21 days before they are detected. The breach you don't know about is the dangerous one. For leadership, the real question is not whether it will happen, but what you do in the first 72 hours when you find out.
Jan Kaastrup · 200+ ransomware cases investigated · Europol EC3 Advisory Board 2013–18
The numbers your board needs to see
📋 Sources: IBM Cost of a Data Breach Report 2024 · Verizon DBIR 2024 · Coveware Ransomware Report Q4 2024 · ENISA Threat Landscape 2024 · CFCS Trusselsrapport 2024
Legal exposure
Under NIS2, the board is personally accountable
NIS2 Article 20 requires that management bodies approve cybersecurity measures and oversee their implementation. Non-compliance can result in personal liability and fines of up to €10M or 2% of global turnover.
Is your organisation prepared?
Answer honestly. Most boards cannot answer all five.
Could not answer all five? You are not alone — and it is fixable.
Book a lectureFrom the source
The following are real quotes from leaked internal communications of four ransomware groups — Conti, Black Basta, LockBit and TheGentlemen. They reveal how attackers think about the organisations they target.
Black Basta — internal chat, 2024
"There is revenue — so we go."
An operator confirming a target after looking up the company's annual revenue on ZoomInfo. Victim selection is a business decision.
For leadership: Your public revenue figures are used to assess whether you are worth attacking.
Conti — internal chat, 2021
"Set up the CRM. Enter companies continuously with employee contacts — name, title, position. Then build scripts. Split into departments: warm-up, action, follow-up."
An operator describing how to build a systematic phone-based social engineering operation targeting employees — using spoofed numbers from IT colleagues and managers.
For leadership: Attackers build structured call-centre operations to deceive your employees. They know names, titles and phone numbers.
LockBit — negotiation panel, 2025
"Don't go to the police or the FBI for help and don't tell anyone that we attacked you. They will forbid you from paying the ransom and will not help you in any way — your business will die."
Standard message sent to every victim when their systems are encrypted. Deliberate isolation of the leadership from outside help.
For leadership: Isolation is a tactic. Organisations without a pre-defined crisis protocol are most vulnerable.
LockBit — negotiation panel, 2025
"Some pay, some don't. We won't be upset. But offer too little — and we got upset."
Response to a victim's CEO attempting to negotiate by explaining the company cannot afford to pay. The attackers had already reviewed the company's financials.
For leadership: Negotiation happens on the attackers' terms. They have done it hundreds of times. Your leadership team has not.
TheGentlemen — internal data, 2026
"Sector: software. Revenue: 5M. [IP address and access point noted.]"
Entry in a structured target database — compiled months before any attack. Companies are catalogued by IP, sector and revenue before a single line of malicious code is executed.
For leadership: You may already be on a list. The question is your priority on it.
C-level priorities
Based on 200+ investigated attack cases, with a focus on leadership priorities, not technical checklists.
Which data or systems would cripple the business if encrypted or published? Those are the ones to protect first, not everything at once.
Organisations that handle attacks best have practised. Not necessarily technical drills, but the decision process: who decides what, when, and who is contacted?
An untested backup is not a backup. Attackers know this. They often wait to encrypt until they know the backup system is compromised.
The ransom decision involves legal, insurance and ethical dimensions. It belongs on the board agenda, not a helpdesk ticket.
What do you tell customers, media and authorities? And when? In many cases, poor communication causes more damage than the attack itself.
Many attacks happen via suppliers with lower security levels. NIS2 requires attention here, and it is simply good business to know the risk.
The problem
Employees click through slides, pass the quiz and forget everything within weeks. Not because they are inattentive, but because a PowerPoint has never been able to replace a story from the real world.
Our approach
Jan Kaastrup has investigated 200+ real cyberattacks. Michael Sjøberg has negotiated with hackers on behalf of companies. Together they bring the cyber threat to life through real stories, not slides.
Compliance
Under NIS2 and DORA, organisations must demonstrate active cybersecurity awareness measures. Our programme provides documented, structured training that satisfies regulatory requirements and actually works.
Next step
Whether it is employee awareness, leadership crisis training or an author evening, send an enquiry and we will tailor a programme for your organisation.
We respond within 1–2 business days.