When we talk about cyberattacks, the conversation often starts with data.
What was stolen?
How many records were affected?
Was personal information compromised?
But the recent cyber incident at Boston Scientific is a reminder that sometimes the most immediate impact is much simpler:
The business can’t operate normally.
On 25 August, medical technology company Boston Scientific identified a cybersecurity incident that caused a global disruption to parts of its network.
The impact went beyond access to IT systems. The company confirmed that affected systems supported its ability to manufacture products, process orders and ship them to customers.
More than a week later, NHS Supply Chain reported that Boston Scientific’s automated ordering, picking, packing and shipping capabilities remained unavailable. Orders could still be submitted, but were being queued for future fulfilment, with some orders being handled through manual processes.
The investigation is ongoing, and Boston Scientific has said there is currently no known impact to its cloud-based systems, with the unauthorised activity identified in certain on-premise systems.
It’s easy to think about cybersecurity in terms of preventing a breach.
But prevention is only part of the equation.
If critical systems suddenly became unavailable tomorrow:
Those questions become much harder to answer when an incident is already underway.
No security programme can promise that an organisation will never experience a cyber incident.
The goal is to make sure an incident doesn’t become a business-ending event.
That means understanding your critical systems and dependencies, detecting and containing threats quickly, having tested recovery processes and knowing exactly who does what when something goes wrong.
Because the true cost of a cyberattack isn’t always the data an attacker takes.
Sometimes, it’s the business you can’t do while your systems are down.
If you’re not completely confident about what would happen if your critical systems went offline tomorrow, talk to us.
Peritus can help you assess your incident readiness, identify critical gaps and build a cyber resilience strategy designed for what happens in the real world.
Talk to Peritus about your cyber resilience →
Browse more content in this category and keep building your knowledge with helpful insights, tutorials, and real-world tips.