September 3, 2026
What if a cyberattack doesn’t steal your data - it stops your business?

When we talk about cyberattacks, the conversation often starts with data.

What was stolen?
How many records were affected?
Was personal information compromised?

But the recent cyber incident at Boston Scientific is a reminder that sometimes the most immediate impact is much simpler:

The business can’t operate normally.

On 25 August, medical technology company Boston Scientific identified a cybersecurity incident that caused a global disruption to parts of its network.

The impact went beyond access to IT systems. The company confirmed that affected systems supported its ability to manufacture products, process orders and ship them to customers.

More than a week later, NHS Supply Chain reported that Boston Scientific’s automated ordering, picking, packing and shipping capabilities remained unavailable. Orders could still be submitted, but were being queued for future fulfilment, with some orders being handled through manual processes.

The investigation is ongoing, and Boston Scientific has said there is currently no known impact to its cloud-based systems, with the unauthorised activity identified in certain on-premise systems.

The bigger question: could your business keep running?

It’s easy to think about cybersecurity in terms of preventing a breach.

But prevention is only part of the equation.

If critical systems suddenly became unavailable tomorrow:

  • Do you know which systems the business absolutely cannot operate without?
  • Could key processes continue manually?
  • How quickly could affected systems be isolated without bringing everything else down?
  • Do you know what needs restoring first?
  • Have your incident response and recovery plans actually been tested?

Those questions become much harder to answer when an incident is already underway.

Cyber resilience is about what happens next

No security programme can promise that an organisation will never experience a cyber incident.

The goal is to make sure an incident doesn’t become a business-ending event.

That means understanding your critical systems and dependencies, detecting and containing threats quickly, having tested recovery processes and knowing exactly who does what when something goes wrong.

Because the true cost of a cyberattack isn’t always the data an attacker takes.

Sometimes, it’s the business you can’t do while your systems are down.

Would your business be ready?

If you’re not completely confident about what would happen if your critical systems went offline tomorrow, talk to us.

Peritus can help you assess your incident readiness, identify critical gaps and build a cyber resilience strategy designed for what happens in the real world.

Talk to Peritus about your cyber resilience →

Explore more in this category

Browse more content in this category and keep building your knowledge with helpful insights, tutorials, and real-world tips.