);
  • Link to LinkedIn
Contact Us: +61 2 9994 8914
Janellis Consulting, Strategy and Resilience
  • Home
  • Capabilities
    • Overview
    • Accreditations
      • Critical Thinking Professional Accreditation
      • Cyber Resilience Professional Accreditation
      • Organisational Resilience Accreditation
      • Stakeholder Engagement Accreditation
    • Case Studies
    • Capability Uplift
    • Executing Strategy
      • Project Delivery
      • Accelerating Strategy EPMO
      • Accelerating Strategy CEO & Executive
      • Stakeholder Engagement & Alignment
      • Change Management & Transformation
      • Strategic Project Management
      • Project Sponsor Capability
    • Organisational Resilience
      • Cyber Resilience Scorecard
      • Organisational Resilience Scorecard
      • Scenario-Based Planning
      • Post Incident Review
      • Governance in Crisis
      • Crisis Management Tools
      • Cyber Crisis Response
      • COVID19
      • City Resilience
    • Project Delivery
    • Scorecard Assessment
      • Cyber Resilience Scorecard
      • Organisational Resilience Scorecard
    • Tools & Frameworks
      • Decision Support Tool
      • Executive Level War Room
      • Organisational Resilience Framework
      • Critical Thinking Framework
  • Featured Insights
    • Case Studies
    • Spotlight Articles
      • Embedding a Unified Decision-Making Process
      • The Role of the Board in a Crisis
      • The Role of the CEO in a Crisis
      • Building a Culture of Cyber Resilience​
      • Responding to Cyber Security Risks
      • HBR Organisational Resilience Paper
      • Building an Agile Workforce
      • How to Build your Organisation’s Resilience
      • Creating a Thinking Organisation
    • Cyber Resilience Resources
    • COVID-19 Resources
    • Research Initiatives
      • Critical Thinking & Decision Making within Agile Environments
      • Strategies for Building Resilience in Critical Infrastructure
      • The Value of Change Management in Executing Strategy
  • Events
  • News
    • Spotlight Articles
    • Articles
    • In the Media
    • Awards
  • About Us
  • Contact
    • Contact Us
    • Join Us
    • Engage a Consultant
  • Click to open the search input field Click to open the search input field Search
  • Menu Menu

Responding to Cyber Security Risks

Boards and senior executives can achieve higher levels of assurance their organisations can prevent and rapidly respond to major and multiple cyber-attacks, by uplifting critical thinking capability.

Organisations around the world are experiencing some of the most challenging security and privacy breaches to date, exposing millions of their customer’s personal data to criminals.

We know organisations are spending a significant amount on continuing to secure their systems. According to Cybersecurity Ventures, protecting consumers from cybercrime will drive global spending on cybersecurity services to $1.75 trillion for the five-year period from 2021 to 2025.i

The Australian government’s response to the recent cyber-attacks has demonstrated a growing lack of confidence in Australian business leaders with Attorney-general Mark Dreyfuss warning companies could be subject to hundreds of millions of dollars in penalties for serious or repeated hacks. The new legislation includes fines of up to $50 million, three times the value of any benefit obtained through the misuse of information or 30% of a company’s adjusted turnover in the relevant period.ii

The government’s Australian Cyber Security Centre’s (ACSC) guidelines for preparing and responding to cyber security incidents predominately focus on improving the technology aspects of cyber security.iii

Although teams and executives complete ongoing cyber awareness training, cyber specialists say human error is still the cause of 99% of cyber breaches.iv In addition to the current guidelines and investments in protecting the data, the focus needs to include the human dimension of cyber resilience.

DOWNLOADS

Article 6 pages

HOW WE CAN HELP

Post Incident Review (PIR)

What more can organisations do?

To prevent cyber security breaches, organisations need to focus on how they anticipate, detect, manage and recover from cyber-attacks.

One way organisations can improve capability holistically is implementing a Cyber Resilience Scorecard that is aligned with a broader Resilience Framework, which fuses cyber resilience capabilities within a single framework comprised of Risk, Readiness, Response and Assurance.

A Cyber Resilience Scorecard can help organisations:

  • Prioritise and validate cyber resilience investments.
  • Identify areas of excellence that should be applied more broadly.
  • Identify gaps in design or capability that need immediate action.
  • Provide assurance to key stakeholders internally and externally.

The scorecard enables organisations to review current investments and approaches to cyber risks and evaluate whether plans, systems, controls, training and scenario-based activities comply and align with standards and regulatory requirements. In addition, a Cyber Resilience Scorecard also provides assurance and guidance for future Cyber Resilience investments.

To combat the ever-present threat of cyber-criminal activity, organisations also need to build and demonstrate their critical thinking skills at every level from the individual to the team, to executive leadership teams, all the way up to the board.

ARTICLES

Cyber Resilience: What Does Good Look Like?

Building a Culture of Cyber Resilience

WHITE PAPER DOWNLOAD

Organisational Resilience Framework Technical Version

Guide to Exceptional Thinking

Ransom demands require rapid, complex decision-making

In the recent Australian Financial Review article, ‘Ashurst’s five tips to handling a hack’, cyber risk consultant, John Macpherson says the second step after auditing the data, is to practise crisis scenarios.


The challenge for a leadership team in the event of a big attack is making critical decisions that impact customers and shareholders in a vacuum of information, very quickly, Macpherson says.

In the third step, Macpherson also acknowledges making any ransom payment is a complex decision-making process and probably one of the most difficult decisions that a board needs to consider.v

We could argue that boards and executives make complex decisions every day and that most would possess an intuitive capability. The challenge with this type of decision, compared to others the board would make, are the higher levels of scrutiny and uncertainty and significant, potential, cascading impacts in the short and long term. Cyber security related decisions also have evolving technical complexity, conflicting or incomplete information and many competing stakeholders’ needs and expectations to consider; and the decision needs to be transparent and defendable.

Currently, few organisations have an agreed, unified, robust, and transparent decision-making framework that can address this level of complexity; and even less have a unified decision-making framework embedded across the enterprise to manage internal events such as security errors that enable cyber-attacks to occur.

Arguably, these are the blind spots and vulnerabilities that cyber criminals seek to exploit.

HOW WE CAN HELP

Executive Level Digital War Room

Scenario-Based Planning

Scenario Planning & Exercising

Cyber Response Resources

Enterprise-wide decision-making framework builds critical thinking skills

The lack of a transparent decision-making framework at any layer of most organisations suggests that high-quality decision-making remains a ‘nice to have’ rather than a business-critical capability that needs to occur daily at every level of the organisation. Many organisations have enterprise-wide systems and enterprise-wide risk management frameworks, but they lack a consistent and transparent decision-making process for use across the enterprise.

High quality decision-making is underpinned by critical thinking skills and whilst most executive leaders have honed this skill, it should not lay exclusively in their domain; particularly where distributed decision-making is an organisation’s strategic objective.

A robust decision-making framework enables critical thinking skills by ensuring individuals and teams take the time to apply best practice tools to separate facts from assumptions, uncover bias and blind spots, identify the main issues or risks, consider potential scenarios, and the broader impacts before making decisions.

Cyber Resilience requires exceptional critical thinking skills

To achieve higher levels of assurance that teams can prevent and rapidly respond to major and multiple cyber-attacks, organisations can embed an enterprise-wide Critical Thinking Framework.

A Critical Thinking Framework can upskill individuals and teams to:

  1. Identify, anticipate, detect and manage threats.
  2. Consider potential scenarios and uncover blind spots.
  3. Recognise, escalate and respond to incidents more quickly.
  4. Make rapid and effective decisions with incomplete or conflicting information, high levels of scrutiny, compressed timeframes and significant impacts.

Creating a culture of cyber resilience across the organisation involves improving how teams assess cyber threats and breaches by building resilience and an adaptive capacity to respond.

HOW WE CAN HELP

Critical Thinking Framework

Critical Thinking Professional Accreditation

Decision Support Tool

Digitally Enabled Team-Based Critical Thinking

Building cyber resilience across the enterprise

  • Review all current cyber security guidelines, standards, and legislation relevant to your organisation.
  • Elevate ‘high-quality decision-making’ to business critical and gain endorsement at the executive and board level to embed a standardised, best practice approach to decision-making across the organisation.
  • Identify a Critical Thinking Framework that can be used at all levels of the organisation to review and build capability to respond to cyber security risks. The Critical Thinking Framework needs to be used in risk identification, mitigation, and response. It needs to be used by individuals for high-quality ‘in the moment’ rapid decision-making, as well as by teams to work through more complex problem-solving and decision-making.
  • Review your current Cyber Resilience capability through the Critical Thinking Framework and against the guidelines and legislation to generate a shared view of current high priority risks and immediate actions. Ensure the review includes your broader resilience capability, such as enterprise risk management, business continuity, disaster recovery and incident and crisis management.
  • Complete War Room Scenario Planning activities using the Critical Thinking Framework to uncover blind spots, resolve immediate areas of vulnerability and build capability.
  • Identify people within the organisation and subject matter experts who have strong decision-making/critical thinking skills to facilitate social learning opportunities, model high-quality decision-making, and accelerate the capability uplift.
  • Identify all high priority teams responsible for preventing or responding to cyber threats and develop a capability uplift program that embeds high-quality decision-making and critical thinking within these teams.
  • Develop an enterprise-wide Critical Thinking Capability Uplift Program to ensure individuals and teams have the skills to identify, anticipate, detect, manage, respond, and recover from on-going cyber related risks. Embed the capability through an Accreditation Program that includes scenario-based planning, social learning opportunities, access to tools, templates, eLearning and aide memoires to build, consolidate and maintain high-quality decision-making capability.
HOW WE CAN HELP

Cyber Resilience Capability Uplift

Cyber Resilience Professional Accreditation

Cyber Resilience Scorecard

CASE STUDIES

Building Cyber and Information Security Resilience: Australian Superannuation Company

Building Cyber Resilience: Leading Australian Government Agency

Summary

Organisations today are tackling multiple, major cyber security breaches using technology solutions alone, which continues to comprise their customers’ privacy and personal safety, all the while incurring millions of dollars in fines.

A more robust approach to cyber resilience is understanding that people are masterminding cyber-attacks by searching and discovering weaknesses within organisational information systems as well as compromised thinking and decision-making processes. Uplifting the critical thinking capabilities of individuals, executive leadership teams and boards within organisations is the most robust method of preventing privacy breaches and building cyber resilience and adaptive capacity. Identifying and managing cyber threats, escalating and responding to incidents and making rapid, robust defendable decisions can prevent further privacy breaches, safeguard customer information and enable organisations to regain their customer’s trust as well as rebuild the value of their companies.

To learn more about our capabilities in this area, visit:

Cyber Crisis Response Overview

Crisis Management Capability Uplift

Janellis Organisational Resilience Framework

Critical Thinking Framework

Executive Level Digital War Room

Embedding High-Quality Decision-Making across the Enterprise Roadmap

About Janellis

Janellis is an enterprise management consulting firm that specialises in helping organisations execute strategy and build organisational and cyber resilience. Since 2006, we have embedded our unique Organisational Resilience Framework within large and complex organisations in Australian critical infrastructure to anticipate, detect, manage, and recover from risk, including cyber security incidents.

Building cyber resilience also involves embedding a Critical Thinking Framework at all levels of an organisation to build capability to respond effectively and rapidly to cyber security risks. Uplifting critical thinking skills relies on experiential and ‘learning by doing’ activities using scenarios. Our Master Facilitators enable experiential learning both in real-time and online using virtual tools where teams put into practice our tools and frameworks.

How Critical Thinking Skills Build Cyber Resilience

“Team-based critical thinking allows us to be both agile and robust in our decision making, drawing upon the brains trust of the organisation”

CEO
Energy Company

“Critical thinking skills are essential skills for our organisation when responding to the rapid onset of change”

Managing Director
Critical Infrastructure

“By developing our critical thinking capabilities our teams can manage difficult situations well and also see the opportunities to execute strategy more efficiently”


Executive Leader
Insurance

Our Upcoming Events

Click on any of the below events to find out more details

Janellis AI Lab

AI Decision Lab | Critical Thinking in an AI-Enabled Environment

26 August, 2026 @ 16:30 - 17:30 AEST
Janellis AI Lab

AI Decision Lab | Critical Thinking in an AI-Enabled Environment

16 September, 2026 @ 16:30 - 17:30 AEST
See All Events

References

[i] Cybercrime Magazine. 2021. Cybersecurity Market Report. [ONLINE] Available at: https://cybersecurityventures.com/. [Accessed 28 October 2022].

[ii] Parliament of Australia. Parliamentary Library. Bills Digest. 2022. Privacy Legislation Amendment (Enforcement and Other Measures) Bill 2022. [ONLINE] Available at: https://parlinfo.aph.gov.au/parlInfo/download/legislation/billsdgs/8863742/upload_binary/8863742.pdf;fileType=application/pdf. [Accessed 08 November 2022].

[iii] Australian Government – Australian Cyber Security Centre. 2022. Preparing for and Responding to Cyber-Security Incidents. [ONLINE] Available at: https://www.cyber.gov.au/acsc/view-all-content/publications/preparing-and-responding-cyber-security-incidents [Accessed 27 October 2022].

[iv] Australian Financial Review. 2022. Medibank, Optus hacks: ‘Human stupidity’ the likely cause, says top cybersecurity expert. [ONLINE] Available at: https://www.afr.com/technology/human-stupidity-likely-cause-of-medibank-optus-breaches-20221025-p5bsqu. [Accessed 27 October 2022].

[v] Australian Financial Review. 2022. Ashurst’s five tips to handling a hack. [ONLINE] Available at: https://www.afr.com/work-and-careers/leaders/five-steps-to-handle-a-cyber-hack-20221102-p5buv6. [Accessed 08 November 2022].

Quick Links

  • Home
  • Project Delivery
  • Cyber Resilience Accreditation
  • Capabilities
  • Executing Strategy
  • Capability Uplift
  • Organisational Resilience
  • Research
  • Events
  • About Us
  • Latest News
  • Contact

Upcoming Events

Aug 26
16:30 - 17:30 AEST

AI Decision Lab | Critical Thinking in an AI-Enabled Environment

Sep 16
16:30 - 17:30 AEST

AI Decision Lab | Critical Thinking in an AI-Enabled Environment

View Calendar

Get In touch

Email
info@janellis.com.au

Phone
Head Office: +61 2 9994 8914

Visit Us Online

  • www.janellis.com.au
  • www.criticalthinkinghub.com.au
  • www.cbdresponse.com.au

Office
141 Walker Street, North Sydney, NSW 2060

Media Enquiries
+61 2 9994 8942

media@janellis.com.au

Our Sites

cbd response logo
Critical thinking Hub
© Janellis | Privacy Policy
  • Link to LinkedIn
Scroll to top Scroll to top Scroll to top