SecuritylabJuly 21, 2026🇷🇺Translated from Russian

How CISOs Can Speak to CEOs: Translating Cyber Risks into Business Impact and Financial Consequences

The morning of July 28, 2025, brought a major cyber incident to Aeroflot, resulting in widespread flight cancellations. Groups Silent Crow and Belarusian Cyber-Partisans claimed they had maintained access to the airline’s internal network for over a year, exfiltrated data, and disabled thousands of servers. Although the company did not publicly confirm the full scope, the operational fallout—canceled flights, a criminal case opened by prosecutors, market scrutiny of shares, and stranded passengers—moved the event beyond purely technical territory.

In almost every large organization, security teams have previously documented weak points such as legacy systems, third-party contractors, privileged accounts, and poorly segmented networks. Yet these warnings are frequently viewed by executives as routine budget requests rather than credible scenarios for business disruption. The core issue often lies not in firewalls or detection tools but in the language used to convey risk to the CEO.

Two Languages in One Office

CISOs typically present data on EDR coverage, mean time to detect, vulnerability remediation rates, and multi-factor authentication adoption. CEOs mentally convert these figures into questions about potential financial loss, halted processes, accountability to customers and regulators, and effects on revenue if action is postponed. Surveys by EY reveal a perception gap: 68% of CISOs believe senior leadership underestimates cyber threats, while 57% of other C-level executives agree. Splunk’s CISO Report 2025 shows that 46% of CISOs measure success by security milestones, compared with only 19% of board members who expect return-on-investment language and concrete damage reduction.

Real-World Consequences of Miscommunication

Several 2024–2025 incidents illustrated the cost of failing to translate technical risks:

  • Marks & Spencer lost contactless payments and online order fulfillment for weeks after an attack attributed to a third-party contractor, with profit impact estimated at £300 million.
  • Jaguar Land Rover halted global production for nearly six weeks following detected unauthorized activity, causing an estimated £1.9 billion loss to the UK economy.
  • Clorox filed a $380 million lawsuit against Cognizant over a 2023 incident allegedly enabled by inadequate identity verification at the service desk.
  • Change Healthcare suffered a breach through a Citrix portal lacking multi-factor authentication; UnitedHealth later confirmed a $22 million ransom payment and exposure affecting approximately 190 million individuals.

Regulatory Pressure and Personal Liability

Actions by the SEC against SolarWinds CISO Timothy Brown and the criminal conviction of Uber’s former security chief Joe Sullivan established that statements to regulators and disclosure timing can result in personal legal consequences. In Russia, Federal Law No. 420-FZ introduced turnover-based fines for personal data breaches, reaching 1–3% of annual revenue. These developments make cybersecurity a direct concern for boards and top executives.

Recommended Translation Approach

The article supplies a practical mapping of common CISO statements into language CEOs understand, emphasizing specific business processes that could stop, daily downtime costs, and comparisons between proactive investment and post-incident remediation expenses. Effective dialogue begins with three questions: which business process may halt, what a day of downtime costs, and whether reducing risk now is cheaper than explaining consequences later.

Related articles

BoletimSecPolicy & Regulation

EU Forces Google to Open Android Microphone, Camera and Screen Access for Rival AI Assistants

The European Union has ordered Google to provide competing AI assistants with the same level of access to sensitive Android resources that is currently reserved for Gemini. The ruling covers eleven system functions, including voice activation, home button integration, background execution, and on-device AI model access. Rival assistants will also gain real-time environmental data streams from the microphone, camera, screen, and speakers under identical consent and notification rules applied to Google services. Additional capabilities include cross-app interaction, messaging, scheduling, device settings control, and multi-step task automation. Screen automation will allow assistants to operate apps inside a virtual window while the user performs other activities. Most changes are scheduled for Android 18 by 1 August 2027, while simultaneous activation of multiple assistants by voice keyword will arrive in Android 19 no later than 1 August 2028. Access to the most sensitive functions may require objective security certification and explicit user authorization.

HabrPolicy & Regulation

Walk In, You've Been Recognized: The Evolution of Identification Technologies in Modern Access Control Systems

PERCo has expanded its PERCo-Web access control system with new BLE-enabled readers, companion mobile apps, and a joint facial recognition solution developed with the CRТ group. The update provides an opportunity to examine how identification methods in physical access control have developed without any single technology fully displacing the others. Traditional proximity and MIFARE cards remain the foundation, while QR codes, NFC, BLE, and biometrics each occupy specific niches based on convenience, security, and regulatory requirements. Russian Federal Law 572-FZ has fundamentally changed facial biometrics deployment by mandating use of the Unified Biometric System (EBS) or accredited commercial systems (KBS) for authentication. The article explains the technical workflow from reader to controller, the cryptographic protections of modern cards, the contactless advantages of BLE, and the privacy and compliance considerations that now make facial recognition a 'technology of trust' rather than simple convenience.

AntiMalwarePolicy & Regulation

Russian Users Report Widespread App Store Outages as Roskomnadzor Denies Any Role in Restricting Access

Russian users began experiencing technical problems with the App Store starting early in the day, with the monitoring service Sboy.rf receiving 251 complaints about instability and failed downloads. The majority of reports originated from Moscow, accounting for 20 percent of cases, followed by Saint Petersburg at 13 percent and several other regions including Udmurtia, Kursk, Rostov, Bryansk oblasts and Stavropol Krai each contributing 5 percent. Affected users described inconsistent behavior of the App Store application itself along with difficulties downloading games and other software, where the Get button would appear but actual downloads would succeed only sporadically. In response to the growing number of reports, Roskomnadzor quickly issued a brief statement clarifying that it is not imposing any restrictions on access to the App Store. The exact cause of the disruptions remains unknown, Apple has not provided any official comment, and the scale of the incident is considered limited since only several hundred users have reported issues and not everyone is affected. Standard troubleshooting steps such as verifying internet connectivity, restarting the App Store application, and waiting for service restoration have been recommended to users.

AntiMalwarePolicy & Regulation

VK Apps Remain Downloadable in US Google Play Despite Removal in Russia and Turkey Amid Sanctions

The removal of VK services from Google Play has proven to be less global than initially reported, with applications still accessible to users whose Google accounts are registered in the United States region. Testing revealed a clear geographic pattern: the apps are unavailable in Russian and Turkish storefronts but remain fully visible and installable under the American region. The services disappeared from the store on July 16, prompting VK to confirm that already installed applications will continue functioning without restrictions and directing users to alternative stores such as RuStore. The exact cause of the regional discrepancy remains unclear and may relate to Google Play configuration settings, ongoing sanctions against Russia, distribution policies, or simple catalog synchronization delays. In a related development, VK users have begun receiving notifications urging them to switch to the vk.ru domain, which the company states offers superior speed and reliability and will now serve as the primary address.