SecuritylabJuly 21, 2026🇷🇺Translated from Russian

How CISOs Can Speak to CEOs: Translating Cyber Risks into Business Impact and Financial Consequences

The morning of July 28, 2025, brought a major cyber incident to Aeroflot, resulting in widespread flight cancellations. Groups Silent Crow and Belarusian Cyber-Partisans claimed they had maintained access to the airline’s internal network for over a year, exfiltrated data, and disabled thousands of servers. Although the company did not publicly confirm the full scope, the operational fallout—canceled flights, a criminal case opened by prosecutors, market scrutiny of shares, and stranded passengers—moved the event beyond purely technical territory.

In almost every large organization, security teams have previously documented weak points such as legacy systems, third-party contractors, privileged accounts, and poorly segmented networks. Yet these warnings are frequently viewed by executives as routine budget requests rather than credible scenarios for business disruption. The core issue often lies not in firewalls or detection tools but in the language used to convey risk to the CEO.

Two Languages in One Office

CISOs typically present data on EDR coverage, mean time to detect, vulnerability remediation rates, and multi-factor authentication adoption. CEOs mentally convert these figures into questions about potential financial loss, halted processes, accountability to customers and regulators, and effects on revenue if action is postponed. Surveys by EY reveal a perception gap: 68% of CISOs believe senior leadership underestimates cyber threats, while 57% of other C-level executives agree. Splunk’s CISO Report 2025 shows that 46% of CISOs measure success by security milestones, compared with only 19% of board members who expect return-on-investment language and concrete damage reduction.

Real-World Consequences of Miscommunication

Several 2024–2025 incidents illustrated the cost of failing to translate technical risks:

  • Marks & Spencer lost contactless payments and online order fulfillment for weeks after an attack attributed to a third-party contractor, with profit impact estimated at £300 million.
  • Jaguar Land Rover halted global production for nearly six weeks following detected unauthorized activity, causing an estimated £1.9 billion loss to the UK economy.
  • Clorox filed a $380 million lawsuit against Cognizant over a 2023 incident allegedly enabled by inadequate identity verification at the service desk.
  • Change Healthcare suffered a breach through a Citrix portal lacking multi-factor authentication; UnitedHealth later confirmed a $22 million ransom payment and exposure affecting approximately 190 million individuals.

Regulatory Pressure and Personal Liability

Actions by the SEC against SolarWinds CISO Timothy Brown and the criminal conviction of Uber’s former security chief Joe Sullivan established that statements to regulators and disclosure timing can result in personal legal consequences. In Russia, Federal Law No. 420-FZ introduced turnover-based fines for personal data breaches, reaching 1–3% of annual revenue. These developments make cybersecurity a direct concern for boards and top executives.

Recommended Translation Approach

The article supplies a practical mapping of common CISO statements into language CEOs understand, emphasizing specific business processes that could stop, daily downtime costs, and comparisons between proactive investment and post-incident remediation expenses. Effective dialogue begins with three questions: which business process may halt, what a day of downtime costs, and whether reducing risk now is cheaper than explaining consequences later.

Related articles

AntiMalwarePolicy & Regulation

Russia's Ministry of Digital Development to Bind M2M SIM Cards to Devices and Restrict Unauthorized Calls Starting 2027

The Russian Ministry of Digital Development has proposed new regulations requiring companies and individual entrepreneurs to register M2M SIM cards and associated equipment in the ESIA system. The rules, scheduled for launch on September 1, 2027, aim to combat fraud by preventing the misuse of these cards for anonymous calls and mass messaging. Each M2M SIM card will be strictly tied to a specific device, with changes to identifiers allowed only once per month except in cases of loss or damage. Operators will gain access to a unified platform for managing SIM cards, including activation, deactivation, status checks, location tracking via base stations, and service suspension for discrepancies. All relevant data such as owner INN, operator details, equipment type, identifier, and installation address must be submitted through Gosuslugi or operator platforms. Voice calls will be limited to one minute, white lists for contacts can be updated monthly, and mass SMS or auto-dialing will be banned except for authorized senders.

AntiMalwarePolicy & Regulation

Russia Simplifies State Support Access for National AI Model Developers

Russian authorities have decided to shorten and clarify the path to government support for developers of large AI models. Following the entry into force of the law on artificial intelligence development, obtaining the status of a national or sovereign model will become easier, with decisions verified through a single set of test tasks. The reference test is planned to be published in open access and updated regularly, allowing developers to know in advance the exact criteria the state will use to evaluate their neural networks. Companies such as MWS AI and T-Bank will be able to apply for the new statuses and associated support measures. Expertise will be entrusted to several organizations that have passed state verification, with the main criterion being Russian company control over the entire model lifecycle rather than the origin of every line of code. The use of foreign components under open licenses will be permitted if the developer can independently modify, develop, and maintain the solution. Bureaucratic procedures will be reduced, missing documents can be submitted after the application, and computing infrastructure must be located in Russia but can be rented. The first areas of mandatory application of domestic models will be education and public services, with key provisions of the law taking effect on September 1, 2026, and requirements for sovereign models on March 1, 2027.

HabrPolicy & Regulation

EU Extends Chat Control 1.0 Regulation to 2028 Despite Privacy Concerns and Parliamentary Opposition

The EU Council has extended Regulation (EU) 2021/1232, known as Chat Control 1.0, allowing voluntary scanning of unencrypted messages by providers such as Discord and Gmail until 2028. The measure targets detection of child sexual abuse material but has drawn criticism for its impact on encryption and privacy. A proposed Chat Control 2.0 version under COM(2022) 209 would mandate scanning of encrypted communications, which critics argue undermines end-to-end encryption. The extension passed after a July 2026 European Parliament vote failed to reach the required majority due to absent lawmakers. Investigations revealed lobbying ties between Commissioner Ilva Johansson's office and organizations including Thorn and WeProtect Global Alliance. The European Data Protection Supervisor found that targeted advertising supporting the regulation violated EU data rules.

HabrPolicy & Regulation

NIST Bans Periodic Password Rotation While Russia's FSTEC Mandates 90-Day Changes for Government Systems

In July 2025, NIST released the final version of SP 800-63B, explicitly prohibiting periodic password changes with the requirement that verifiers and CSPs shall not require subscribers to change passwords periodically. Eight months later, in April 2026, FSTEC approved a methodological document requiring passwords in state information systems and critical information infrastructure to be changed at least every 90 days, with mobile devices limited to 30 days and no reuse of the last 12 passwords. The requirements originate from Order No. 117, which itself contains no mention of passwords, but delegates details to lower-level methodological documents including the April 2026 guide that defines measure IAF.3. Compliance is enforced through the KZI protected indicator calculation submitted to FSTEC twice a year, with penalties including zeroing of the 0.25 weight group for repeated failures and immediate zeroing during penetration testing. The policy applies to government bodies, state unitary enterprises, institutions, and CII subjects, while commercial organizations outside this scope retain flexibility to set their own policies based on threat models. NIST and FSTEC requirements align closely on minimum length, failed attempt limits, MFA for privileged accounts, and prohibition of default passwords, differing primarily on the rotation mandate.