SecuritylabJuly 21, 2026🇷🇺Translated from Russian

How CISOs Can Speak to CEOs: Translating Cyber Risks into Business Impact and Financial Consequences

The morning of July 28, 2025, brought a major cyber incident to Aeroflot, resulting in widespread flight cancellations. Groups Silent Crow and Belarusian Cyber-Partisans claimed they had maintained access to the airline’s internal network for over a year, exfiltrated data, and disabled thousands of servers. Although the company did not publicly confirm the full scope, the operational fallout—canceled flights, a criminal case opened by prosecutors, market scrutiny of shares, and stranded passengers—moved the event beyond purely technical territory.

In almost every large organization, security teams have previously documented weak points such as legacy systems, third-party contractors, privileged accounts, and poorly segmented networks. Yet these warnings are frequently viewed by executives as routine budget requests rather than credible scenarios for business disruption. The core issue often lies not in firewalls or detection tools but in the language used to convey risk to the CEO.

Two Languages in One Office

CISOs typically present data on EDR coverage, mean time to detect, vulnerability remediation rates, and multi-factor authentication adoption. CEOs mentally convert these figures into questions about potential financial loss, halted processes, accountability to customers and regulators, and effects on revenue if action is postponed. Surveys by EY reveal a perception gap: 68% of CISOs believe senior leadership underestimates cyber threats, while 57% of other C-level executives agree. Splunk’s CISO Report 2025 shows that 46% of CISOs measure success by security milestones, compared with only 19% of board members who expect return-on-investment language and concrete damage reduction.

Real-World Consequences of Miscommunication

Several 2024–2025 incidents illustrated the cost of failing to translate technical risks:

  • Marks & Spencer lost contactless payments and online order fulfillment for weeks after an attack attributed to a third-party contractor, with profit impact estimated at £300 million.
  • Jaguar Land Rover halted global production for nearly six weeks following detected unauthorized activity, causing an estimated £1.9 billion loss to the UK economy.
  • Clorox filed a $380 million lawsuit against Cognizant over a 2023 incident allegedly enabled by inadequate identity verification at the service desk.
  • Change Healthcare suffered a breach through a Citrix portal lacking multi-factor authentication; UnitedHealth later confirmed a $22 million ransom payment and exposure affecting approximately 190 million individuals.

Regulatory Pressure and Personal Liability

Actions by the SEC against SolarWinds CISO Timothy Brown and the criminal conviction of Uber’s former security chief Joe Sullivan established that statements to regulators and disclosure timing can result in personal legal consequences. In Russia, Federal Law No. 420-FZ introduced turnover-based fines for personal data breaches, reaching 1–3% of annual revenue. These developments make cybersecurity a direct concern for boards and top executives.

Recommended Translation Approach

The article supplies a practical mapping of common CISO statements into language CEOs understand, emphasizing specific business processes that could stop, daily downtime costs, and comparisons between proactive investment and post-incident remediation expenses. Effective dialogue begins with three questions: which business process may halt, what a day of downtime costs, and whether reducing risk now is cheaper than explaining consequences later.

Related articles

HabrPolicy & Regulation

Alfa-Bank Balances Cloud Trust and Zero Trust Models During Migration to Yandex Cloud

Alfa-Bank's head of container and cloud security, Sasha Chertok, detailed how the bank migrated regulated workloads to Yandex Cloud while preserving existing Zero Trust controls. The organization mapped on-premises network segmentation, Active Directory authentication, and firewall policies directly onto Yandex Cloud resources using interconnect links secured with GOST encryption. Responsibility for managed services is shared under a Cloud Trust model, yet the bank retains oversight through Terraform-managed Security Groups, custom CSPM checks, and internal CI/CD gates. User access continues to authenticate via on-premises Active Directory and KeyCloak federations, while authorization leverages granular Yandex Cloud IAM roles. Logging and detection rely on a combination of Yandex Cloud Audit Trail, Cloud Logging, and the YCDR service to compensate for incomplete control-plane visibility. The resulting hybrid architecture now supports 1,500 virtual machines, 100 managed services, and 1,000 identities across multiple environments without disrupting established security processes.

HabrPolicy & Regulation

EnvSpec Naming Standard Introduces Strict Six-Environment Hierarchy for Zero Trust Infrastructure

The EnvSpec Naming 1.0.0 standard proposes replacing ad-hoc hostnames with a strict hierarchical naming system based on environment, perimeter, system, slot and node. It defines exactly six environments—dev, test, stage, prod, infrastructure and workplace—and treats any test or pilot system processing real data as prod. The model projects names into SPIFFE IDs, Kubernetes namespaces, cloud projects and mandatory tags for automated policy enforcement. Rules prohibit direct communication between different linear environments and require all access from workplace devices through dedicated gateways. The standard is published under CC BY-SA 4.0 and includes machine-checkable criteria for compliance.

AntiMalwarePolicy & Regulation

Russian Woman Fined 30,000 Rubles and Loses iPhone 11 for Posting AI-Generated Bear Photo

A resident of Duldurga village in Zabaykalsky Krai was fined 30,000 rubles under part 9 of article 13.15 of the Russian Code of Administrative Offenses for publishing an AI-generated image of a bear presented as authentic. The court also ordered confiscation of her iPhone 11 as the instrument of the administrative violation. The woman knew the photograph was fake before posting it, yet the image spread widely online and was even shared by a local Ministry of Natural Resources channel on 10 September. Local authorities used the case to warn residents that publishing neural-network-generated fake images carries real legal consequences. The incident highlights ongoing enforcement of Russian legislation against the distribution of knowingly false socially significant information under the guise of credible reports. Meanwhile, wildlife specialists continue to investigate separate reports of actual bears near populated areas in the region.

HabrPolicy & Regulation

Inserting Contracts into ChatGPT Risks Major Fines Under Russia's 152-FZ Personal Data Law

A detailed analysis examines the legal consequences of uploading contracts containing personal data into foreign AI services such as ChatGPT under Russian Federal Law 152-FZ. The article clarifies that even standard supply agreements include names, positions, passport details, INN numbers, phones and emails that qualify as personal data. It breaks down applicable administrative penalties from Article 13.11 of the Code of Administrative Offenses, including 150-300 thousand rubles for processing without a proper legal basis and separate fines for failing to notify Roskomnadzor. Cross-border transfer rules under Article 12 require a dedicated notification to the regulator before sending data to services hosted in the United States or European Union. The piece also reviews recent court practice, including a Moscow district court ruling that treated uploading commercial information to DeepSeek as disclosure of trade secrets. No criminal liability under Article 272.1 of the Criminal Code applies to ordinary business use, yet the absence of a data processing agreement with OpenAI or similar providers creates ongoing compliance exposure.