How CISOs Can Speak to CEOs: Translating Cyber Risks into Business Impact and Financial Consequences
The morning of July 28, 2025, brought a major cyber incident to Aeroflot, resulting in widespread flight cancellations. Groups Silent Crow and Belarusian Cyber-Partisans claimed they had maintained access to the airline’s internal network for over a year, exfiltrated data, and disabled thousands of servers. Although the company did not publicly confirm the full scope, the operational fallout—canceled flights, a criminal case opened by prosecutors, market scrutiny of shares, and stranded passengers—moved the event beyond purely technical territory.
In almost every large organization, security teams have previously documented weak points such as legacy systems, third-party contractors, privileged accounts, and poorly segmented networks. Yet these warnings are frequently viewed by executives as routine budget requests rather than credible scenarios for business disruption. The core issue often lies not in firewalls or detection tools but in the language used to convey risk to the CEO.
Two Languages in One Office
CISOs typically present data on EDR coverage, mean time to detect, vulnerability remediation rates, and multi-factor authentication adoption. CEOs mentally convert these figures into questions about potential financial loss, halted processes, accountability to customers and regulators, and effects on revenue if action is postponed. Surveys by EY reveal a perception gap: 68% of CISOs believe senior leadership underestimates cyber threats, while 57% of other C-level executives agree. Splunk’s CISO Report 2025 shows that 46% of CISOs measure success by security milestones, compared with only 19% of board members who expect return-on-investment language and concrete damage reduction.
Real-World Consequences of Miscommunication
Several 2024–2025 incidents illustrated the cost of failing to translate technical risks:
- Marks & Spencer lost contactless payments and online order fulfillment for weeks after an attack attributed to a third-party contractor, with profit impact estimated at £300 million.
- Jaguar Land Rover halted global production for nearly six weeks following detected unauthorized activity, causing an estimated £1.9 billion loss to the UK economy.
- Clorox filed a $380 million lawsuit against Cognizant over a 2023 incident allegedly enabled by inadequate identity verification at the service desk.
- Change Healthcare suffered a breach through a Citrix portal lacking multi-factor authentication; UnitedHealth later confirmed a $22 million ransom payment and exposure affecting approximately 190 million individuals.
Regulatory Pressure and Personal Liability
Actions by the SEC against SolarWinds CISO Timothy Brown and the criminal conviction of Uber’s former security chief Joe Sullivan established that statements to regulators and disclosure timing can result in personal legal consequences. In Russia, Federal Law No. 420-FZ introduced turnover-based fines for personal data breaches, reaching 1–3% of annual revenue. These developments make cybersecurity a direct concern for boards and top executives.
Recommended Translation Approach
The article supplies a practical mapping of common CISO statements into language CEOs understand, emphasizing specific business processes that could stop, daily downtime costs, and comparisons between proactive investment and post-incident remediation expenses. Effective dialogue begins with three questions: which business process may halt, what a day of downtime costs, and whether reducing risk now is cheaper than explaining consequences later.
Related articles
Costly Mistakes: How Russian Businesses Risk Millions in Fines for Personal Data Violations
A year after stricter Russian personal data protection fines took effect, many entrepreneurs continue to commit violations that could trigger multimillion-ruble penalties from Roskomnadzor. The article details ten common breaches, including the prohibited use of Google Forms for data collection, missing cookie banners, absent or invalid consent forms under forms, and failure to obtain separate consents for publishing reviews. Additional violations cover missing privacy policies, outdated notifications to Roskomnadzor, improper transfer of employee data to third parties without written consent, lack of data processing agreements, and absence of records for paper-based data storage locations. Each violation is explained with direct references to the Law on Personal Data, the Code of Administrative Offenses, and specific government orders, along with exact fine ranges for citizens, individual entrepreneurs, and legal entities. Practical remediation steps are provided, such as replacing foreign services with Yandex Forms, drafting compliant consent texts per Article 9, and submitting updated notifications under Order No. 180. The guidance emphasizes conducting a full site audit and implementing all required documents to avoid penalties throughout 2026.
Rethinking SSO: Centralized User Data Provision and Authorization Processing in Corporate Systems
The article examines Single Sign-On systems not merely as authentication gateways but as architectural hubs for delivering user attributes and executing additional authorization logic. It highlights how SSO can aggregate data from sources like Active Directory, HR systems, and IDM platforms, then deliver it via OIDC claims to downstream applications. The discussion covers the shift from fragmented integrations across dozens of apps to a single trusted enforcement point using standards such as aggregated and distributed claims. It also explores the authorization pipeline where SSO acts as a Policy Enforcement Point querying external Policy Decision Points via the AuthZEN Authorization API 1.0. Practical examples include electronic business cards, role assignment, access routing, and mandatory MFA checks before token issuance. The piece stresses maintaining data ownership with source systems while establishing SSO as the single point of trust for applications.
Bitrix24 Releases Fully On-Premise BI Constructor for Regulated Enterprises
Bitrix24 has introduced a new delivery model for its BI Constructor that allows complete deployment inside a customer's own infrastructure. The update eliminates any requirement for external servers, cloud APIs, or internet connectivity, ensuring that all corporate data remains within the organization's closed perimeter. Previously, even the boxed version of the platform needed access to external infrastructure for updates and auxiliary services, creating conflicts with internal security policies and regulatory demands in highly regulated sectors. The new on-premise variant performs all data processing and storage exclusively on customer servers, giving organizations full control over access rights, backups, updates, and integration with internal protection tools. The solution is compatible with the boxed edition of Bitrix24 running on PostgreSQL and does not connect to external CDNs or cloud services. Bitrix24 expects strong interest from large enterprises and organizations handling restricted-access data that must stay inside the corporate network. Pilot implementations have already been completed, with broader customer pilots planned in the coming months.
Russia's Data Leak Penalties: 2.6 Million Rubles in Fines Despite 1.58 Billion Records Exposed in 2025
Russia introduced turnover-based fines for personal data leaks through Federal Law 420-FZ in late 2024, fundamentally altering the economics of information security investments. Over the first 18 months, Roskomnadzor opened 52 administrative investigations and issued 40 protocols totaling just 2.6 million rubles in penalties, with zero turnover fines applied. This occurred against a backdrop of 1.58 billion compromised records in 2025 alone. Public data leaks dropped fourfold in the first half of 2026, yet trading activity on underground forums rose nearly 60 percent as operators shifted to private sales. The law now ties penalties directly to the number of affected individuals and adds a turnover component for repeat violations under Article 13.11 of the Code of Administrative Offenses. Analysts note that the mere threat of larger fines has prompted companies to reassess data retention policies and risk models even without actual enforcement precedents.