Securitylab•July 21, 2026•🇷🇺Translated from Russian

How CISOs Can Speak to CEOs: Translating Cyber Risks into Business Impact and Financial Consequences

The morning of July 28, 2025, brought a major cyber incident to Aeroflot, resulting in widespread flight cancellations. Groups Silent Crow and Belarusian Cyber-Partisans claimed they had maintained access to the airline’s internal network for over a year, exfiltrated data, and disabled thousands of servers. Although the company did not publicly confirm the full scope, the operational fallout—canceled flights, a criminal case opened by prosecutors, market scrutiny of shares, and stranded passengers—moved the event beyond purely technical territory.

In almost every large organization, security teams have previously documented weak points such as legacy systems, third-party contractors, privileged accounts, and poorly segmented networks. Yet these warnings are frequently viewed by executives as routine budget requests rather than credible scenarios for business disruption. The core issue often lies not in firewalls or detection tools but in the language used to convey risk to the CEO.

Two Languages in One Office

CISOs typically present data on EDR coverage, mean time to detect, vulnerability remediation rates, and multi-factor authentication adoption. CEOs mentally convert these figures into questions about potential financial loss, halted processes, accountability to customers and regulators, and effects on revenue if action is postponed. Surveys by EY reveal a perception gap: 68% of CISOs believe senior leadership underestimates cyber threats, while 57% of other C-level executives agree. Splunk’s CISO Report 2025 shows that 46% of CISOs measure success by security milestones, compared with only 19% of board members who expect return-on-investment language and concrete damage reduction.

Real-World Consequences of Miscommunication

Several 2024–2025 incidents illustrated the cost of failing to translate technical risks:

  • Marks & Spencer lost contactless payments and online order fulfillment for weeks after an attack attributed to a third-party contractor, with profit impact estimated at £300 million.
  • Jaguar Land Rover halted global production for nearly six weeks following detected unauthorized activity, causing an estimated £1.9 billion loss to the UK economy.
  • Clorox filed a $380 million lawsuit against Cognizant over a 2023 incident allegedly enabled by inadequate identity verification at the service desk.
  • Change Healthcare suffered a breach through a Citrix portal lacking multi-factor authentication; UnitedHealth later confirmed a $22 million ransom payment and exposure affecting approximately 190 million individuals.

Regulatory Pressure and Personal Liability

Actions by the SEC against SolarWinds CISO Timothy Brown and the criminal conviction of Uber’s former security chief Joe Sullivan established that statements to regulators and disclosure timing can result in personal legal consequences. In Russia, Federal Law No. 420-FZ introduced turnover-based fines for personal data breaches, reaching 1–3% of annual revenue. These developments make cybersecurity a direct concern for boards and top executives.

Recommended Translation Approach

The article supplies a practical mapping of common CISO statements into language CEOs understand, emphasizing specific business processes that could stop, daily downtime costs, and comparisons between proactive investment and post-incident remediation expenses. Effective dialogue begins with three questions: which business process may halt, what a day of downtime costs, and whether reducing risk now is cheaper than explaining consequences later.

Related articles

AntiMalware•Policy & Regulation

VK Files Lawsuit in EU Court Seeking to Overturn Sanctions Imposed in July

Russian internet company VK has submitted a formal challenge to the European Union's sanctions regime by filing a case with the Court of Justice of the European Union. The company argues that the restrictions placed on VK and its subsidiary Communication Platform LLC are both unjustified and unlawful. The lawsuit, registered under case number T-664/26 on 7 October, directly contests the July sanctions that targeted the developer of the MAX messenger. Earlier restrictions had already led to the removal of multiple VK ecosystem applications from Apple App Store and Google Play, forcing users toward alternative distribution channels such as RuStore, Huawei AppGallery, Samsung Galaxy Store and Xiaomi GetApps. While installed Android applications continue to function and receive updates, iOS users face disrupted push notifications after the apps were delisted. The legal action itself does not automatically restore app availability in the affected stores.

Securitylab•Policy & Regulation

VPN Rules in Russia 2026: No Fine for Ordinary Users but Strict Penalties for Advertising and Extremist Content Access

As of September 2026, Russia maintains no separate administrative fine for ordinary citizens simply connecting to a VPN service. Responsibility arises only for specific actions such as deliberately searching for known extremist materials, advertising tools to bypass restrictions, or failing to comply with Roskomnadzor demands as a service operator. Corporate VPNs used for remote access to company networks remain fully legal under exceptions in Article 15.8 of Law No. 149-FZ. New provisions in the Code of Administrative Offenses, including Articles 13.53, 13.52 and 14.3 introduced by Laws 281-FZ and 282-FZ, impose fines ranging from 3,000 to 500,000 rubles depending on the violation and the offender category. The rules distinguish clearly between end users, service owners and advertisers. VPN technology itself is not banned, yet public services face ongoing blocking and operators must integrate with state filtering systems. The material reflects the regulatory situation on 24 September 2026.

Habr•Policy & Regulation

Troubleshooting Erroneous TSPU Blocks: How Admins Can Collaborate with Russian Regulators

A Moneta client outage traced back to erroneous filtering on Russia's TSPU system rather than internal infrastructure or DDoS protection. Engineers used curl, traceroute, nping, and custom Python scripts to confirm TCP payload-based blocking after the handshake. The team submitted a request via the VTS personal account, received partial acceptance status, then escalated to DCOA and SSOP to obtain the specific TSPU site number. Detailed network traces and active traffic were required for diagnostics. The case highlights coordination challenges between operators, DCOA, and SSOP when erroneous blocks occur on information resources.

AntiMalware•Policy & Regulation

Security Vision Unveils Self-Assessment Portal for Unified Information Security Evaluation Across Corporate Holdings

Security Vision has launched a new Self-Assessment portal designed to consolidate information security self-evaluations for entire corporate groups and holdings. The platform addresses common challenges where subsidiaries maintain inconsistent compliance records, with some requirements fulfilled while others remain unresolved for years in scattered emails and spreadsheets. Security Vision SA covers the complete workflow from defining requirements and distributing questionnaires to calculating results and tracking remediation actions. Parent organizations gain a consolidated view of subsidiary compliance status along with detailed breakdowns by individual systems. The system supports requirement templates, version control, scheduled assessments, automated metric-based answers, and conversion of gaps into actionable plans with assigned owners and deadlines. Additional features include internal policy document management and interactive dashboards for analysis. The first public demonstration is scheduled for the SOC Forum on October 27-28.