CIO Applications Europe
About UsConferencePartner With Us
Close
  • Applications
      • Business Intelligence & Analytics
      • Call Center Solutions
      • CRM & Customer Experience
      • Data Center
      • Digital Transformation
      • E-Invoicing
      • Intelligent ERP & Automation
      • Risk Management & Compliance
      • Unified Communications (UCaaS)
  • Industries
      • Automotive & Mobility
      • Construction & Infrastructure
      • Financial Services
      • Healthcare
      • Retail & E-commerce
      • Telecom & Media
      • Travel and Hospitality Tech
  • Technologies
      • Cloud
      • Cybersecurity & Resilience
      • Data Engineering & Analytics
      • Generative and Agentic AI
      • IoT & Edge Computing
      • Robotics
  • Platforms
      • AWS
      • IBM
      • Microsoft
      • Salesforce
      • SAP
      • ServiceNow
  • Leadership Perspectives
  • Innovation Insights
  • Research
  • News
  • CXO Awards
    • Europe
      • US
  • Topics

  • Menu
      • Business Intelligence & Analytics
      • Cloud
      • Digital Transformation
      • Generative and Agentic AI
      • Microsoft
      • Risk Management & Compliance
      • Travel and Hospitality Tech
      • Unified Communications (UCaaS)
  • Microsoft
  • Risk Management & Compliance
  • Travel and Hospitality Tech
  • Generative and Agentic AI
  • Digital Transformation
  • Business Intelligence & Analytics
  • Cloud
Topics
  • Topics

  • Business Intelligence & Analytics
  • Cloud
  • Digital Transformation
  • Generative and Agentic AI
  • Microsoft
  • Risk Management & Compliance
  • Travel and Hospitality Tech
  • Unified Communications (UCaaS)
  • Home
  • Cybersecurity & Resilience

A featured contribution from Leadership Perspectives: a curated forum reserved for leaders nominated by our subscribers and vetted by the Construction Tech Review Advisory Board.

Head of Data Breach Response Services at Experian

Jim Steven

How the Evolution of Ransomware Is Changing How We Communicate to Consumers Who Have Been Impacted

Introduction

The continued growth of ransomware over the last three years has seen cyberattacks as one of the top three risks on most company boards’ risk registers.

This form of attack changed the way companies dealt this these types of crises, as it meant companies must make decisions faster and not always with all the information required.

In 2023, we saw the evolution extend with the ‘Move-It’vulnerability, whichimpacted software used by large numbers of organisations globally and caused personal and corporate data to be compromised and left businesses with the challenge of notifying those impacted as well as dealing with the mitigation of the attack itself.

In this post, I will look at two aspects of the landscape this has resulted in. The way companies had to change their approach to informing consumers, employees, and other cohort groups that their personal information had been compromised and how the industry supporting these companies had to look at better ways to manage the volume of attacks and ensure that capacity and capability was available to support them.

How the Consumer Response Changed

Ransomware reduces the time companies have to plan and inform people. It is designed to elicit payment as the threat actor has control over the timeline and uses deadlines and the release of sensitive information as a tool to get businesses to pay rather than suffer the consequences.

This time pressure has meant businesses now have to work much faster to get to a point where they can control the narrative in respect of the communication, both internally and externally, about the event. In many cases, the exact information compromised is not fully known, as systems are still being investigated to determine what data they contain.

Most companies do have a disaster recovery plan and can get their IT systems back up and running quickly. We see less than 40per cent of companies, however, having a customer communication plan in place. Even using specialist partners from Legal and IT forensics to determine what to do from a regulatory perspective and better understand what data has been compromised still leaves the challenge of letting people know.

Notification

How do you notify people? Email, post, and press release there are a number of options. In reality, it is normally a hybrid of these as contact information for people whose data you hold is varied. In many incidents, you may not know exactly what information is compromised by a person, as this will take a few weeks to determine. So, do you tell people straight away or wait until you know more? Even when you make that determination, do you send these communications to everyone at the same time, or do you stagger them to ensure you can deal with any inbound enquiries that come back?

Inbound Communications and Resourcing

Once communications have gone out, can you cope with the inbound enquiries this generates? Howwill these be handled, by telephone, live chat, chatbot, or email? Do you have enough resources to manage this, or do you need to outsource partners?

Having this resource in place with the relevant scripts and escalation protocols takes time, so it will impact your notification timeline. As with the notification itself, do you need to stagger your communications to balance against the response resource you have available?

There is always a push from businesses to inform consumers and employees as soon as possible, even more so if it is your customer's customers but understanding the consequences of telling someone their personal data is compromised and then not being able to get through to someone to understand the severity of this situation, is likely to compound the issue.

Offering Mitigation Services

Depending on the type of data loss, many companies may decide to offer some form of mitigation. That can take the form of credit/identity monitoring services, compensation, loyalty offers etc. Will this be offered proactively or reactively? What would be the impact on the brand depending on the direction they take? What is the right level of mitigation? Do you offer differing levels according to the level of data loss by an individual?

There are a large number of decisions to be made in a short space of time, and it is that compaction that ransomware gangs utilise to get companies to pay. By continuing to put pressure on the deadline with the release of information or going out to the media to amplify the situation, it continues to ramp up the noise and potential impacts to get people to pay.

Ransomware reduces the time companies have to plan and inform people

How the Industry is Changing to Support Companies

The partners supporting businessesin recovering and responding to these attacks from the Legal, IT, PR, and consumer response industries have been working hard to match the speed of execution that is required.

Especially in relation to the 'Move-it'vulnerability, the sheer volume of organisations affected was and is a huge challenge. How do you have enough resources in place to meet demand, and can you mobilise those resources faster?

Ultimately, many providers have looked at engaging with businesses earlier before an event to pre-allocate resources against a set level of compromise. Organisations determine their risk appetite and will then agree on retainers with partners to ensure they can get the tailored response they need. Where we see systemic events, such as Move-it, is there enough resource available to meet demand, and what do you do if there is not or there is a delay until it is available?

These types of challenges are now a serious consideration. You may have insurance, but is the response guaranteed, and is that important to you?

Having plans around consumer response is becoming ever more important, and the impact ransomware is having in terms of speed of planning and execution is making more businesses ask the question, are we prepared? Do we have a plan? Do we know what resources we need, and are they available?

The articles from these contributors are based on their personal expertise and viewpoints, and do not necessarily reflect the opinions of their employers or affiliated organizations.
The Leadership Perspectives forum brings together voices shaping construction technology and innovation. Participation is by invitation only. It features leaders who are not merely observing technological change, but actively contributing to it through digital transformation and execution-driven insights.
EDITOR'S CHOICE
  • Willis Towers Watson

    Legal & General

    Building Technology Foundations That Last

    Mark Hall, Group Chief Technology Officer

  • Willis Towers Watson

    Adp Uk

    "Shift left" Defect Discovery using Agile and DevOps

    Keith Watson, Director Of Devops

  • Willis Towers Watson

    Motor Oil

    Trust, Security Strategy and the AI-Driven Threat Landscape

    Syngelakis J. Christos, Group Data Protection Officer

  • Willis Towers Watson

    Swiss Re [SWX: SREN]

    A Future of Enhanced Human Work

    Sergio Chelli, IT Procurement Manager at Swiss Re [SWX: SREN]

Weekly Brief

loading

I agree We use cookies on this website to enhance your user experience. By clicking any link on this page you are giving your consent for us to set cookies. More info

×
#

CIO Applications Europe Weekly Brief

Be first to read the latest tech news, Industry Leader's Insights, and CIO interviews of medium and large enterprises exclusively from CIO Applications Europe

Subscribe

loading

THANK YOU FOR SUBSCRIBING

CIO Applications Europe
Follow on LinkedIn

About

  • Home
  • About Us
  • Partner With Us

Stay Connected

  • Subscribe
  • Newsletter
  • Sitemap

Contact Us

  • editor@cioapplicationseurope.com
  • sales@cioapplicationseurope.com
  • marketing@cioapplicationseurope.com

Legal

  • Editorial Policy
  • Privacy Policy
  • Terms of Use

© 2026 CIO Applications Europe. All rights reserved. Headquarteblue in Fort Lauderdale, FL, USA.

This content is copyright protected

However, if you would like to share the information in this article, you may use the link below:

https://cyber-security-and-resilience.cioapplicationseurope.com/leadership-perspective/how-the-evolution-of-ransomware-is-changing-how-we-communicate-to-consumers-who-have-been-impacted-nid-3422.html