The Business Is Still Running. Does That Mean the Cyber Incident Was Minor?

The Business Is Still Running. Does That Mean the Cyber Incident Was Minor?
Customers are still being served. Employees are still working. No system appears to be unavailable.
Yet company information may already have been taken.
Levi Strauss recently disclosed that social engineering gave an unauthorised party access to three employees’ company computers. The company reported no operational interruption, but certain corporate information was accessed and extracted.
This highlights an important management blind spot: downtime is not the only measure of a cyber incident.
When an incident occurs, leaders should ask:
• What information was accessed or copied?• Which accounts and devices were involved?• Whether the access has been fully removed?• Who may be affected or require notification?• Whether the information could be misused later?• What allowed the approach to succeed?
One action for today: review your incident assessment process and confirm that it considers information loss, legal obligations, customer trust and future misuse—not only whether operations stopped.
Expected outcome: management gains a more accurate view of the incident and can make better decisions about containment, investigation and communication.
Takeaway: An incident can have serious consequences even when the business never closes.
Sources: Levi Strauss SEC filing and Reuters report




Comments