top of page

ARVIND CLEMENTE

Reflection
3

The Weekend That Changed My Life: The Attack

The Attack

One of the most dangerous assumptions in cybersecurity is the belief that enough technology can eliminate risk. After many years in this field, I have come to accept that no organisation is ever completely protected. The goal was never to build an impenetrable fortress, because no such fortress exists.


Some weekends quietly divide your career into two parts: everything before them, and everything after them.


February 2023 was one of those weekends for me.


What began as a silent compromise late on a Friday evening unfolded into one of the most challenging experiences of my professional life. Unknown to us, the attackers had already established their presence inside the network. While the business carried on as normal, they were patiently preparing the environment for what would follow.


The first visible signs appeared on Monday morning. Users began reporting that files could no longer be opened, and familiar file names had changed into unfamiliar extensions. Within minutes, it was clear this was not an isolated technical issue.


The organisation was under a full-scale ransomware attack.


The immediate priority was containment. Internet connectivity was disconnected, remote access was terminated and the investigation began. Every minute mattered. The opportunity to prevent the attack had already passed; the responsibility now was to stop it becoming worse.


As the investigation progressed, the situation grew more serious. The attackers had destroyed the organisation's on-premises backup infrastructure before encrypting production systems. They had also gained privileged access and extracted sensitive company data. What had first appeared to be a ransomware incident was quickly becoming something much larger.


It had become a business crisis.


One lesson from that weekend has stayed with me ever since. Our server naming convention, created simply to make administration easier, had unintentionally become a source of intelligence for the attackers. Systems with predictable names made it easier to identify critical infrastructure.


Sometimes the smallest design decisions create risks that only become visible during a crisis.


Fortunately, one decision made many years earlier would ultimately save the organisation. Long before the attack, investment had been made in a Business Continuity and Disaster Recovery strategy built around multiple independent backup tiers, including immutable offsite backups isolated from the production environment. While the local backups had been destroyed, those offsite copies remained untouched. Without them, the outcome would have been very different.


They became our lifeline.


As the forensic investigation continued, another lesson emerged, one that changed the way I think about organisational visibility. The attackers had not selected their target at random. They had studied the organisation long before deploying the ransomware. Publicly available information, company activities, leadership visibility and financial indicators had all contributed to a picture of the organisation and its potential ability to pay.


Building a strong brand matters. Sharing achievements, celebrating growth and maintaining an active public presence all contribute to business success. But visibility also creates a digital footprint. Threat actors study organisations in much the same way that legitimate customers or investors do, analysing websites, social media, public announcements and executive profiles to understand who their targets are and how valuable they might be.


Brand reputation and cyber resilience are no longer separate conversations. Both require thoughtful governance.


Looking back, I no longer believe cybersecurity is simply about deploying better technology. It is about understanding risk, preparing for failure and building resilience long before it is ever needed. No organisation should measure its cybersecurity programme by the absence of incidents; it should measure it by its ability to withstand them.


The attack was over and the recovery was about to begin.

Closing Reflection

Perfect security is an aspiration. Resilience is a decision.


Organizations are rarely defined by the attacks they suffer. They are defined by how well they prepared before the attack ever began.

— Arvind Clemente

Reflections on Leadership, Technology & Risk
About

These reflections draw on more than 28 years of experience leading technology, cybersecurity and business transformation. Their purpose is not to document events, but to preserve the leadership lessons those experiences revealed.

The views expressed are personal reflections and do not represent the views of any employer, client or organization.

Written from experience. Not from a template.

bottom of page