30 Jul 2026

Is your business crisis‑ready?

Cybersecurity stock 1

Written by Jo Yeaman from MIH Group

Most organisations believe they are prepared for a crisis.

After all, they have cybersecurity training, risk registers, and business continuity plans tucked away somewhere. But when a real crisis hits — fast, unexpected, and deeply disruptive — those assumptions are quickly tested.

The uncomfortable truth is that crisis readiness isn’t proven in theory. It’s only proven when something goes wrong.

 

When “Well‑prepared” isn’t enough

In June 2024, our client, Synnovis - a major pathology services provider to the NHS in south east London - experienced a significant cyberattack during a period of complex transformation. The organisation was consolidating more than 70 laboratories, integrating over 100 legacy IT systems, and setting up a new central hub. Staff were reportedly well-briefed on cyber safety, and yet attackers succeeded in gaining access and believed to have been inside systems for days or even weeks before detection.

This is a reminder that even organisations doing many of the right things remain vulnerable - especially during periods of change.

 

The real‑world impact of a cyber crisis

The effects of the attack were immediate and severe:

  • Emergency operations and transplants cancelled
  • GP testing unavailable for weeks, with specimens destroyed
  • Over 11,000 outpatient appointments and procedures cancelled
  • Daily testing capacity dropped from more than 100,000 tests to around 1,000
  • Loss of access to finance, HR, ordering, and laboratory systems
  • No connectivity between labs or clients, meaning a return to manual processes
  • A major blood shortage, prompting a nationwide appeal
  • More than six months to restore services
  • No clear picture of what data may have been stolen
  • Significant financial losses and long‑term reputational damage

Crucially, the attack resulted in major clinical disruption to two major NHS acute hospital Trusts and hundreds of GP practices, affecting millions of patients.

Reputational damage was also high, with consumer trust and confidence severely damaged. And with most systems offline, the ability to identify and contact the thousands of clinical service users was severely impaired.

 

Crisis readiness is about people, not just plans

One of the most important lessons from incidents like this is that crisis readiness extends well beyond technical controls. It is about clarity, communication, and leadership under pressure.

A crisis exposes unanswered questions very quickly:

  • Who is in charge?
  • Who needs to be contacted first?
  • What do staff, partners, patients, or customers hear — and when?
  • Who speaks to the media?
  • How are critical decisions made when information is incomplete?

Without prior discussion and rehearsal, these questions don’t slow a crisis down — they amplify it.

 

Ten questions every leadership team should be asking

At MIH, we’ve developed ten key questions which can be used as a useful way to stress‑test readiness. If you cannot confidently answer ‘yes’ to all of them, then you’re not ready!...

  1. Have you identified the things that could realistically go wrong?
  2. Have you rated the likelihood and potential impact of those risks?
  3. Do you have outline response plans for the most likely scenarios?
  4. Do you know who your key stakeholders are and how to reach them quickly?
  5. Do you have up‑to‑date emergency contact details for all employees and key service users?
  6. Is it clear who would handle media engagement in a crisis?
  7. If your work could harm clients or the public, do you have emergency contact routes for them?
  8. Have you identified the key people needed to respond?
  9. Are those people trained, prepared, and contactable urgently?
  10. Has the leadership team discussed all of the above — and do they each know their role?

Many organisations find they can answer “yes” to some, but not all. That gap is where risk lives.

 

Making crisis readiness real

Crisis readiness isn’t about predicting every possible event. It’s about building the muscle memory to respond effectively under pressure. That means:

  • Regularly revisiting risks, especially during transformation or change
  • Practising crisis scenarios, not just documenting them
  • Having access to trained, competent and willing spokespeople and leaders
  • Ensuring contact lists, roles, and decision‑making authority are clear
  • Aligning technical response with communications and leadership actions

The organisations that recover fastest are rarely those with the thickest plans — they are the ones that have talked honestly about what they would do when things go wrong, not if.

 

Final thought

Cyber incidents, system failures, and operational crises are no longer remote possibilities. The question for leaders isn’t whether a crisis might happen, but whether their organisation is truly ready when it does.

Because that’s when outcomes - and reputations - are shaped.

Get in touch to find out how MIH Group can help you become crisis-ready - or help you handle one if it’s already happening.

Related topics