podcast_1080-primary (2)
CISO Unplugged
SureCloud Production
Subscribe

18 Dec 2025   |   11:54 Share this

Share this episode

Copy the link or share directly:

E1: The First 72 Hours: What Really Matters in a Major Incident

Cyber resilience is no longer just a security problem. It is a business survival issue.

 

In this episode of CISO Unplugged, Nick Rafferty sits down with Jon Staniforth, a CISO with more than 20 years of experience across complex, highly visible organisations, to unpack what resilience really means when cyber incidents and IT outages are inevitable.

 

The conversation explores why communication during a crisis is often the defining factor in how organisations are judged, how early uncertainty shapes regulatory reporting and why many businesses struggle to balance transparency with accuracy. Jon also explains the critical distinction between business continuity and IT disaster recovery, and why rushing to recovery can sometimes do more harm than good.

 

The discussion then widens to resilience as a strategic capability. From cultural mindset shifts and executive governance to supply chain dependencies and third party risk, this episode highlights why resilience must focus on keeping essential services running, not just adding more security controls.

 

With real-world examples and practical insights, this episode is designed for senior leaders navigating increasing regulatory pressure, operational complexity and rising expectations from customers, regulators and boards.

 

Key Topics Covered

  • Why crisis communication shapes trust during major incidents

  • How regulatory reporting timelines affect incident response decisions

  • Business continuity versus disaster recovery and why the difference matters

  • Resilience as a cultural and governance challenge, not just a technical one

  • Lessons from major outages at global technology providers

  • Understanding and managing supply chain and third party dependencies

  • How resilience is likely to evolve under regulations such as NIS2 and DORA

 

Who Should Listen

  • Chief Information Security Officers

  • Chief Information Officers

  • Risk and compliance leaders

  • Business resilience and continuity professionals

  • Senior executives with operational accountability

Hosted by: Nick Rafferty CEO and Co-Founder

Guest: Jon Staniforth CISO

  • Cybersecurity
Vector
Reviews

Read Our G2 Reviews

4.5 out of 5

"Excellent GRC tooling and professional service"
The functionality within the platform is almost limitless. SureCloud support & project team are very professional and provide great...

Posted on
G2 - SureCloud

5 out of 5

"Great customer support"
The SureCloud team can't do enough to ensure that the software meets our organisation's requirements.

Posted on
G2 - SureCloud

4.5 out of 5

"Solid core product with friendly support team"
We use SureCloud for Risk Management and Control Compliance. The core product is strong, especially in validating data as it is...

Posted on
G2 - SureCloud

4.5 out of 5

"Excellent support team"
We've been happy with the product and the support and communication has been excellent throughout the migration and onboarding process.

Posted on
G2 - SureCloud