
Cyberattacks are no longer abstract threats reserved for large corporations or government agencies. They’re everyday business risks—quiet, persistent, and increasingly sophisticated. To understand what companies truly face, I sat down with Jon Isenberg, Chief Solutions Architect at The Calysto Group, who has spent decades helping organizations navigate cybersecurity vulnerabilities, incident response, and long‑term protection strategies.
His insights reveal a simple truth: your business is more vulnerable than you think—and more capable of defending itself than you realize.
How Fast Could Your Business Recover from a Cyberattack?
Jon begins with a clarification many companies overlook: An incident is not automatically an attack. It’s a signal—an anomaly inside your network that might indicate malicious activity.
Recovery time depends entirely on what you’ve done before the incident occurs.
“If you have a good backup, and you can isolate the incident quickly, you may be able to recover in a few hours… or it may take months.”
The determining factors include:
- Backup strategy — What’s backed up? Servers only, or workstations too?
- Testing frequency — Has your backup ever been validated?
- Incident detection — Where was the issue found, and what triggered the alert?
- Company size — Larger networks mean more complexity and longer recovery windows.
A small business with strong backups and quick isolation might bounce back in a day. A mid‑sized company with weak protections could face weeks or months of downtime.
Why Every Business Needs a Cybersecurity Incident Response Plan
Most organizations have a business continuity plan—a strategy for fires, floods, or physical disruptions. But Jon stresses that this is not enough.
A cybersecurity incident response plan is its digital counterpart, and it must be just as detailed.
It should clearly define:
- Who to call first
- Escalation order — internal leadership, national authorities, FBI, etc.
- Testing procedures — because a plan that hasn’t been tested is just paper.
Jon’s warning is blunt:
“It’s no longer a question of if we’re going to be attacked. It’s when.”
The Human Factor: Our Greatest Cybersecurity Weakness
Machines don’t click suspicious links. Humans do. Jon explains that ransomware, phishing, and social engineering succeed because people are curious, rushed, or simply unaware.
He shares a favorite test used by incident response teams: They drop USB flash drives—loaded with a harmless “skull and crossbones” alert—around the office parking lot. Employees pick them up. Employees plug them in. Employees fail the test.
This is why cybersecurity training must be ongoing, repeated, and reinforced. One training session a year won’t stop a phishing email that arrives tomorrow.
Are Businesses Spending Too Much or Too Little on IT Services?
Jon doesn’t hesitate: “We’re spending too little.”
He frames the decision as a simple financial equation:
- Spend $10,000 now on proactive protection—security software, vulnerability scans, penetration testing.
- Or spend $100,000 to $1,000,000+ later recovering from an attack.
Cybersecurity is not a luxury. It’s a cost‑avoidance strategy.
What Does a Cyberattack Really Cost?
The financial impact varies by industry, but Jon offers sobering examples:
- A food manufacturer whose AI‑driven system is hacked could unknowingly ship contaminated products—leading to lawsuits, medical claims, and reputational damage.
- A construction company whose compromised systems cause structural failures could face injury claims and legal action.
Even a “small” attack can easily exceed $100,000, and severe cases climb into the millions.
Will Cyber Insurance Actually Pay Out?
Jon is careful to note he’s not an insurance agent, but he’s seen enough cases to understand the patterns.
Cyber insurance usually pays—unless:
- The attack was intentional (e.g., a disgruntled employee).
- The company misrepresented its cybersecurity practices on the application.
- Required protections (like MFA) were claimed but not actually implemented.
He shares a striking example: A multimillion‑dollar company checked “Yes, we use MFA” on its insurance application. They didn’t. An employee clicked a malicious link. The insurer denied the claim.
Jon’s advice:
- Review your policy with your insurer
- Verify every requirement with your IT provider
- Buy standalone cyber policies, not just the $15,000 add‑on bundled with business insurance.
One of his former clients learned this the hard way: their $15,000 policy covered only one day of incident response—nowhere near enough to remediate the damage.
Final Thoughts: Every Business Needs a Qualified IT Partner
Jon closes with a message every business leader should hear:
“All businesses need to work with an IT professional.”
Whether it’s an internal IT team or an external managed service provider, expertise matters. Many companies benefit from co‑managed IT, where internal staff handle daily operations and an external cybersecurity team manages proactive protection.
The key is simple: Choose an IT partner who understands cybersecurity, has real experience, and can deliver a complete solution.
Expert Spotlights are featured interviews, conversations, and announcements sourced through our event series, audio podcast, and newsmaker interviews — developed with the support of industry partner and sponsor organizations.



Recent Comments