
Cyberattacks are no longer abstract threats reserved for large corporations or government agencies. Theyโre everyday business risksโquiet, persistent, and increasingly sophisticated. To understand what companies truly face, I sat down with Jon Isenberg, Chief Solutions Architect at The Calysto Group, who has spent decades helping organizations navigate cybersecurity vulnerabilities, incident response, and longโterm protection strategies.
His insights reveal a simple truth: your business is more vulnerable than you thinkโand more capable of defending itself than you realize.
How Fast Could Your Business Recover from a Cyberattack?
Jon begins with a clarification many companies overlook: An incident is not automatically an attack. Itโs a signalโan anomaly inside your network that might indicate malicious activity.
Recovery time depends entirely on what youโve done before the incident occurs.
โIf you have a good backup, and you can isolate the incident quickly, you may be able to recover in a few hoursโฆ or it may take months.โ
The determining factors include:
- Backup strategy โ Whatโs backed up? Servers only, or workstations too?
- Testing frequency โ Has your backup ever been validated?
- Incident detection โ Where was the issue found, and what triggered the alert?
- Company size โ Larger networks mean more complexity and longer recovery windows.
A small business with strong backups and quick isolation might bounce back in a day. A midโsized company with weak protections could face weeks or months of downtime.
Why Every Business Needs a Cybersecurity Incident Response Plan
Most organizations have a business continuity planโa strategy for fires, floods, or physical disruptions. But Jon stresses that this is not enough.
A cybersecurity incident response plan is its digital counterpart, and it must be just as detailed.
It should clearly define:
- Who to call first
- Escalation order โ internal leadership, national authorities, FBI, etc.
- Testing procedures โ because a plan that hasnโt been tested is just paper.
Jonโs warning is blunt:
โItโs no longer a question of if weโre going to be attacked. Itโs when.โ
The Human Factor: Our Greatest Cybersecurity Weakness
Machines donโt click suspicious links. Humans do. Jon explains that ransomware, phishing, and social engineering succeed because people are curious, rushed, or simply unaware.
He shares a favorite test used by incident response teams: They drop USB flash drivesโloaded with a harmless โskull and crossbonesโ alertโaround the office parking lot. Employees pick them up. Employees plug them in. Employees fail the test.
This is why cybersecurity training must be ongoing, repeated, and reinforced. One training session a year wonโt stop a phishing email that arrives tomorrow.
Are Businesses Spending Too Much or Too Little on IT Services?
Jon doesnโt hesitate: โWeโre spending too little.โ
He frames the decision as a simple financial equation:
- Spend $10,000 now on proactive protectionโsecurity software, vulnerability scans, penetration testing.
- Or spend $100,000 to $1,000,000+ later recovering from an attack.
Cybersecurity is not a luxury. Itโs a costโavoidance strategy.
What Does a Cyberattack Really Cost?
The financial impact varies by industry, but Jon offers sobering examples:
- A food manufacturer whose AIโdriven system is hacked could unknowingly ship contaminated productsโleading to lawsuits, medical claims, and reputational damage.
- A construction company whose compromised systems cause structural failures could face injury claims and legal action.
Even a โsmallโ attack can easily exceed $100,000, and severe cases climb into the millions.
Will Cyber Insurance Actually Pay Out?
Jon is careful to note heโs not an insurance agent, but heโs seen enough cases to understand the patterns.
Cyber insurance usually paysโunless:
- The attack was intentional (e.g., a disgruntled employee).
- The company misrepresented its cybersecurity practices on the application.
- Required protections (like MFA) were claimed but not actually implemented.
He shares a striking example: A multimillionโdollar company checked โYes, we use MFAโ on its insurance application. They didnโt. An employee clicked a malicious link. The insurer denied the claim.
Jonโs advice:
- Review your policy with your insurer
- Verify every requirement with your IT provider
- Buy standalone cyber policies, not just the $50,000 addโon bundled with business insurance.
One of his former clients learned this the hard way: their $50,000 policy covered only one day of incident responseโnowhere near enough to remediate the damage.
Final Thoughts: Every Business Needs a Qualified IT Partner
Jon closes with a message every business leader should hear:
โAll businesses need to work with an IT professional.โ
Whether itโs an internal IT team or an external managed service provider, expertise matters. Many companies benefit from coโmanaged IT, where internal staff handle daily operations and an external cybersecurity team manages proactive protection.
The key is simple: Choose an IT partner who understands cybersecurity, has real experience, and can deliver a complete solution.
Expert Spotlights are featured interviews, conversations, and announcements sourced through our event series, audio podcast, and newsmaker interviews โ developed with the support of industry partner and sponsor organizations.



Recent Comments