Select Page

Cyberattacks are no longer abstract threats reserved for large corporations or government agencies. Theyโ€™re everyday business risksโ€”quiet, persistent, and increasingly sophisticated. To understand what companies truly face, I sat down with Jon Isenberg, Chief Solutions Architect at The Calysto Group, who has spent decades helping organizations navigate cybersecurity vulnerabilities, incident response, and longโ€‘term protection strategies.

His insights reveal a simple truth: your business is more vulnerable than you thinkโ€”and more capable of defending itself than you realize.

How Fast Could Your Business Recover from a Cyberattack?

Jon begins with a clarification many companies overlook: An incident is not automatically an attack. Itโ€™s a signalโ€”an anomaly inside your network that might indicate malicious activity.

Recovery time depends entirely on what youโ€™ve done before the incident occurs.

โ€œIf you have a good backup, and you can isolate the incident quickly, you may be able to recover in a few hoursโ€ฆ or it may take months.โ€

The determining factors include:

  • Backup strategy โ€” Whatโ€™s backed up? Servers only, or workstations too?
  • Testing frequency โ€” Has your backup ever been validated?
  • Incident detection โ€” Where was the issue found, and what triggered the alert?
  • Company size โ€” Larger networks mean more complexity and longer recovery windows.

A small business with strong backups and quick isolation might bounce back in a day. A midโ€‘sized company with weak protections could face weeks or months of downtime.

Why Every Business Needs a Cybersecurity Incident Response Plan

Most organizations have a business continuity planโ€”a strategy for fires, floods, or physical disruptions. But Jon stresses that this is not enough.

A cybersecurity incident response plan is its digital counterpart, and it must be just as detailed.

It should clearly define:

  • Who to call first
  • Escalation order โ€” internal leadership, national authorities, FBI, etc.
  • Testing procedures โ€” because a plan that hasnโ€™t been tested is just paper.

Jonโ€™s warning is blunt:

โ€œItโ€™s no longer a question of if weโ€™re going to be attacked. Itโ€™s when.โ€

The Human Factor: Our Greatest Cybersecurity Weakness

Machines donโ€™t click suspicious links. Humans do. Jon explains that ransomware, phishing, and social engineering succeed because people are curious, rushed, or simply unaware.

He shares a favorite test used by incident response teams: They drop USB flash drivesโ€”loaded with a harmless โ€œskull and crossbonesโ€ alertโ€”around the office parking lot. Employees pick them up. Employees plug them in. Employees fail the test.

This is why cybersecurity training must be ongoing, repeated, and reinforced. One training session a year wonโ€™t stop a phishing email that arrives tomorrow.

Are Businesses Spending Too Much or Too Little on IT Services?

Jon doesnโ€™t hesitate: โ€œWeโ€™re spending too little.โ€

He frames the decision as a simple financial equation:

  • Spend $10,000 now on proactive protectionโ€”security software, vulnerability scans, penetration testing.
  • Or spend $100,000 to $1,000,000+ later recovering from an attack.

Cybersecurity is not a luxury. Itโ€™s a costโ€‘avoidance strategy.

What Does a Cyberattack Really Cost?

The financial impact varies by industry, but Jon offers sobering examples:

  • A food manufacturer whose AIโ€‘driven system is hacked could unknowingly ship contaminated productsโ€”leading to lawsuits, medical claims, and reputational damage.
  • A construction company whose compromised systems cause structural failures could face injury claims and legal action.

Even a โ€œsmallโ€ attack can easily exceed $100,000, and severe cases climb into the millions.

Will Cyber Insurance Actually Pay Out?

Jon is careful to note heโ€™s not an insurance agent, but heโ€™s seen enough cases to understand the patterns.

Cyber insurance usually paysโ€”unless:

  • The attack was intentional (e.g., a disgruntled employee).
  • The company misrepresented its cybersecurity practices on the application.
  • Required protections (like MFA) were claimed but not actually implemented.

He shares a striking example: A multimillionโ€‘dollar company checked โ€œYes, we use MFAโ€ on its insurance application. They didnโ€™t. An employee clicked a malicious link. The insurer denied the claim.

Jonโ€™s advice:

  • Review your policy with your insurer
  • Verify every requirement with your IT provider
  • Buy standalone cyber policies, not just the $50,000 addโ€‘on bundled with business insurance.

One of his former clients learned this the hard way: their $50,000 policy covered only one day of incident responseโ€”nowhere near enough to remediate the damage.

Final Thoughts: Every Business Needs a Qualified IT Partner

Jon closes with a message every business leader should hear:

โ€œAll businesses need to work with an IT professional.โ€

Whether itโ€™s an internal IT team or an external managed service provider, expertise matters. Many companies benefit from coโ€‘managed IT, where internal staff handle daily operations and an external cybersecurity team manages proactive protection.

The key is simple: Choose an IT partner who understands cybersecurity, has real experience, and can deliver a complete solution.


Expert Spotlights are featured interviews, conversations, and announcements sourced through our event series, audio podcast, and newsmaker interviews โ€” developed with the support of industry partner and sponsor organizations.

Share via
Copy link