At JG Summit, Cyber Crisis Readiness Begins Before the Breach

Dennis Opiso shares three decisions organizations must make before a cyber crisis

As the digital environment grows more complex, the question is no longer whether every cyberattack can be prevented, but whether a business can continue operating when an attacker gets through.

“The breach may be inevitable. The disaster is optional,” said Dennis Mathew Opiso, Chief Information Security Officer of JG Summit Holdings, at the BusinessWorld Cybersecurity Summit 2026, held on July 21 at Hilton Manila Newport World Resorts.


Joining fellow security and risk leaders for a panel on cyber crisis command, Opiso discussed how organizations should lead, communicate, and maintain continuity during the critical hours following an attack. Strong defenses remain essential, he said, but prevention alone does not make an organization resilient. Systems may still become unavailable, suppliers may be compromised, and leaders may need to act before they fully understand what happened.

Citing a 2026 survey by research and advisory firm Gartner, Opiso noted that 66% of surveyed boards are focused on cyber resilience, reflecting growing recognition that cybersecurity is also about keeping the business running when an attack occurs. Recognizing the need for resilience, however, is only the first step.

“The gap between belief and preparation is where incidents become disasters,” Opiso said.

For leaders, preparation comes down to three questions:

     • Who will command?
     • What must happen during the first two hours?
     • How will the organization verify identities and instructions under pressure?

Establishing One Clear Command

“The commander’s job during an incident is not technical. It cannot be delegated to IT and audited once a year,” Opiso said.

Cybersecurity specialists investigate the attack, contain the threat, and begin restoring systems. The crisis commander carries a different responsibility: making decisions with incomplete information, keeping the response aligned with business continuity, and maintaining enough order for people across the organization to perform their roles.

This distinction becomes critical once an incident affects operations, customers, sensitive information, or regulatory obligations, because leaders must then weigh business, legal, and reputational consequences at the same time. The crisis commander should therefore be appointed in advance and given clear authority, rather than selected while an attack is already underway and the organization is most in need of clarity.


Opiso described the appropriate structure as “federated readiness, unified command.” Business units should be capable first responders because they understand their operations and immediate risks, but once an incident crosses a defined severity threshold, one decision authority should direct the wider response.

“One commander,” Opiso emphasized. “Confusion does more damage than the attacker.”

That leader, however, still depends on technical, legal, operational, communications, and risk specialists. The team provides the expertise, but accountability must remain clear.

Rehearsing the First Two Hours

Assigning responsibilities on paper is not enough, because organizations need to know whether their people can carry them out under pressure. “A plan you haven’t tested is a document, not a capability,” Opiso said.

Simulation exercises, often called tabletop exercises, allow leaders and response teams to work through a hypothetical cyberattack before confronting a real one. Even a short session can expose unclear reporting lines, conflicting priorities, and uncertainty over who may authorize major actions. The simulation should go beyond technical containment to cover who will notify regulators, communicate with employees and customers, issue an initial public statement, disconnect systems, or suspend a service.

Such decisions are easier to make “on a calm Tuesday,” Opiso shared, rather than at 2 a.m. while an attack is unfolding. The first two hours can shape the entire response, requiring leaders to establish command, assess the impact, protect critical operations, activate the right teams, and create reliable channels for sharing information. Urgency matters, but acting quickly without coordination can deepen the damage.

Verifying Identity Under Pressure

Artificial intelligence has made impersonation and social engineering more difficult to detect. A cloned voice can sound like a trusted executive, while a compromised account can make a fraudulent instruction appear legitimate, especially during a crisis when employees may feel pressure to bypass normal controls in the interest of speed.

“Trust by familiarity is dead,” Opiso warned. Organizations need reliable ways to verify sensitive instructions, privileged access, and the identities of everyone involved in the response, with those controls remaining in place throughout recovery, particularly when administrative access is restored or systems are reconnected.

Preparing Leaders Before the Crisis

An effective crisis commander is not chosen solely for technical expertise. The role requires judgment, composure, business understanding, and the ability to provide clear direction amid uncertainty.

Cyberattacks may be unpredictable, but the leadership structure should not be. “Crisis commanders aren’t found during a crisis,” Opiso concluded. “They’re built before one.”

Organizations may not be able to control whether the bad day comes, but they can control whether it remains a contained incident or becomes a public crisis.