The First 30 Days · crisis profile
06 / 06
The Lucky One
You came out of the 30 days on your feet — a little dizzy, but on your feet. A few good decisions, a few less good ones, and a statistically suspicious amount of luck: the attacker could have been more persistent, the backup more broken, the client less understanding. Luck is an excellent ally and an appalling security system: it signs no contract and never shows up twice in a row. Next time — because there is always a next time — it deserves a welcome slightly better prepared than crossed fingers.
3 recommendations
- Pick your first three holes to plug: a tested backup, two-step authentication, and the phone-call rule for any change of bank account — in that order.
- Run a one-hour exercise this month: "what do we do if tomorrow morning the files are encrypted?" — the conversation alone surfaces what nobody in the company knows.
- Decide now, in peacetime, who you call in a crisis — IT company, specialist, contract — so you're not searching the internet with the house on fire.
What's your profile?
12 decisions, 3 minutes — and you'll know how you lead when nobody gives you time to think.
Play it yourself — 3 minutesThen this story isn't just a game for you.
Companies in regulated sectors have legal security obligations — NIS2, in Romania GEO 155/2024 — with reporting deadlines, mandatory measures and real fines. CERTO walks you through them step by step, in plain language, no jargon.
See CERTO — NIS2 compliance without the bureaucracyThe good news: everything you practised here can be trained for real.
The instinct from that first email, the reflex to pick up the phone and verify, a culture where people report — that is exactly what our training programmes build, with realistic simulations and no blame hunts.
A work of fiction — the characters and companies are invented. The attack mechanisms and the lessons are real.