With each new revelation, the hacked organization loses credibility and faces greater liability. Not knowing what the attackers got their hands on could be extremely damaging to a company financially. The time to start is long before the breach ever happens, says Adrian Asher, CISO at the London Stock Exchange Group. “If you only ever focus on after the breach then the answer is you cant,” Asher says of the problem. If you haven’t invested in the controls and people before a breach occurs, then youll be ill prepared.”]

