With 90% of Hadwin’s working life spent helping clients respond to incidents – he is in the privileged position of seeing organisations go through some of the biggest crises they will experience, and throughout his career has gained insight into the foundations that can deliver big impact when the worst happens.
What has rung true time and time again, is that when incidents occur, there are things that could have been done beforehand to mitigate their impact.
While this could be the case in a myriad of ways depending on the business – Hadwin approached his keynote around mitigation through the lens of organisational and cultural aspects within firms that can have a huge impact on how you absorb and recover if the worst is to happen.
He explored this through three distinct themes: external team, survival strategy and culture.
External Team
Incident response rarely happens in isolation. While internal teams play a critical role, the speed and complexity of modern cyber incidents often require organisations to draw on trusted expertise from their network. A strong team combined of carefully curated internal and external specialists can make the difference between an organisation’s ability to promptly respond and an uncertain and ineffective plan of defence.
Hadwin explained that forming an external team to support is the factor that costs – or rather wastes – the most time when an incident occurs, in his opinion.
In most cases, in the event of a cybersecurity incident, organisations will need help from external providers, for example, forensic investigators, infrastructure specialists, or crisis comms professionals.
“Very often these situations are not something that can be handled using internal resources only”, Hadwin posited.
Often, security leaders will be raising an incident to other senior leaders in a business – and they will all come to the same realisation that external help is required. Hadwin noted: “The question becomes, who comes in at this point?”
Often this question is met with silence.
What you want to avoid is a “scramble to appoint the people at very short notice”.
You may end up running into a range of problems from competing against other organisations for resources, to your preferred provider not having capacity.
Hadwin commented: “Organisations can end up losing 24, 48, 72 hours dealing with this bottleneck, and you don’t need me to tell you this, but that’s an awfully long time in the event of a cyber-incident. Not least from an operations disruption point of view, but also in terms of the havoc a threat actor may be wreaking in that time”.
“So how do we address this issue in peacetime?”
Organisations should think about who they would want to work with in a crisis. Build the relationship with your “dream team” now.
Secondly, organisations should consider the tools and capabilities they may need access to during an incident, whether that includes specific cyber defence technologies or cyber insurance. It’s important to recognise that certain partners and insurers operate within defined ecosystems of technologies and vendors, so these dependencies should be understood.
Create an environment where you have access to the right range of resources – ahead of time.
Thirdly, make sure contracts with these providers are fit for purpose.
When considering your external team, “make sure this is not an appointment, make sure it’s a relationship, get to know these people outside your organisation”.
“By taking the time and helping them to get to know the intricacies of your organisation”, they can be integrated more quickly and “help save valuable minutes, hours, or days, when [a cyber incident] happens”.
Survival Strategy
Survival strategy was the second component the audience were urged to consider.
When an incident escalates, organisations will look to try to maintain some sense of organisational continuity. Rather than attempting to run operations at their peak, sustaining core operations, critical services and a minimum level of service becomes the priority. Establishing this baseline ahead of time will create clarity in a time of serious uncertainty.
“Imagine you have a destructive cyber-attack happening, what’s the fundamental question they are going to ask you around the table?”
The question that we see asked when things go well, is often how do we keep progressing?
But in times of crisis, this question becomes “What’s our minimal viable business, what’s the absolute minimum we need to do to keep the lights on, to keep selling and to keep enough people happy enough to get through all of this?
“That might sound like an unambitious aim from a strategic point of view”, but, Hadwin highlighted, the end goal is getting back to where we were yesterday, so we can keep progressing..
“This creates a view of the business where leaders can understand their main priorities, allowing them to strategically get back to the minimum viable business, before they get back to where they were yesterday, eventually”.
Hadwin’s advice was to map out your minimum viable business, map the dependencies and test your ability to get back to that baseline.
Assume worst case scenario – this allows organisations to understand their first security priorities and where to focus on mitigating risks within the organisation, prior to an attack.
Internal Culture
The third topic Hadwin brought offered insight on was how culture impacts cybersecurity responses. Even with the right plans and external support in place, the effectiveness of cyber responses can be impacted by organisational culture.
Cultural issues can stagnate decision-making and undermine recovery. Getting this right can support a controlled, team-effort response, and avoid prolonging disruption.
You can create an organisation with a great external reputation, and fantastic infrastructure, but you can still fail on internal culture.
Hadwin shared: “In the face of a destructive cyber-incident, there are so many decisions that need to be made under intense pressure, with a lot of uncertainty. And a lot of the decisions that need to be made can have negative short-term consequences.
“Those are not easy situations to operate in”.
His experience allowed him to highlight three culture issues that he sees most often, and how to navigate them.
The first cultural problem is ”an absence of empowered decision makers”, he noted.
Organisations often lack clarity in who can make decisions – “particularly decisions that will cause disruption”.
There can be a culture in organisations where each executive (c-suite and board member), thinks another is responsible.
“If you have pre-agreed authority levels and decision making capabilities – and practise them and have them formalised – it makes that process so much quicker”.
Hadwin again emphasised the value of time, and cost of wasted time, in this context.
The second cultural issue Hadwin often notices is a blame culture.
“If an organisation’s instinctive reaction in response to an incident is to find out what mistakes were made and by whom, you will probably find that people in key situations and key roles will start to think about things quite differently. They might be less open and try to conceal information”.
In this situation they will start to defend their own position, rather than focus on organisational recovery.
“Having a blame culture is something which has to be actively managed”, organisations should strive to “foster a culture of openness, zero blame”.
Hadwin noted he has seen significant differences in the levels of success of response to cyber-incidents, with culture playing a significant role.
Finally, he highlighted “outdated thinking” as an indicator of organisations ability to prepare and respond to cyber threats.
There have been so many game changers in security, even in the last few years. Hadwin said: “From a proactive risk management and security point of view the pace of change is well known.
“On the incident response side, sometimes we still see thinking which years ago might have been appropriate, but which is now less and less relevant and therefore less and less useful”.
For example, “we see too much emphasis placed on looking at the point of ingress in an investigative context and from a containment point of view, [with] people thinking that is a top priority”.
However, if a threat actor has been in the system for days, point of ingress becomes less important as it will already have established persistence.
“Cultural change is not something that you can do quickly or in an instant, it takes time, so you have to embed it in everything you do”.
Recommended reading
- Scottish Cyber Awards 2026 | Meet the Finalists
- Report: Public Sector Scottish Cyber Activity 2026
- Cybersecurity Talent Is the UK Job Market’s Hot New Bombshell
He urged the audience to consider whether any of these issues might apply to their organisation – and if so to start to address them.
Hadwin concluded, if he could sum up his learnings, he would say “pretty much everything that determines the outcome of a cyber incident, is decided before the incident happens.
“So the external relationships that you have, the minimum viable business that you try to revert to, and the culture that you translate, these are all key variables that we see go wrong quite often, but that can be proactively managed”.
Hadwin set the audience a final call to action, to go back to their organisations and ask these three questions:
“Number one, if you have a serious incident tomorrow morning, would you be able to get your full external response team lined up and ready to go before lunch?
“Number two, if everything were to go down tonight, do you know what you would prioritise and what your minimum viable business would be?
“And number three, internally, do you have the right people empowered to make decisions that may be difficult in a crisis scenario, and do you have the right culture that will support everyone who is involved in the response.
“And if the answer to any of those questions is, don’t know, or definitely not, then I have added something else to your already very busy to-do list!”





