Skip to content
Proof Concept Anatomy Breach Crisis Response A 31600

Proof Concept Anatomy Breach Crisis Response A 31600

www.databreachtoday.com • September 29, 2026

When a breach hits, problems escalate fast. What begins as a technical issue quickly becomes a business, legal and reputational crisis. In those early hours, decisions carry long-term consequences, yet many organizations struggle to respond with clarity and speed.

See Also: Your Mission-Critical Dev Tools Have No Backup. Your Dev Velocity and Your Business Pays the Price

In this Proof of Concept on "Anatomy of a Breach," panelists shared advice on how to manage that moment. Don Gibson, former CISO at Kinly, now heading up a fractional CISO practice, led security architecture at Travelex during a high-profile ransomware attack in 2019. He advises calm leadership, clear communication, rapid coordination and setting aside feelings of failure.

"You're going to have to start to put all that behind you very quickly and start being a calm, clear voice - because a lot of people are going to be losing their heads," Gibson said.

At the same time, delays in recognizing the incident, gaps in visibility, and weak organizational alignment can intensify the impact, warned Lars Klinghammer, global IT security remediation and resilience leader at DXC Technology.

"If you don't know what you have, if you don't know what's going on, then it's difficult to protect against these kinds of situations," Klinghammer said. Gibson and Klinghammer joined Anna Delaney, ISMG's executive director of productions, and Tom Field, ISMG's senior vice president of editorial, to : How breaches escalate from technical incidents to business crises; How early decision-making shapes long-term impact and recovery; How visibility, culture and coordination affect incident response. Anatomy of a Breach Series In this three-part series, ISMG asks security leaders and legal professionals to break down the key steps for breach readiness, incident response and remediation, and dealing with the long-term legal and regulatory fallout. Episode 1 features experts on preparedness from Equifax and Rapid7. Episode 3 focuses on managing the legal and regulatory fallout with experts from Blackbaud. the Speakers For more than two decades, Gibson has created pragmatic security programs that mold strong, diverse and resilient teams and functions that help deliver business objectives. He also advocates for cyber mental health. He was previously CISO at Kinly, head of cyber at the Department for International Trade for the U.K. government and security architect at Travelex. He is a member of the CyberEdBoard . Klinghammer leads global remediation and resilience at DXC Technology’s security delivery practice and was recently named a Distinguished Technologist. With more than 30 years of experience in cybersecurity consulting, he leads complex, large-scale security initiatives for organizations worldwide, helping them strengthen resilience and recover from security incidents. He previously worked as security architect and consultant at HPE Enterprise Services and Microsoft.

Gibson and Klinghammer joined Anna Delaney, ISMG's executive director of productions, and Tom Field, ISMG's senior vice president of editorial, to :

How breaches escalate from technical incidents to business crises;

How early decision-making shapes long-term impact and recovery;

How visibility, culture and coordination affect incident response.

Anatomy of a Breach Series

In this three-part series, ISMG asks security leaders and legal professionals to break down the key steps for breach readiness, incident response and remediation, and dealing with the long-term legal and regulatory fallout. Episode 1 features experts on preparedness from Equifax and Rapid7. Episode 3 focuses on managing the legal and regulatory fallout with experts from Blackbaud.

For more than two decades, Gibson has created pragmatic security programs that mold strong, diverse and resilient teams and functions that help deliver business objectives. He also advocates for cyber mental health. He was previously CISO at Kinly, head of cyber at the Department for International Trade for the U.K. government and security architect at Travelex. He is a member of the CyberEdBoard . Klinghammer leads global remediation and resilience at DXC Technology’s security delivery practice and was recently named a Distinguished Technologist. With more than 30 years of experience in cybersecurity consulting, he leads complex, large-scale security initiatives for organizations worldwide, helping them strengthen resilience and recover from security incidents. He previously worked as security architect and consultant at HPE Enterprise Services and Microsoft.

Klinghammer leads global remediation and resilience at DXC Technology’s security delivery practice and was recently named a Distinguished Technologist. With more than 30 years of experience in cybersecurity consulting, he leads complex, large-scale security initiatives for organizations worldwide, helping them strengthen resilience and recover from security incidents. He previously worked as security architect and consultant at HPE Enterprise Services and Microsoft.

Advanced SOC Operations / CSOC

Data Backup and Recovery

Data Breach Notification

Fraud Management & Cybercrime

-Generation Technologies & Secure Development

Training & Security Leadership

Executive Director, Productions, ISMG

An experienced broadcast journalist, Delaney conducts interviews with senior cybersecurity leaders around the world. Previously, she was editor-in-chief of the website for The European Information Security Summit, or TEISS. Earlier, she worked at Levant TV and Resonance FM and served as a researcher at the BBC and ITV in their documentary and factual TV departments.

Extracted Entities

Attack Types (1)

Companies (1)