Ransomware and the New Business War: Professor Kai London's Battle Plan for Critical Services
By the Ezeiza Times Business Desk
Ransomware can now halt an airline, freeze a payment processor or shut down a logistics network. For operators of critical services, Professor Kai London, a senior CISO, frames it as a war to be planned for, not merely a technical incident to be handled. “When ransomware hits a critical service, the question is not ‘can we recover our data?’ but ‘can we keep operating?’”
“The hard decisions — containment, ransom, disclosure — must be made before the crisis, not during it. The first 24 hours decide the outcome.”
Decide in advance
“The worst time to decide whether you will pay, how you will communicate, or when you will disclose is at 3am with systems down,” London says. He urges boards to make these decisions ahead of time and rehearse them.
Lead the first day
Leadership, not just technology, decides the outcome. Clear command, pre-agreed roles and the ability to operate while core systems are down separate those who contain the damage from those who wear it.
The legal clock
Disclosure timelines are tightening, with director accountability attached. “A ransomware event is a governance and legal event now, not only a technical one,” London notes.
Resilience by design
His controls: tested, offline-capable backups; segmentation to limit spread; and containment plans that assume the attacker is already inside. “Assume breach, contain the blast radius, rehearse recovery,” he says — and treat resilience as a competitive advantage that wins the trust of regulators and customers.
For services whose disruption strands people and stops commerce, London's counsel is to treat ransomware as a board-level operational risk: planned for, rehearsed, and survivable by design.
About Professor Kai London. Professor Kai London is a senior technology, security and transformation executive with 25+ years of board- and C-suite leadership across banking, aviation, defence, government and critical national infrastructure. He is Founder & CEO of Quantum AI Systems Security, an Honorary Professor in Cybersecurity, AI & Quantum Computing and a UCL researcher, holding CISSP, CISM, CCISO, ISO 27001 Lead Auditor, ISO 42001, DORA and NIS2 credentials. He is available for board advisory, NED and interim/fractional CISO/CIO/CTO mandates across the UK and internationally. Learn more at professorkailondon.com.
