Editor's Note: Originally published August 12, 2016. This article was substantially updated in July 2026 to reflect current governance practices and the broader organizational lessons that remain relevant today.
Many organizations respond to security incidents by investing in more technology. Often, however, the underlying problem isn't technical at all. This real-world ransomware incident illustrates why governance—not just security tools—is essential to building a resilient organization.
Several years ago, our team was asked to help an organization recover from a ransomware attack.
At first glance, the situation looked familiar. Files had been encrypted, employees couldn't access important information, and leadership wanted to understand how their security systems had failed.
The organization had invested in cybersecurity. They had antivirus software, email filtering, and other technical safeguards that represented good security practices at the time.
But as we investigated what happened, it became clear that the real failure wasn't technological.
It was organizational.
The attack succeeded because someone made a well-intentioned business decision outside the organization's normal processes. Technology can reduce risk, but it cannot compensate for unclear governance or inconsistent organizational processes.
That lesson has only become more relevant.
The Problem Wasn't the Security Software
When organizations experience a cyberattack, the first instinct is often to ask whether they need different tools.
Should we buy another security platform?
Do we need a stronger email filter?
Should we replace our antivirus software?
Those are reasonable questions, but they're often the wrong place to start.
Technology can block known threats, detect unusual activity, and help organizations recover more quickly. What it cannot do is govern the countless day-to-day decisions people make while trying to accomplish their work.
In this case, the organization's security tools were only one part of a much larger system. The real issue emerged when an established business process was bypassed in an effort to solve an immediate problem.
No security platform can fully compensate for decisions that occur outside an organization's governance framework.
Governance Exists for a Reason
Like many organizations, this team wasn't trying to ignore security.
They were trying to solve a business problem.
A department needed to fill an open position quickly. Someone chose a more convenient approach than the organization's standard hiring process. It seemed like a minor adjustment at the time.
Unfortunately, that small exception created an opportunity for attackers.
This is how many organizational risks develop—not through malicious intent, but through well-meaning people creating workarounds that unintentionally bypass established safeguards.
Governance is often misunderstood as bureaucracy. In reality, good governance provides clarity about how important decisions should be made, who is responsible for them, and why certain processes exist in the first place.
When those expectations become unclear, even experienced employees can unknowingly increase organizational risk.
The Same Pattern Appears Far Beyond Cybersecurity
Although this incident involved ransomware, the underlying pattern is remarkably common.
Employees adopt new software because it helps them work faster.
Departments create their own spreadsheets to track critical information.
Teams begin using AI tools without understanding how organizational data is being processed or stored.
Managers develop local processes that gradually replace official ones.
Each individual decision may seem reasonable. Collectively, however, they create complexity, inconsistency, and risk.
We've spent decades talking about "shadow IT." Today, organizations are seeing the same dynamic emerge with Shadow AI.
The technology has changed, but the governance challenge has not.
Technology Supports Good Decisions
One of the reasons governance is often overlooked is that it isn't as visible as technology. New software is easy to demonstrate. Policies, decision-making frameworks, and clearly defined responsibilities are much harder to see, even though they often have a greater impact on how an organization operates.
Over the years, we've seen organizations invest heavily in technology while giving much less attention to the processes and governance that determine how those tools are actually used. The result is often frustration. The technology works as designed, but the organization struggles because expectations are unclear, responsibilities overlap, or employees create their own workarounds.
Technology is an important part of organizational resilience, but it cannot make decisions on behalf of the organization. That still requires thoughtful leadership, clear governance, and well-designed processes.
Governance Creates Consistency
One of the benefits of good governance is that it helps organizations make better decisions long before a crisis occurs.
When roles, responsibilities, and processes are well understood, employees don't have to invent new approaches every time they encounter a challenge. They have a framework for making decisions, knowing when to ask questions, and understanding where exceptions should be reviewed.
That doesn't eliminate risk—no organization can do that—but it does make the organization more resilient. Small, well-intentioned decisions are less likely to create unintended consequences because they're made within a shared framework rather than in isolation.
Whether an organization is strengthening its cybersecurity program, adopting AI, modernizing Microsoft 365, or improving knowledge management, the underlying challenge is remarkably similar. The technology may change, but organizations are still relying on people to make thoughtful decisions, follow established processes, and exercise good judgment.
Final Thoughts
Every security incident teaches technical lessons.
The most valuable ones teach organizational lessons.
The ransomware itself was ultimately contained and the organization recovered. What stayed with us wasn't the malware—it was the reminder that technology alone cannot compensate for unclear governance, inconsistent processes, or ad hoc decision-making.
Organizations become more resilient not simply by buying better technology, but by strengthening the organizational foundations that allow technology to work.
Continue Reading
This article explores one aspect of organizational governance. If you're interested in related topics, these resources provide additional executive guidance.