The Dashboard Was Green. The Data Was Gone. Represented by a premium conceptual abstract graphic on a reflective white background illustrating the green dashboard illusion. A sapphire glass cubic matrix on the right glows with a calm emerald-green outer grid, while a hidden red threat stream silently escapes from its core, intercepted and isolated at the base by a razor-sharp neon light-blue containment line to leave the wide left half pristine for text.The Dashboard Was Green. The Data Was Gone. Represented by a premium conceptual abstract graphic on a reflective white background illustrating the green dashboard illusion. A sapphire glass cubic matrix on the right glows with a calm emerald-green outer grid, while a hidden red threat stream silently escapes from its core, intercepted and isolated at the base by a razor-sharp neon light-blue containment line to leave the wide left half pristine for text.
S10 Group Article series · The operational attack realities

The Dashboard Was Green.
The Data Was Gone.

Availability can keep your executive team calm while
exclusivity over sensitive data has already failed.
Article #6
Published: 18 September 2026
By Stan van Gemert | S10 Group
By Stan van Gemert
When attacks move series

Executive summary

The previous publication, “What happens when something still slips through?”, argued that prevention may reduce the chance of entry, but it does not determine what remains controllable afterwards. Once a trusted pathway becomes unsafe, leadership needs to know which identities, connections and data flows can be restricted—and who has the authority to act before the full incident picture is known.

This article follows that control question into a quieter failure mode. An organisation may remain available, functional and outwardly calm while sensitive data is already being copied through a legitimate-looking transfer route. Green availability metrics show that services are responding; they do not show whether the organisation still has exclusive control over the information it holds.

The MOVEit campaign and the Caesars Entertainment disclosure illustrate why data theft can create legal, customer and strategic consequences without causing a visible outage. Backups may restore access, but they cannot restore privacy after information has left the organisation. Leadership therefore needs explicit exposure control: the authority and technical ability to interrupt suspicious data movement before silent loss becomes attacker leverage.

The next publication, “When One Breach Becomes Everyone’s Problem”, widens the lens from data leaving an organisation to operational pressure arriving through a trusted dependency. Using the Change Healthcare disruption, it examines why one provider’s incident can interrupt care, payments and other critical processes elsewhere—and why resilience depends on knowing what can be disconnected, narrowed or kept running.

The illusion of the green dashboard

The dashboard did not look worried. Customer portals responded. Orders moved. Employees logged in, answered questions, processed work and closed tickets. Nothing on the executive status screen looked broken enough to justify a full crisis posture. The morning report showed uptime. The business was still functioning.

Then the message arrived that changed the meaning of every green light.

Files had been copied. Records had left. The systems were still available, but your organisation no longer had exclusive control over the data inside them. That is one of the most uncomfortable realities in modern cyber incidents: the business can keep running while control has already failed.

GREEN IS NOT SAFE
A green dashboard proves that systems are responding.
It does not prove that sensitive data is still under your organisation’s control.

The uptime illusion

Executives are trained to read availability as a sign of health. If the website works, if the payment route is open, if the customer portal responds and if teams can keep using the tools they need, the incident feels contained or even theoretical. That assumption is understandable but it is also dangerous.

Availability is only one dimension of control. It tells the executive team that the system is still usable. It does not tell them whether the data inside that system is still private, still exclusive, still unaltered, still unstaged and still unavailable to criminals.

Data theft does not need to stop the business in order to change the business. It can happen while invoices are generated, appointments are booked, claims are processed, cars are sold, patients are treated, files are transferred and employees continue to work as if nothing has changed.

That is why such incident shape is so difficult for boards and executive teams. There may be no locked screen, no dark hotel lobby, no factory line going silent. The consequence is not the absence of service. The consequence is the loss of exclusivity.

Your organisation still has the data but that is not the same as still controlling it.

AVAILABILITY IS NOT CONTROL
A system can be up. A process can continue. A business can operate.
Data control may still have been lost.

The breach that keeps the lights on

The shape of breach can mislead the executive team because your organisation still looks alive.

The visible business process continues. The portal responds. The transfer completes. The customer-facing operation may remain intact. Yet the asset your organisation was trusted to protect may already have crossed a boundary that cannot be restored by bringing systems back online.

That is why silent data loss belongs in the "When Attacks Move sequence". An attacker does not always need to break availability to create leverage. Sometimes the stronger position is to leave the business calm while the data moves elsewhere.

The dashboard was not lying. It was answering the wrong question.
MOVEit, Caesars and the green-dashboard problem
MOVEIT:
The 2023 MOVEit campaign is a clean example because the affected technology existed to move files. Mandiant reported wide exploitation of a zero-day vulnerability in MOVEit Transfer for data theft, including web-shell deployment and data theft observed in incident-response engagements. The business lesson is not the technical detail of the vulnerability. It is that a trusted transfer route can become the route through which sensitive information leaves.

Caesars Entertainment:
Caesars disclosed in September 2023 that customer-facing operations, including physical properties and online/mobile gaming applications, continued without disruption. The same disclosure said an unauthorised actor had acquired a copy of the loyalty-programme database, including driver’s licence numbers and/or Social Security numbers for a significant number of members. That is the green-dashboard problem in board language: operations can continue while data exclusivity has failed.

What this proves:
Availability metrics answer whether the service is usable. They do not answer whether sensitive information is still under exclusive control, whether a trusted route has been abused or whether an organisation has already inherited a legal, customer and trust problem.

Question:
If sensitive data may be moving through a legitimate path, who can interrupt the flow before the outage is visible and before the evidence is perfect?
View more details chevron A white downward-facing V-shaped chevron on a transparent background.
View more details
Close more details

What is lost when nothing is down

When systems are encrypted, the loss is visible. People cannot work. Customers cannot transact. Operations stop. The incident becomes undeniable.

Data theft is different. It creates consequence before it creates theatre. Your organisation loses control over who can use the data, where it may appear next, how customers will be targeted, whether criminals will return with extortion demands, which regulators must be notified, which contractual promises are now in question and how the public will interpret the delay between internal awareness and external disclosure.

Backups do not solve that problem. A backup can help restore access to data. It cannot restore privacy once a copy has left your organisation. You can rebuild a database. You cannot make stolen information private again by restoring yesterday’s version.

This operational reality marks a critical governance shift: the incident is no longer only about whether the business can continue operating. It is about whether your organisation can still explain, defend and govern what has happened to the information it was trusted to protect.

BACKUPS DO NOT RESTORE PRIVACY
A backup may restore access. It cannot restore exclusivity.
Once sensitive data has left, recovery becomes a trust problem, not only a technology problem.

Why your organisation misreads the situation

Most executive dashboards are built around visible failure. They show whether systems are online, whether applications are responding, whether queues are moving, whether endpoint tools are reporting, whether alerts are open and whether the business process is still functioning.

That is useful but it is not enough.

Data leaving your organisation can look like legitimate activity: a file transfer, a database export, a service account moving information, a cloud sync, a compressed archive, an encrypted outbound connection or a vendor integration behaving normally until someone asks whether the volume, destination, timing or user context makes sense.

Attackers understand this. They do not always need to destroy availability. In some cases, breaking systems too early would damage their own leverage. Quiet theft allows them to keep the victim calm, keep the investigation delayed and keep the pressure external until the moment your organisation is forced to respond publicly.

That is why “nothing is down” is not a resilience statement. It is only the beginning of a better question.
What is still moving?
Where is it moving?
Who authorised it?
And can we interrupt it before the private crisis becomes a public one?

The CISO dilemma

Data theft escalates into a board-level problem long before it becomes a public headline. The CISO may see enough to worry. The legal team may ask whether the evidence is strong enough to trigger notification obligations. Operations may resist blocking a transfer route that supports customers, suppliers or critical internal workflows. The CIO may need to decide whether to isolate a system that appears healthy. The CEO may hear that nothing is visibly broken and still be asked to treat the situation as serious.

That is a hard decision to defend when your organisation is not yet bleeding in public.

Interrupting business activity creates visible cost. Allowing data movement to continue creates invisible risk. In the first hour, the visible cost often feels more real than the invisible risk. That is exactly why data-loss incidents can expand quietly while excutive teams wait for certainty. The better question is not whether the business is still running. The better question is whether your organisation still controls what is running through it.

When sensitive data may be leaving, who has authority to interrupt the flow before the outage is visible and before the evidence is perfect?

Containment before the public crisis

Containment changes the problem from “how bad is the breach?” to “how far is the breach allowed to go while we find out?” That matters because data theft is often discovered at the worst possible moment: after staging, after transfer, after criminals have leverage or after an external party brings the problem back into your organisation. By then, the incident is no longer only technical. It has become legal, reputational, contractual and human.

This is exactly where we step in, at the precise moment when uptime is no longer an adequate measure of control. Our objective is not to keep every system online at all costs, but to preserve enough operational control to interrupt malicious movement, halt data staging, prevent exfiltration, and limit the blast radius. Ultimately, we ensure leadership does not discover too late that a quiet incident has already become an external crisis.

That is exposure control in operational terms. It is not another dashboard that tells your organisation a transfer happened. It is a control layer that helps decide what a suspicious flow is allowed to become.

In a live incident, this distinction matters. If your organisation can interrupt the paths that matter while services remain governed, it reduces the attacker’s leverage before the ransom note, the regulator, the customer email and the press question arrive.

CONTAINMENT IS EXPOSURE CONTROL
The goal is not only to keep systems available.
It is to stop sensitive data from becoming leverage while your organisation can still govern the outcome.

The next horizon

Data exfiltration shows that serious consequences can form while an organisation’s own systems remain available.

The next article widens the boundary again: when a critical supplier is breached, operational pressure can arrive without the attack ever entering your environment. Resilience then depends on knowing which connections can be narrowed, which processes must continue and who can act before another organisation’s incident becomes your own crisis.

Hear first when a new S10 Group release is published

Would you like to receive a short note when S10 Group publishes a new article or newsletter?

Leave your name and email address below. We will send a short update when a new release is available, with a brief summary and a direct link to the publication.
Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.

Coming soon

Monday 21 September:
R03: "When One Breach Becomes Everyone’s Problem"

Wednesday 23 September:
L03: "Why Mature Security Stacks Still Fail Under Pressure"

Further readings