Back
Eva Sagemo
Chief Financial Officer, Tomra Systems

Eva Sagemo

🎥 Mar 26, 2024 📺 Business Insight Group ⏱ 15m 👁 29 views
Watch on YouTube
Transcript (13 segments)
I
Interviewer0:21
So with me now I have Eva S. Right, uh, just finding the right way. Hello Eva, how are you?
E
Eva Sagemo0:36
I can hear you perfectly fine. Nice to have you here.
I
Interviewer0:42
You're about to tell us about a serious cyber attack that hit you last year, but from your group CFO point of view, without ruining your speech, why do you feel it's important to share such a story with your CFO peers here within Scandinavia?
E
Eva Sagemo0:58
Oh, that's a good question. You know, I think it's very important to share because this is all about prepping other CFOs for what a cyber attack can do with your organization and what you need to think about as also part of your leadership team in an organization. So hopefully that will be inspiring for the listeners today.
I
Interviewer1:22
Perfect. I leave the stage or the scene to you.
E
Eva Sagemo1:26
Thank you. So I didn't prepare any slides today, so I will tell the story a bit from our side, and I hope that that would be inspirational for all of you. So to set the scene, Tomra is a global company consisting of approximately 5,500 employees, and we operate in more than 100 countries through three autonomous business divisions. We are a growth company and we have grown over the last 20 years, also including acquisitions. At Tomra, we decided to centralize it back in 2021 with a reporting line then to CFO. In this centralization project, we established a separate department focusing on security, and the strategy was and still is to build up a holistic security structure and culture within Tomra. We weren't quite finished when the cyber attack hit us back in July, but we were, I would say, well on our way. We have been working according to a kind of three-stage model where maturity was planned to be built over a five-year plan. As I said, a lot was done when the cyber attack hit us, and that was also the reason we believe that we were able to take control of the situation back in July.
I tend to ask people when I talk about this: where were you on July 16, 2023? You know, I remember very well what I was doing. I was in Italy, the vacation had just started, and then on Sunday morning I got a call from the CISO of Tomra, and that is not normal, right? The conversation was very short and to the point, but at the same time it was filled with a lot of unclarity, I would say. It was not entirely certain that the attack at Tomra was extensive, and we didn't at that point in time have a complete overview of the situation. But still I got this feeling, or the sense, that something was really, really wrong. So we decided to define it as a crisis. The first thing I did then was to call Tove to Anderson, and she completely agreed that we should mobilize for a crisis, and then rather back down if it turned out to be less serious. After we hung up, she called the chairman, and I mobilized the crisis teams in Tomra. This is also important: you need to know how to think and act in such a situation. Just to give you a flavor, on July 16, that was a day with a lot of meetings. At one point, the message was that no, we have everything under control, we can just go back to normal, but in the next second it just kind of blew up in our faces, and the attack was really massive. So we decided to pull the plug, that is, to take down the data centers globally.
So that is to take down the data centers globally. When you do that, you know that is not an easy decision to take. In Tomra, we had just signed an agreement with a third party for support for operational safety and information security team setups, and also a company that would do incident response if we had an attack. They were new to Tomra, they didn't know us that well, but they were called in. We quickly understood that we needed to strengthen the team, so we called in a special global team from another company as well. I think in a crisis like this, you need to understand your limitations. That is really key, and that is one of the very important decisions that we took early in the crisis, to really get control of what to do next. Because we didn't really know what had hit us, what kind of damage was done to our systems, and also how we could start putting things back up. And that is important: when you know that you have had an attacker in your system, you don't just put things back up because there can be back doors set up in the system that can hit you hard again. The investigation in Tomra for the incident showed that we were so close to being subject to a ransom demand, either in the form of being shut down from our systems, locked out of our systems, or sensitive data could have been taken out. But since we took down our systems, we had full control of the situation, and we are very glad that we did that, even if it has come with a price of 200 million NOK to rebuild our infrastructure. Just to set it in perspective, it is important that this is not only an IT crisis for a company, it's so much more to think about. For us, our machines: we have more than 110,000 machines globally, where more than 75% are connected back to our systems. So if our customers would have been impacted by the incident through the attacker, that would really damage our trust and reputation in the market. So those are decisions taken in a very hectic time, but looking back in hindsight, that was the right thing to do.
You just need to be bold and dare to take decisions in such a scenario. That kind of links me into crisis management in Tomra. For me, when I mobilized the crisis team in Tomra, I would do that on group level but also in our three business divisions. So I would be leading the group team, and then the divisions would lead their crisis team, but they all work together. We follow the same structure, we use the same communication, and that is important: it's kind of like one voice in a crisis, to both internal stakeholders but also external stakeholders. For us, we also work with an external company when it comes to crisis management training, and we just had a training during the spring, so this was really fresh in mind. That is also very important to reflect on from a leadership team perspective, because in a crisis you shouldn't be in doubt of what to do, how to act, and who should take the different roles. So really think about the structure, what kind of names do you place into the different roles, and if you also have substitutes for those roles, it's important because you need to act and you need to do that fast in a crisis like this. Also, one more thing that I think is important learning from this incident is how you run crisis management team meetings.
It is important to reflect upon having a clear structure on how you run the meetings. It is important because in a time like that, again, a lot of information is flying fast, and you work many hours. It's really unrealistic to think that you can remember and then log it afterwards. So having a clear agenda, asking yourself: do we have any new information since the last meeting? What does that information do with a case? Does it change how we look at our stakeholders? Does it change how we look at the worst case scenario thinking? Do we need to take any new actions or decisions? And then make sure that you log it throughout the whole crisis. One thing that is also very important to reflect on in a crisis like this is information and communication. That is so important, but maybe the most difficult thing, because you need to think about how you communicate internally but also externally. So to really work with your communication teams in-house, but also think if you need to bring in external ones, is important. It's all about how do you communicate to, for us, the stock exchange, how do you work with your investors, how do you work with your customers, and everyone that is outside of your Tomra company, and then also with all your employees. You want the people to run in the same direction, to have the same information, to trust what you are saying. So really think about what kind of data points we need to give and how we should give it: we would do town halls, emails, internet, and so on and so forth. So really having a good understanding of how you should run your communication.
In Tomra, I think also here we are quite proud of the culture in Tomra, so we really, really stand together in the crisis, and I think that is also important. It's not given that your employees will cancel vacations and that they will work nonstop for eight months, but in Tomra they have done so. So I think that is also a result of how we have managed the whole crisis and the rebuild of everything. So now we are closing up on our rebuild in Tomra, and that feels good. We have most of our applications up and running again, our infrastructure for IT, our integrations between systems. So a lot has been rebuilt from scratch, and most of the people in Tomra feel that they are operational again. That is important to have speed and also to be able to deliver to the market. So in Tomra, there is no doubt that this crisis has accelerated our safety journey. As I said, we are in a good place, and we have used this crisis also to do some important transformation, both in terms of from a technical point of view and also in how we have looked at strengthening the awareness for our employees but also customers and suppliers. So to summarize my reflections...
So to summarize my reflections: crisis management plan is important to define role names, do trainings, super important. Also that you need to understand your weak spots in the systems, that you also need to understand what your assets are in your company to protect them, and to categorize them on criticality because you can't take everything back at the same time. Also how you mitigate risk, because you need to define your own risk appetite in your company. So it is important to do that, but also to have a plan on how you should then be operational again, because that is also important for coming back to business as usual as fast as possible. And then work on the communication and also put risk on the board agenda.
And just very quickly on the CFO point of view, for me, not only managing the crisis but also taking care of the whole financial setup. So ERP is done, what do you do? How do you set up your manual processes? How do you document them? How do you prepare for audit? How do you put things into the system again? One thing that is important, that is also difficult, is if you don't have access to your system, how can you follow and track and chase your cash? So that is also something that could be a pressure point for the CFO. Also to think about: will you be able to pay your liabilities or come into a situation where you breach your covenant, for example? So really do the right things before an event happens for you in a future scenario. So hopefully, I see my time is out. I hope that you have at least received some good input for crisis management for cyber attack. And if you would have any follow-up questions, just contact me.