Cybersecurity Governance: The Board's 24-Hour Fog of War
Return to Part 0: Table of Contents
Previous Article: Part 6, The Hour-Zero Protocol: Navigating the Fog of War
At 3:30 AM Eastern on 11 March 2026, employees at Stryker Corporation sat down at their computers and found them blank. Not locked. Not ransomed. Not waiting for a countdown clock to expire. Just blank. Eighty thousand devices across 61 countries, wiped in under three hours, with no malware deployed at any point. [1][2]
No virus. No exploit. No zero-day vulnerability in the classic sense. An attacker authenticated to a single cloud-based management console using stolen credentials, issued one enterprise-wide wipe command, and walked away. The attack used a legitimate administrative platform exactly as the platform was designed to be used.
By the time European employees arrived at work, Stryker, a Fortune 500 medical technology company with US$25.1 billion in 2025 revenue and 56,000 staff, had sent thousands of workers home in Ireland and issued an internal message describing the situation as a "severe, global disruption." [1] Its corporate communication systems, including Microsoft Teams, Outlook, and every managed device connected to its network, were offline. The crisis response infrastructure had been destroyed by the same attack that triggered the crisis.
So Stryker's senior leadership coordinated their response on WhatsApp.
That detail is not a footnote. It is the governance failure. When your crisis response defaults to a consumer-grade messaging application because the attacker destroyed your corporate communication infrastructure, every decision made in those first 24 hours exists outside your organisation's governance envelope. No audit trail. No discoverable record. No board-level documentation demonstrating that directors exercised appropriate judgement under the Companies Act. A chat thread on personal phones.
This is Part 7 of the Cyber Guide for New Zealand Boards. Part 6 introduced the Hour-Zero Protocol and the decisions that shape everything in the fog of war that follows a serious cyber incident. Part 7 extends that framework into the specific failure mode Stryker crystallised: not the breach itself, but the collapse of board communication governance during the response.
The Management Plane Is the Perimeter Now
To understand what happened at Stryker, you need to understand what Microsoft Intune does and why a compromised Intune admin account is categorically different from a compromised employee account.
Intune is the platform large organisations use to manage their entire device fleet from a single cloud-based console. It enforces security policies, pushes software updates, and provides administrators with one web interface to monitor and control every enrolled device regardless of location. The capability is operationally necessary. It is also a significant attack surface. From one console, a properly credentialled administrator can push a factory reset to every laptop, phone, and tablet in the organisation simultaneously.
That is the exact capability that Iran-linked hacktivist group Handala exploited.
The attack, confirmed by Krebs on Security, Cybersecurity Dive, Palo Alto Networks Unit 42, and a CISA advisory issued on 19 March 2026, followed a pattern security practitioners call living-off-the-land. [1][2][3] Rather than deploying malware, Handala compromised a Microsoft Intune administrator account, authenticated to the console with those stolen credentials, and issued an enterprise-wide wipe command using entirely legitimate platform functions. No endpoint detection tool would have caught it. No intrusion detection system would have flagged it. The attack used the platform exactly as designed, which is precisely what makes it so difficult to defend against after the fact.
Handala claimed to have wiped devices across 79 countries. The conservative confirmed figure, reported by BleepingComputer and independently corroborated by Guardz and IBM security researchers, is approximately 80,000 devices. [4][5] The 200,000-plus figure in Handala's Telegram channel has been assessed as inflated.
This is the Lethal Trifecta realised at enterprise scale.
The Lethal Trifecta, introduced in Chapter 5 of the Cyber Guide for New Zealand Boards and developed in depth in the companion Zero Trust Thursday series, describes what happens when an account simultaneously holds three capabilities: access to sensitive data, authority to execute destructive or irreversible commands, and network-wide reach. [6] Compromising such an account does not give an attacker a foothold. It hands them administrative authority over the entire organisation.
The Stryker Intune admin account held all three. Data access across the full enrolled device fleet. Destructive command execution via remote wipe. Network-wide reach across operations in 61 countries. When Handala authenticated to that console, they did not infiltrate Stryker's network in the conventional sense. They became Stryker's administrator.
The zero trust principle that Part 6 introduced, and that the Zero Trust Thursday series examines in architectural depth, is that identity is the only meaningful perimeter in a cloud-managed enterprise. [7] Firewalls do not protect the Intune console. Network segmentation does not protect the Intune console. The only thing standing between your entire device fleet and a remote factory reset is the credential protecting the admin account. Stryker's credential fell. The perimeter was gone.
CISA understood the implication immediately. Its advisory, issued eight days after the attack, recommended four specific controls: require multi-admin approval for high-impact Intune changes including device wipes; configure alerts for bulk wipe commands triggering on more than three to five devices within a short time window; require phishing-resistant multi-factor authentication (FIDO2 or passkeys, not SMS or push notifications) for all MDM admin accounts; and restrict Intune admin access to specific named, compliant devices from specified locations. [3]
These are not aspirational controls. They are minimum viable protections for the management plane. Yet the attack succeeded. The investigation, led by Microsoft DART and Palo Alto Networks Unit 42, is ongoing. [5]
There is a prior breach dimension worth noting. Stryker disclosed a separate compromise in December 2024, involving unauthorised access between May and June 2024, with personally identifiable information and medical records exfiltrated. [9] Whether persistence from that earlier intrusion contributed to the March 2026 Intune access is under investigation and has not been confirmed by Stryker. The pattern, however, is consistent with a well-documented threat actor behaviour: initial access established during a prior intrusion, followed by an extended period of observation while the attacker maps administrative infrastructure, culminating in a destructive action once the target is sufficiently understood.
Check Point Research confirmed that Handala had been conducting reconnaissance against Stryker's infrastructure for months before the 11 March attack, including brute-force attempts originating from Starlink IP ranges following Iran's internet shutdown in January 2026. [8] This was not opportunistic. It was planned and patient.
The Cultural Security Envelope Failure
The Stryker case validates a second concept from Chapter 3 of the Cyber Guide: the Cultural Security Envelope.
The Cultural Security Envelope is the governed, auditable, discoverable channel architecture that organisations use for decision-making. It encompasses email, internal messaging platforms, videoconferencing, board portals, and management information systems. These channels are governed because they integrate with the organisation's records management infrastructure. Communications within the envelope are discoverable under the Official Information Act and the Public Records Act. They create the audit trail that regulators, courts, and boards rely on to reconstruct decision-making when accountability questions arise.
When Stryker's corporate systems went offline, its Cultural Security Envelope collapsed entirely. WhatsApp, the fallback, sits outside that envelope. It is not integrated into records management. WhatsApp communications are not readily discoverable under corporate governance obligations. They are encrypted end-to-end on personal devices and produce none of the contemporaneous documentation that a Director's Incident Log requires.
That is the Skynet Vector at work: ungoverned, undocumented, unaccountable decision-making, not chosen but defaulted into. The Heaven Vector equivalent, a governed, auditable fallback channel that directors can reach from non-corporate devices at 3:30 AM, requires deliberate architectural design before the incident occurs. It cannot be improvised in the fog.
Consider what WhatsApp-as-crisis-channel means in practice. Every decision Stryker's leadership made in those first hours, which suppliers to contact, which products to pull from distribution, whether to notify regulators, how to communicate with customers whose surgical equipment had just gone offline, exists in a chat thread on personal phones. If a regulator, a court, or a shareholder action later asks what the board knew, when they knew it, what alternatives they considered, and why they chose the path they did, the answer is: we used WhatsApp.
This is not a theoretical concern. Under section 137 of the Companies Act, directors must act as a reasonably diligent person with the general knowledge, skill, and experience appropriate to their position. Demonstrating that standard during a crisis requires documentation. WhatsApp does not produce that documentation. It produces a conversation thread that may not be accessible, may be deleted, and was never designed for the governance purpose it ended up serving.
Beyond the documentation problem, there is a structural risk that organisations should address as a matter of standard practice: maintaining at least one communication channel that does not depend on the same cloud tenant as primary operations. If your crisis plan assumes Teams will work when Teams is the attack surface, the plan will fail the moment you most need it.
The New Zealand Lens
The question every New Zealand director should be asking after reading about Stryker is not whether this could happen here. The question is: what would your board actually do if Teams and Outlook went offline simultaneously at 3:30 AM?
Would you call the board chair on a personal mobile? Send a WhatsApp message? Use Signal? Does your organisation have a pre-designated out-of-band communication channel that all board members know about, can access from non-corporate devices, and is documented in your crisis response plan?
If the answer is unclear, you are in the same structural position Stryker was in before 11 March 2026.
The NZ regulatory context sharpens this question from three directions.
First, the Office of the Privacy Commissioner's position shifted in March 2026. Privacy Commissioner Michael Webster, speaking at the National Cyber Security Summit on 17 March, stated that the OPC is using the NCSC Minimum Cyber Security Standards, published 30 October 2025, as its "defensible baseline" when assessing whether organisations have taken "reasonable steps" under the Privacy Act 2020. [10] This establishes the governance floor for all New Zealand organisations managing personal information, not only those specifically mandated under the Public Service Act. If your crisis response infrastructure relies on a single vendor's cloud platform with no documented out-of-band fallback, that is a gap organisations now need to assess against a published standard the OPC is actively applying. The Stryker scenario, an attacker destroying corporate communications via a management console, is precisely the kind of single-point-of-failure the NCSC Minimum Cyber Security Standards address.
Second, the proposed critical infrastructure legislation creates a more immediate pressure point. The DPMC consultation, open until 19 April 2026, proposes mandatory notification obligations that include a 24-hour initial early warning to DPMC following a cyber incident. [11] For organisations in scope across communications and data, defence, energy, finance, health, transport, and water sectors, these are proposed statutory obligations with director personal liability provisions of up to $100,000 for serious incidents and $500,000 for critical ones.
A board that cannot communicate internally during the first 24 hours of a cyber incident cannot meet a 24-hour external reporting obligation. Those two requirements are directly connected. Organisations considering whether to submit on the consultation should treat the 19 April close as a planning deadline for their out-of-band communication protocols, regardless of when or whether the proposed legislation takes effect.
Third, the ManageMyHealth breach remains the series' ongoing case study. MMH detected the breach on 30 December 2025, notified the OPC on 1 January 2026, and completed a complex multi-week stakeholder notification process. As of 23 March 2026, all patient notifications are complete and MMH's mobile app is preparing to relaunch following an end-to-end security review. [12] The OPC inquiry remains active and ongoing; the Ministry of Health's independent review is due by 30 April 2026. Two governance questions remain in the public domain: what board communication processes governed the first 24 hours after breach detection, and what was the relationship between the anonymous warning the OPC received in June 2025 and board-level awareness of systemic vulnerability? These are exactly the governance questions that post-breach accountability processes examine. For any board in the health, finance, or data-intensive sectors, they are the questions to answer now, before an incident.
What Directors Should Do
The Cyber Guide for New Zealand Boards provides three frameworks that address this gap directly. Each is implementable without a technical project.
The Director's Incident Log as the evidentiary foundation. Part 6 introduced the Director's Incident Log, the real-time documentation template that demonstrates directors exercised appropriate governance during chaos. The Stryker case shows exactly why the log must be initialised before crisis systems go offline. Every significant decision requires a timestamp, the directors present, the information relied upon, any dissenting views, and the rationale for the path taken. This is not bureaucracy. Under section 137 of the Companies Act, directors must act as a reasonably diligent person with the general knowledge, skill, and experience appropriate to their position. The log is the evidence that they did.
But the log is only useful if it lives somewhere directors can reach it when the corporate network is down. That is the practical governance question Stryker forces every board to answer: where does your Director's Incident Log live, and can every director access it from a non-corporate device at 3:30 AM?
The Red Line Matrix for pre-authorised containment. The Red Line Matrix establishes automatic containment triggers for sensitive data types before incidents occur, removing the need for emergency board deliberation in the fog of war. Category 1 of the matrix, covering health records and medical data, requires that any anomaly in health data flows triggers immediate disconnection, with CISO authority to act without board approval and board notification within two hours. This is precisely the model Stryker lacked for its management plane. The board did not need to vote in real time on whether to revoke Intune admin access. That authority should have been pre-delegated, with a defined trigger condition (anomalous bulk wipe command activity) and a named individual authorised to act immediately.
Review your Red Line Matrix against your actual administrative tooling. If your MDM platform, cloud admin console, or identity management system lacks a pre-authorised containment protocol with defined triggers and named decision-makers, that is the gap to close before the next board meeting.
The Crisis Compass for communication decisions. The Crisis Compass provides four directional points for board decision-making under pressure. The North point is most relevant here: stakeholder protection over organisational reputation. When the temptation is to use an ungoverned channel because it is faster and more convenient, the Crisis Compass North points toward the governed alternative, even when that means slower coordination. The board's obligation to maintain auditable decision-making does not pause when systems are offline.
Practically, this means your organisation needs a documented out-of-band communication protocol, pre-registered with all board members and key executives, that does not depend on any platform also used for normal corporate operations. Options include a dedicated secure messaging application on personally managed devices, a pre-agreed telephone tree with direct mobile numbers, or a board portal hosted on an independent provider not integrated with the main corporate tenant. The protocol should be tested annually, specifically simulating the scenario where corporate email and internal messaging are simultaneously unavailable.
The CISA advisory provides the technical baseline. Phishing-resistant multi-factor authentication on all administrative accounts. Multi-admin approval for destructive operations including device wipes. Location-restricted access for management consoles. [3] For New Zealand organisations using Microsoft 365 or any comparable cloud management platform, implementing these controls is a configuration change, not a lengthy infrastructure project. Most IT teams can execute the configurations within weeks.
What it requires is a board that asks the question.
The First 24 Hours Matter More Than the Preceding Months
The source book puts it plainly: the first 24 hours matter more than the preceding months of prevention architecture or the subsequent months of remediation work. This is when governance either demonstrates it is real or reveals it was compliance theatre.
Stryker's story is still being written. The investigation continues, systems are still recovering, and the full governance record of those first hours has not been publicly disclosed. What is already clear is that an organisation generating US$25.1 billion in annual revenue, operating a dedicated security function across 61 countries, had its entire global workforce reduced to a consumer messaging application in under three hours.
The attack used no malware. It needed no sophisticated exploit. One compromised admin credential. A management console with insufficient access controls. That is the entire attack chain.
Every New Zealand organisation managing sensitive data at scale, health records, financial credentials, justice system data, or data held under Te Tiriti obligations, faces the same structural question. Your MDM console, your cloud admin portal, your identity management system: who holds admin access, what does it take to authenticate, and what is the pre-authorised containment plan if that credential falls?
The proposed critical infrastructure legislation is not yet in force. The 19 April consultation closes without immediate enforcement. But the governance gap those proposed obligations are designed to address exists today, regardless of the legislative timeline. And the OPC's adoption of the NCSC Minimum Cyber Security Standards as a "defensible baseline" means that gaps in management plane protection are already being measured against a published standard.
The fog of war does not wait for board meetings. Build the frameworks before the fog arrives.
What communication protocol does your board have for the scenario where Teams, Outlook, and every managed device in your organisation go offline simultaneously? And have you tested it in the last twelve months?
The views expressed in this article are entirely my own, informed by more than 30 years of professional experience in architecture, security, and technology leadership in New Zealand. They do not represent the views of my employer, any government agency, or the New Zealand government. My commentary on legislation and policy is analytical, drawing on publicly available sources and my professional expertise in architecture, security, and AI governance. I follow the Public Service Commissioner's Code of Conduct for the Public Sector and social media guidance.
Andreas Hamberger is a New Zealand leader in Architecture & Security and Associate Member of the Institute of Directors. The Hamberger Report: Cyber Guide for New Zealand Boards is the third book in The Hamberger Report series, providing board members and senior leaders with practical cyber resilience governance guidance.
I use AI tools, including Sudowrite, Claude, Perplexity AI, DeepSeek AI, ChatGPT, Grok, Copilot, Openart and Gemini, as deliberate production tools, not ghostwriters. This is consistent with my position: AI amplifies human judgement; it does not replace it. The frameworks, arguments, and editorial decisions in this series are original work. AI accelerated the process. The thinking is mine.
[1] Krebs, B. "Iran-Backed Hackers Claim Wiper Attack on Medtech Firm Stryker." Krebs on Security. March 2026. https://krebsonsecurity.com/2026/03/iran-backed-hackers-claim-wiper-attack-on-medtech-firm-stryker/
[2] Cybersecurity Dive. Stryker Intune wiper attack coverage. March 2026. [Primary URL to be confirmed by author from research package]
[3] TechCrunch. "CISA Urges Companies to Secure Microsoft Intune Systems After Hackers Mass Wipe Stryker Devices." 19 March 2026. https://techcrunch.com/2026/03/19/cisa-urges-companies-to-secure-microsoft-intune-systems-after-hackers-mass-wipe-stryker-devices/
[4] BleepingComputer. Stryker wiper attack: approximately 80,000 devices wiped. March 2026. [Primary URL needed; author to verify from research package before publication; BleepingComputer cited as source in research package]
[5] Guardz. "The Stryker Story: When Device Management Platform Becomes a Weapon." March 2026. https://guardz.com/blog/the-stryker-story-when-device-management-platform-becomes-a-weapon/
[6] Hamberger, A. Cyber Guide for New Zealand Boards. Chapter 5 (Lethal Trifecta). The Hamberger Report. 2026.
[7] Hamberger, A. Zero Trust Architecture for the Agentic Enterprise. Zero Trust Thursday series. The Hamberger Report. 2026. [LinkedIn series: link]
[8] Check Point Research. Handala reconnaissance and Stryker infrastructure targeting. March 2026. [Primary URL to be confirmed by author from research package]
[9] Lumos Systems. "Stryker Hack." 2026. https://www.lumos.com/blog/stryker-hack
[10] Webster, M. Privacy Commissioner. Speech at National Cyber Security Summit. 17 March 2026. [PRIMARY SOURCE URL REQUIRED; author to locate transcript or OPC publication of speech before publication; speech confirmed via research package]
[11] Department of the Prime Minister and Cabinet. Critical Infrastructure Security and Resilience Consultation. 2026. [DPMC Citizen Space; URL to be confirmed]; see also Simpson Grierson and Minter Ellison legal analyses (cited in research package).
[12] ManageMyHealth. "MMH Cyber Breach Update." 23 March 2026. https://managemyhealth.co.nz/mmh-cyber-breach-update/
Next week in Part 8: Trust does not return automatically after a breach. Rebuilding stakeholder confidence is a governance discipline with specific frameworks, timelines, and accountability structures. Part 8 examines what the recovery phase requires from boards, and what the ManageMyHealth trajectory tells us about the gap between technical remediation and restored trust. Sunday 12 April 2026.

