Key Takeaways

  • Receivers, restructuring officers, investors, and lenders should treat cybersecurity oversight with the same priority as cash, collateral, and physical asset protection.
  • Operational disruption, lost revenue, and recovery expenses frequently outweigh the ransom payment itself.
  • Regulatory scrutiny and updated NIST guidance are increasing the value of documented controls, tested recovery plans, and clear vendor accountability.

J.S. Held is urging court-appointed receivers, chief restructuring officers, distressed asset investors, and lenders to incorporate cybersecurity into the core fiduciary work performed during every engagement. The global consulting firm advises that ransomware exposure is no longer confined to the IT department. It can affect asset value, liquidity, legal obligations, and the ability of a distressed business to keep operating.

That distinction matters. A receiver may quickly secure bank accounts, inventory, real estate, and other collateral after taking control of a business. Yet compromised administrator credentials, unprotected backups, or an overlooked service provider could still expose the estate to a disruptive attack.

This risk focuses attention on where much of the damage arises: operational interruption rather than the ransom demand alone. A cyberattack can stop production, disable order processing, interfere with supply chains, and prevent employees from accessing critical systems. Revenue may disappear while the business is offline. New leads can go cold, existing customers may move elsewhere, and emergency recovery work can generate substantial additional expenses.

For a financially stressed business, even a relatively short outage can alter a restructuring plan. If the cash forecast assumes normal operations, but billing, shipping, or manufacturing systems remain unavailable for days, the outage directly impacts borrowing availability, creditor recoveries, insurance claims, and the viability of a sale.

Insurance carriers and cyber claims professionals also examine the issue closely. Cyber business interruption is frequently among the largest components of cyber-related financial losses and insurance claims. Calculating that loss involves more than reviewing historical sales. Analysts separate attack-related losses from an existing decline, account for delayed rather than permanently lost revenue, and assess reasonable mitigation expenses.

Distressed environments present unique security challenges. Technology staff may have departed, software updates may have been deferred, documentation can be incomplete, and several vendors may control different parts of the infrastructure. Cost-cutting can also leave monitoring and response functions thin at precisely the wrong moment.

This perspective aligns with growing regulatory attention to fiduciary cyber oversight. Forvis Mazars reported that the U.S. Department of Labor guidance expanded in September 2024 to all ERISA-covered plans, including retirement, health, and welfare plans. The DOL's 2026 enforcement priorities include cybersecurity, increasing the stakes for fiduciaries responsible for participant information and plan assets. Documentation is vital, as vendor assurances alone provide limited evidence of actual oversight.

Practical controls are becoming clearer. NIST published NIST IR 8374 Rev. 1 in June 2026, framing ransomware risk management through the NIST Cybersecurity Framework 2.0. Its approach covers preparation, detection, containment, recovery, and resilience, with particular attention to backup integrity, recovery planning, and incident response.

The Plan Sponsor Council of America has likewise highlighted mandatory multifactor authentication and clear contractual allocation of cyber responsibilities as baseline fiduciary controls for retirement plans. Those principles apply to restructuring engagements: know who controls access, identify which party handles an incident, and confirm whether vendors can restore essential services within an acceptable period.

However, a checklist completed on the first day is insufficient. Receivers and restructuring professionals benefit from identifying critical systems, reviewing privileged accounts, preserving logs, verifying offline or protected backups, and establishing escalation contacts. Insurance notice requirements should also be reviewed early, before an incident creates a rushed coverage dispute.

The larger lesson from J.S. Held is straightforward. Digital systems are operating assets, and their availability can determine whether cash continues flowing. Treating ransomware preparedness as part of fiduciary stewardship helps preserve enterprise value, support defensible decision-making, and reduce the chance that a cyber incident turns an already difficult engagement into a deeper financial crisis.