27 Jul 26
Cyber resilience is becoming an increasingly important part of successful event delivery. Drawing on their respective experience advising major sporting events and responding to complex cyber incidents, Leon Farr (Partner at Onside Law and major events specialist) spoke to Casey O'Brien (Global Head of Incident Response at S-RM) to examine why event organisers should treat cyber resilience as a strategic priority from the outset.
On 19 July, billions of people watched Spain triumph over Argentina in the FIFA World Cup Final. Now imagine a different ending. Forty minutes before kick-off, digital tickets stop validating. Tens of thousands of frustrated supporters queue outside the stadium. Security staff are unsure of the contingency protocol. Within minutes, global broadcasters switch to pictures of growing congestion and social media fills with speculation. Organisers race to establish the cause of the problem. Is it a technical failure, or something else?
Modern major sports events are delivered through complex digital ecosystems involving a wide network of technologies, suppliers and stakeholders. Disruption to one critical system can quickly cascade across operational areas, impacting security, workforce management, broadcast, media, commercial and the spectator experience. According to O’Brien, the complex collaboration necessary to deliver major events creates significant opportunities for threat actors.
“From an attacker’s perspective, the myriad organisations involved in the planning and execution of these events presents a big opportunity. Cyber maturity across these organisations will vary greatly, and an attacker only needs to identify the weakest link in the chain to gain a foothold.”
Major events are also high-profile, time-sensitive and geopolitically significant. This means they are uniquely attractive to a dangerous mix of threat actors.
“Most cyber threat actors fall into one of three groups: nation state actors typically engaged in espionage or strategic disruption; financially motivated criminal groups, often responsible for fraud or ransomware attacks; and hacktivists, who tend to be politically motivated and seek maximum impact.”
This is not a theoretical risk. The 2018 Winter Olympics in PyeongChang suffered a malware attack that disrupted ticketing, Wi-Fi and operational systems during the Opening Ceremony. More recently, Paris 2024 saw sustained cyber attacks targeting local authorities, venues and suppliers.
“We increasingly see ransomware groups targeting sectors where there is limited tolerance for operational disruption. Threat actors understand that their leverage increases when their victims cannot afford downtime, and they will exploit the immediacy of a big, public event to pressure companies to pay big ransoms quickly”.
Despite this, cyber resilience is still too often treated as a technical issue to be addressed later in the planning phase, rather than as a strategic consideration from the outset. Cyber resilience is rarely a scored evaluation criterion during bidding or procurement. Event owners assess everything from venue infrastructure to sustainability and human rights compliance, but almost never cyber resilience. Cyber deserves similar scrutiny and due diligence.
“Too often we see organisations accepting what they’ve been told about a partner’s cyber security posture at face value, only to find out – typically when it’s too late – that the picture was inaccurate”.
Indicative budgets and hosting contractual frameworks are also often silent on cybersecurity measures and risks. Hosting agreements and key supplier contracts should clearly allocate roles and responsibilities, apportion liability and define minimum security standards. In an ideal world, these agreements should also be flexible enough for cybersecurity obligations to evolve as the event develops. This will save headaches in the long run.
As operations progress during the planning phase, organisers should dedicate time to thinking like a cyber criminal and understanding where cyber risk sits within the event ecosystem. Often the greatest vulnerabilities will sit within incumbent suppliers or systems operated by venues, host cities and other key stakeholders. Without proactive planning, auditing and upgrading these systems can be challenging for event organisers.
“In an ideal world, you’d have a comprehensive set of security standards that relevant stakeholders adhered to, well ahead of time. But the reality is different. The key is to establish the minimum requirements quickly and make them a non-negotiable, whether this is specific security controls like multi-factor authentication, incident response capabilities or compliance with ISO/IEC 27001. The focus should be on measures that have the most risk mitigation impact and can be implemented in a short space of time.”
In the final planning stages and during delivery, the focus should turn to incident response. Readiness exercises should test the coordinated responses of stakeholders such as local delivery teams, national cyber agencies, police, insurers, venues and suppliers. Decision-making protocols and escalation processes will need to be crystal clear and legal/comms teams should know their role inside out and be prepared to act quickly under pressure.
“Bringing together all relevant stakeholders and running simulations of common cyber attacks is an extremely effective way of improving readiness. You can’t afford to be making uncoordinated decisions mid-event.”
Cyber insurance should also form part of an event’s resilience strategy. More so than any other insured risk, event owners should treat their cyber insurers as a key partner. They should understand not only the scope of cover, but also the quality of incident response support that accompanies it. During a live cyber incident, those services can prove just as valuable as the policy itself.
For decades, major sports events have rightly invested enormous time and resources in physical security. As events become more dependent on complex digital infrastructure and malicious actors become more varied and sophisticated, it is necessary to view cyber resilience through the same lens.
If you would like to discuss any of the issues raised in this article, please contact Leon Farr at Onside Law or Casey O’Brien at S-RM.