← All posts

They Can Still Take Your Order. They Just Can't Ship It.

Boston Scientific detected an intrusion on August 25 and filed an 8-K the next day. A week later, the company still could not tell anyone when it would be back.

The disruption hit manufacturing, order processing, and shipping. In Ireland, where the company employs roughly 7,000 people across three sites, day-shift workers at the Model Farm Road plant in Cork were sent home at two in the afternoon. Friday shifts were cancelled outright. The company brought in CrowdStrike and other outside specialists. As of August 31, it had found no sign of malicious activity on its networks since the day it was detected, and the damage appeared limited to on-premises systems rather than cloud ones.

One detail from the company's own updates deserves a longer look than it has gotten. Boston Scientific said it can still accept orders electronically and place them in a queue for future fulfillment.

Read that again. The company can take your money. It cannot give you the product.

The Gap Between Selling and Delivering

Most boards think about a cyber incident as a data problem. Whose records were taken, how many, what do we have to disclose, what will the plaintiffs' firms do. That framing has been out of date for a while now, and this incident is a clean illustration of why.

Nothing here turns on stolen records. Boston Scientific has not said whether any data was taken. What it has said is that a company treating roughly 48 million patients a year, by its own count, spent a week unable to reliably manufacture and ship the devices those patients need. Cardiac rhythm devices already implanted kept working. But new remote-monitoring communicators could not be activated, meaning newly implanted devices would not transmit data to the remote monitoring system until pairing became possible.

That is not an IT outage. That is the business, stopped.

The order queue makes the point sharper than any breach notification could. Revenue recognition, customer commitments, hospital surgical schedules, and the working assumption that a purchase order becomes a delivered product — all of it sat in a queue while the systems came back.

The Question the 8-K Doesn't Answer

Boston Scientific told the SEC it had not yet determined whether the incident is reasonably likely to have a material impact. That is a defensible position on day two. It is a harder position on day thirty.

We have a recent comparison. In March, Stryker was hit by an attack that disrupted manufacturing, ordering, and shipping. The company later confirmed a material impact on first-quarter results while maintaining full-year guidance. By late July, its CEO was still describing a backlog the company was working through. Boston Scientific is roughly a week into an incident with the same operational shape.

Boston Scientific is not an outlier in its industry. Over the past year, Stryker, Intuitive, Medtronic, Abbott, iRhythm, AdaptHealth, Cook Medical, Baylor Genetics, and UFP Technologies have each disclosed a cyber incident. Most did not lose operations. Two lost the ability to make and ship product. Those two are the ones whose shareholders felt it.

If your board has been treating the SEC's materiality rules as a disclosure exercise handled by counsel, that industry pattern is your warning. Materiality is not determined by how much data left the building. It is determined by how long you cannot do the thing customers pay you to do.

The Three Questions, Applied to Operations

In Cyber Risk Is Business Risk I argue that a board's job is not to audit controls. It is to ask three questions and insist on real answers. Here is what they look like when you point them at operational resilience rather than at data.

What are we protecting? Not "our data." The specific systems that convert an order into a shipped product. Most executives cannot name them. Their manufacturing and logistics leaders can, in about ninety seconds, and nobody has ever asked.

What happens if we lose it? Not a recovery-time objective in a document. A tested number. Boston Scientific has been down a week with no announced restoration date, which suggests the recovery plan and the recovery reality were not the same document.

Who decides? When a plant goes dark and shifts get cancelled, somebody is choosing which systems come back first. Boston Scientific said it is directing resources toward the systems with the greatest impact on customers and product delivery. That is the right call — and it is a business decision, not a technical one. If your CISO is making it alone at two in the morning, your governance failed before the attack started.

What to Ask Your CISO This Week

Four questions. Ask them in this order, and do not accept a slide deck as an answer.

First: if our on-premises systems went dark tomorrow and the cloud stayed up, what could we still do? Boston Scientific's incident was reportedly confined to on-premises systems, and it still stopped manufacturing. A cloud-first strategy is not a resilience strategy if the factory floor runs on the other side.

Second: can we still take orders we cannot fill, and for how long is that acceptable? There is a real answer with a real date attached, and finance and legal both need to be in the room when it gets set.

Third: when did we last test a full restoration — not a tabletop, an actual restore — of the systems that move product? If the answer is longer than a year, or if the test was scoped to a subset, you have an untested plan.

Fourth: what is our public position on day thirty if we still are not restored? Boston Scientific has had to update the market repeatedly with no timeline. Every one of those updates was a decision someone made under pressure. Make those decisions now, in a quiet room.

The Uncomfortable Part

There is no villain in this story yet. No group has claimed the attack. There is no ransom note in the public record, no named nation-state, no obvious moral. Just a very large, very well-resourced company that could not ship product for a week.

That absence is the lesson. Boards spend enormous energy on threat actors — who they are, what they want, whether we are a target. It is the wrong axis. The question that determines whether an incident becomes a material event is not who attacked you. It is how much of your business runs through systems you cannot operate without, and how fast you can get them back.

Boston Scientific will recover. The queue will clear. But somewhere in that company, an executive is learning what the recovery time actually is, as opposed to what the plan said it would be.

You can learn that number the same way. Or you can ask for it on a Tuesday, with the lights on.