What we do
Assessing risk and resilience
Securing the digital transformation
Establishing crisis response and preparedness
Building long-term cyber capabilities
Examples of our work
Uncovering weaknesses in a global bank’s cybersecurity approach
The McKinsey team conducted interviews with roles across the organization; reviewed policies, procedures and other technical documents; and created 60 technical validation test plans to optimize testing efficiency.
Based on the results, we were able to identify 80+ capability and strategy gaps that the bank used to create a road map for a complete cyber transformation.
Helping an oil and gas company with its cybersecurity maturity transformation
We supported a Latin American oil and gas client’s cybersecurity maturity journey across its operational technology (OT) and information technology (IT), defining the company’s value chain, establishing a process to identify the assets most in need of protection, and analyzing controls and costs.
An eight-week assessment produced a holistic transformation program focused on the greatest potential for risk reduction, which the company pursued to greatly advance its cybersecurity maturity.
Establishing cloud security for a major pharma company
We worked with a top five pharmaceutical company to secure its cloud adoption and centrally manage the associated risks.
The McKinsey team assessed the client’s cloud-security abilities, designed a multicloud architecture, and developed a cloud security operating model. By creating a cloud security framework and road map, we helped the pharmaceutical company transform its way of working and adopt an architectural vision for a multicloud future.
Responding to a tech company’s cyber crisis
When a technology services company was struck by a cyberattack, the incident left many customers without service and unearthed a number of critical security gaps across the organization. We worked with the client to develop an approach for customer outreach and coordination, designed and executed a rapid remediation program, and built a governance model for long-term cybersecurity.
The tech client was able to take a crisis that threatened to destabilize the organization and use the experience to make the company more agile and resilient.
Featured experts

Venky Anant
PartnerBay Area

Tucker Bailey
PartnerWashington DC

Ida Kristensen
Senior PartnerNew York

Jim Boehm
PartnerLondon

Jan Shelly Brown
PartnerNew Jersey

Justin Greis
PartnerChicago

Rich Isenberg
PartnerAtlanta

James Kaplan
PartnerNew York

Charlie Lewis
PartnerConnecticut – Darien

Patrick Aron Rinski
PartnerSão Paulo

Marc Sorel
PartnerBoston

David Ware
PartnerWashington DC

McKinsey was named a leader in The Forrester Wave™: Cybersecurity Consulting Services, Q2 2024
Featured Video
Making Cyber Risk a Strategic Priority
Featured insights
Quantum communication growth drivers: Cybersecurity and quantum computing
Tech resilience for healthcare providers: Inaction has a heavy toll
Europe’s next cybersecurity hub: What makes Spain a leading contender?
The cybersecurity provider’s next opportunity: Making AI safer
A board-level view of cyber resilience
Boards of directors: The final cybersecurity defense for industrials
The cyber clock is ticking: Derisking emerging technologies in financial services
New-business building: Six cybersecurity and digital beliefs that can create risk
Cracking the code on enhanced digital and cyber risk maturity
Making the case: How the mid-Atlantic region can become a leading cybersecurity hub
Product security: Navigating regulations and customer expectations
How to enhance the cybersecurity of operational technology environments
Managing a cyber risk event: ‘Be a student of a crisis’
Resiliency and leadership in uncertain times: An interview with Splunk’s CEO
New survey reveals $2 trillion market opportunity for cybersecurity technology and service providers
Building a cybersecurity culture from within: An interview with MongoDB
Perspectives on model risk management of cybersecurity solutions in banking
Localization of data privacy regulations creates competitive opportunities
Securing your organization by recruiting, hiring, and retaining cybersecurity talent to reduce cyberrisk
Cybersecurity legislation: Preparing for increased reporting and transparency
Cybersecurity trends: Looking over the horizon
Ransomware prevention: How organizations can fight back
The unsolved opportunities for cybersecurity providers
Cyber resilience: Protecting America’s digital infrastructure
Cyber Resilience
Organizational cyber maturity: A survey of industries
Security as code: The best (and maybe only) path to securing cloud applications and systems
Building cyber resilience in national critical infrastructure
Enterprise cybersecurity: Aligning third parties and supply chains
Cybersecurity in Iberia: Aligning business and the board
Securing small and medium-size enterprises: What’s next?
Strengthening the IT security posture in corporates and industrials
The Latin American energy sector: How to address cybersecurity
Derisking digital and analytics transformations
Cybersecurity: Emerging challenges and solutions for the boards of financial-services companies
How CIOs and CTOs can accelerate digital transformations through cloud platforms
Three actions CEOs can take to get value from cloud computing
COVID-19 crisis shifts cybersecurity priorities and budgets
A dual cybersecurity mindset for the next normal
Safeguarding against cyberattack in an increasingly digital world
Building security into the customer experience
Cybersecurity in a digital era
Even before the advent of a global pandemic, executive teams faced a challenging and dynamic environment as they sought to...