Organisations worldwide are increasingly facing cybersecurity threats capable of causing significant operational disruption. Recently, organisations have been targeted with “sleeping malware,” a dormant, or “sleeping,” implant embedded in an organisation’s systems that remains there undetected, sometimes for long periods of time, before an activation date or external trigger “awakens” it, causing a cyber incident.