RSS Amplifier

Trade Credit & Liquidity Management · Aug 12, 2026

When the Cash Stops Before the Sirens

0
Sign in to vote or save

Trade Credit & Liquidity Management · Trade Credit & Liquidity Management

By Torsten Böhler

At 07:42 AM, the factory was still running. That was the strange part.

The machines turned. People sat at their desks. The coffee was hot, and the phones worked. If you had walked the floor that morning, you would have seen a company doing exactly what it does every day. What you would not have seen, unless you sat in finance, was that nothing the company earned that morning could be turned into cash. The billing system had been isolated overnight “as a precaution.” The order file was quarantined behind it. Sales were happening. Invoices were not.

And in the treasurer’s office, someone was staring at a question no one in the building could answer: How many days of liquidity do we actually have if billing does not come back online today?

Most cyber plans prepare for the lights going out; the dramatic shutdown, the ransom note, the press statement. But the business often keeps operating. It keeps making promises to customers and running up costs with suppliers. What it stops doing is converting work into cash. The attack does not take the company offline. It takes the order-to-cash cycle offline.

Follow the chain every credit and treasury team depends on — call it the order-to-cash kill chain: an operation becomes an invoice, an invoice becomes cash, cash becomes a forecast, and the forecast becomes the confidence with which everyone else makes decisions. Break any one of those links and the whole chain sags. Revenue is earned but never billed. Cash application stops. The collections queue freezes because no one can confirm what was actually paid. DSO climbs while no one is watching, because the dashboard still shows orders and shipments.

Here is the part that turns a disruption into a crisis. The money coming in stops, but the money going out does not. Payroll still runs, and employees get paid. Suppliers still invoice. Rent, interest, and tax do not pause for an incident. Inflows freeze while outflows keep their schedule — like a pair of scissors closing on your cash.

The arithmetic is unforgiving. A business doing €10 million a month on 45-day terms that cannot invoice for three weeks has roughly €7 million of cash simply not arriving — while its own payments run exactly on time. At first the damage hides inside healthy-looking dashboards. By the second week it stops being a number on a slide and becomes a payment you cannot make.

When Jaguar Land Rover (JLR) was hit in September 2025, the headline was five weeks of production stopped. The quieter story was the money. Numerous suppliers, many of them small companies, most of them owed, warned they faced up to six months of cash-flow difficulty. The strain was severe enough that the UK government backed a £1.2 billion (about $1.6 billion) loan, and JLR stood up a £500 million supplier-financing program to move cash to suppliers earlier than usual. It was the first time a company received state support specifically because of a cyberattack. But that program was a race, and not every small supplier could survive the wait to find out whether it reached them in time.

Change Healthcare made the same point from another angle. In early 2024, a clearinghouse most patients had never heard of went dark, and hospitals across the United States suddenly could not bill. At one point, roughly 60 percent of them were losing at least $1 million a day. The organization that was attacked was not the one that was bleeding cash. Everyone downstream was. If your receivables run through someone else’s system — a payment portal, a clearinghouse, an ERP you do not own — then their bad night becomes your liquidity problem. That is concentration risk, sitting in a vendor instead of a customer.

And when Marks & Spencer suspended online orders for the better part of seven weeks in 2025, the cost ran into hundreds of millions in lost sales and a heavy hit to operating profit. Only a fraction came back through insurance.

Here is the comfortable assumption worth puncturing. Many boards mistakenly believe the cyber policy is the liquidity plan. It is not. Business-interruption coverage is triggered in only about one-in-three ransomware claims. A meaningful share of cyber claims are denied outright, and even a valid claim pays on the insurer’s schedule, not yours, which is often months after the cash was needed. Insurance is a reimbursement. It is not working capital. Someone still has to fund the gap in between, and that someone is Treasury, on a Tuesday, with a payroll run due.

The ransom question sits in the same drawer. If paying is ever on the table (legally, ethically, practically), the first thing finance discovers is whether it can even move the money quickly, and whether anyone is authorized to decide. Those are not the type of questions to answer at two in the morning.

This is where it stops being an IT conversation. Regulators have made the timing unforgiving: a material incident now has to be disclosed within four business days of the moment it is judged material. A call that lands on the CFO and the general counsel, fast, and usually before the facts are clean. The temptation, under that pressure, is to project a confidence the numbers cannot support.

And confidence you cannot support is what tips a bad week into a forced one. Liquidity rarely dies from a single event; it dies from losing control of the sequence. First the bank asks for an updated forecast. Then it asks who else has seen it. A supplier who hears a rumor shortens terms to protect itself. The board, surprised twice in a fortnight, calls a special session, and the options that were open on Monday are gone by Friday. A cyberattack compresses that whole sequence into days.

The good news is that almost all of this can be settled in advance, when nobody is tired or under pressure. Name the systems that stand between an order and a dollar of collected cash, and the person who owns each one. Answer the treasurer’s question before it is ever asked in anger: How many days of liquidity do you have if collections stop tomorrow? Agree, before you need it, who may authorize a ransom decision, who speaks to the insurer, and how much covenant headroom you are really carrying.

Then test it properly. In the next tabletop exercise, do not ask finance to estimate a loss at the end. Give finance the Monday-morning job. Freeze the billing system. Delay a payment feed. Corrupt the sales interface. Then ask for the cash forecast, and watch what happens. The uncomfortable discoveries come quickly, and they are always the same kind: the report only one person can produce, the receivable you cannot finance without data you no longer have, the covenant test nobody had modelled under stress.

Because liquidity, under pressure, is not really your ability to pay. It is your right to choose — to decide early, negotiate from strength, and keep your options open while everyone else is still looking for certainty. A cyberattack is an attack on exactly that right.

The dashboard was green. The factory was running. And the most dangerous number in the building was not the one that was obviously broken. It was the cash position that still looked funded.

If you found this post useful, consider sharing it with your Credit Team.

Share

ACTION ITEMS

  1. Map your order-to-cash kill chain. List the systems that stand between a shipment and applied cash, and name an owner for each.

  2. Answer one number out loud: how many days of liquidity do we have if collections stop tomorrow? If nobody knows, that is the finding.

  3. Model the scissors. Alongside the inflows you would lose, list the outflows (payroll, suppliers, interest, tax) that would not pause. The gap between them is your real exposure.

  4. Pre-authorize the hard calls before you need them. Who may approve a ransom payment, who contacts the insurer, and what covenant headroom you carry.

  5. At your next cyber tabletop, ask finance for the cash forecast with a core system frozen, not a loss estimate at the end.

  • 20–25: Sequence-ready. You would keep control of the timeline while others lose it.

  • 12–19: Partial. You hold some of the pieces, but the gaps are exactly where the pressure will land.

  • 0–11: Exposed. An incident would become a liquidity crisis before finance had a number to stand on.

Where did you land, and which of the five is your biggest gap?

Share your score in the comments below.

Torsten Böhler is a senior operator and advisor with nearly two decades of international leadership across banking, capital markets, private equity, and SMEs. He is the author of Liquidity Under Pressure: The CFO’s Guide to Strategic Management and Decision Making Under Uncertainty.

Follow his insights on LinkedIn, visit www.holomastrik.ie, or email Torsten at torsten.boehler@boehlerglobal.com.

Credit On The Go

Cyber Risk Is a Liquidity Risk

·

Jul 31

In this episode of Credit on the Go, Torsten Boehler, Managing Director of Holomastrik, Ltd., sits down with TCLM’s Bob Shultz to share his view that cyber risk needs to be understood as a liquidity problem rather than a purely technical Issue. That shift is exactly why this podcast is worth your time. For financial executives, the discussion is especia…

No posts

Read the original on tradecredit.substack.com

Comments

Nothing yet. Say the first thing.

    Sign in to join the conversation.