Incident Response

Breach response lessons, IR program maturity, and post-incident analysis.

The Breach Nobody Was Warned About, Twice

Ceva Logistics suffered a ransomware attack in September 2025 that it never disclosed. Ten months later, on July 29, 2026, it happened again, this time much bigger, and a former employee's lawsuit says the first attack should have been the wake-up call that prevented the second.

117 Rules for the Same Bad Day

The Government Accountability Office counted the cybersecurity regulations sitting on top of American companies: 117 of them, across 37 federal agencies. The finding that deserves board attention is the overlap.

The Ransomware Ran Itself

In a ransomware attack, your security team's one reliable advantage is time. The intruder breaks in, then works for hours, sometimes days or weeks, looking around, moving sideways, hunting for what matters, and somewhere in that window your monitoring is supposed to catch them. A report published July 1 shows that window closing.

The Attack That Hasn't Happened Yet

The head of ASIO, Australia's domestic intelligence agency, used his annual threat assessment this month to describe a kind of breach that should change how you read the word. A foreign government's hackers had been inside an Australian critical infrastructure provider for months. They had not stolen data or sent a ransom note. They had taken the login credentials of the network's active users, including the IT staff guarding it, mapped the entire system, and quietly held on to their access. The purpose, ASIO concluded, was sabotage: "mapping out the network and maintaining access so they could cripple it at a time of their choosing."

You Will Be Sued Before Your Forensic Report Is Finished

On April 1, the ShinyHunters extortion group social-engineered a Charter Communications employee into handing over their Microsoft Entra (formerly Azure Active Directory) credentials through a voice phishing call. From that single set of credentials, the attacker pivoted into Charter's Salesforce CRM (customer relationship management system) and extracted customer and employee records before Charter detected the intrusion.

Regulators Are Clocking the Delay, Not the Incident

Delta Dental Insurance Company and Delta Dental of New York paid New York's financial regulator $2.25 million last month for a cybersecurity incident. The incident itself was modest. The penalty was driven by a six-month delay in notification. New York's rules require notification of a covered cybersecurity event within 72 hours. Delta Dental detected a webshell in June 2023 and did not notify the regulator until December 2023. The consent order makes the timing the central finding.

A Breach Three Years Ago Just Cost $117.5 Million

Comcast agreed this week to pay $117.5 million to settle a class action over a 2023 data breach that exposed approximately 36 million Xfinity customer records. Individual payouts reach up to $10,000 for documented out-of-pocket losses. The breach happened three years ago. The settlement landed this week. But don't let the timeline mislead you. Class actions now file within days of a disclosure, not months. The litigation machinery is automated. Plaintiff firms monitor SEC (Securities and Exchange Commission) filings and breach notifications in real time. The moment you disclose, the clock starts.

316,000 Companies Are About to Get a Reporting Clock

CISA's (the federal cybersecurity agency) Cyber Incident Reporting for Critical Infrastructure Act has been law since 2022. The implementing rule, the one that actually triggers compliance obligations, is expected any week. When it lands, approximately 316,000 entities across sixteen critical infrastructure sectors will have seventy-two hours to report covered cyber incidents to CISA. Twenty-four hours if they make a ransom payment. A covered incident is anything that substantially disrupts your operations, compromises your systems, or arrives through a compromised vendor. Non-reporters face DOJ (Department of Justice) referral, contempt proceedings, and suspension from government contracting.

CISA, FBI, and the Lawyers All Came for Stryker This Week

Last week we covered Handala's wiper attack on Stryker Corporation, the medical device manufacturer that initially reported 200,000 systems destroyed across 79 countries. This week, three separate forces closed in on the company at once.