Recent issues
Jul 15, 2026Anatomy of a ransomware attack: the six stages from first login to ransom note
Most incidents follow the same arc — initial access, foothold, escalation, lateral movement, exfiltration, detonation. Knowing the arc tells you where you can still win.Jul 5, 2026Ransomware-as-a-service: why the affiliate model makes attacks relentless
The economics behind modern ransomware — and what the division of labor between operators, affiliates, and access brokers means for defenders.Jul 3, 2026The identity attack surface: how initial access brokers get in
Valid accounts, not zero-days, open most enterprise doors. Where initial access brokers find them — and where to look first.Jul 1, 2026The double-extortion playbook has changed — here's what's new
Exfiltration-first attacks now precede encryption in most enterprise cases, which changes both your detection strategy and your negotiation calculus.Jun 24, 2026Threat profile: the groups targeting mid-market manufacturing
Who they are, how they get in, and the controls that stop them — for the segment sitting in ransomware's blind spot between resources and exposure.Jun 12, 2026Why ransomware groups keep 'shutting down' — and coming back
Takedowns and retirements make headlines, but the people, tooling, and affiliates persist. What the rebrand cycle means for how you plan defenses.Jun 10, 2026Backups aren't recovery: the restore gap that sinks response plans
Why “we have backups” and “we can recover” are very different claims — and how the gap between them turns a bad week into a bad quarter.Jul 8, 2026Phishing-resistant MFA: why passkeys and FIDO2 beat the MFA you have
Push-approval and SMS codes stopped the attacks of 2018, not the attacks of 2026. What changed, and how to move the accounts that matter to hardware-backed auth.Jul 6, 2026Network segmentation: the control that decides your blast radius
Segmentation rarely stops the initial breach — but it's the single biggest factor in whether one compromised laptop becomes a company-wide outage.Jul 2, 2026EDR isn't a silver bullet: the ransomware detection gaps it leaves open
Endpoint detection is essential and oversold. Here are the blind spots attackers exploit around it — and what to pair it with so detection fires before encryption.Jun 28, 2026Immutable backups and the 3-2-1-1-0 rule for the ransomware era
The classic 3-2-1 backup rule predates attackers who hunt and delete your backups first. The updated rule — and what 'immutable' actually has to mean.Jun 20, 2026Active Directory is the prize: hardening the identity tier attackers target
Domain admin turns one compromised laptop into every machine you own. Why AD is the center of gravity in enterprise ransomware — and the tiering model that protects it.Jun 16, 2026Patch what faces the internet first: prioritizing the edge attackers actually hit
You can't patch everything at once, and you don't have to. A risk-based approach that closes the internet-facing edge devices ransomware crews exploit for initial access.Jun 27, 2026To pay or not to pay: build the ransom decision framework before you need it
The ransom decision is a board-level call made under extreme pressure. Pre-decide the inputs, the people, and the legal constraints now — not at 2am mid-incident.Jun 20, 2026Run the tabletop before the attacker does
How to design ransomware exercises that surface real gaps instead of confirming the plan you already wrote. A tabletop everyone passes taught you nothing.Jul 11, 2026The first 24 hours: what to do in the moment everything is on fire
A calm, ordered sequence for the worst day — what to touch, what not to touch, and who to call, so the first hours preserve your options instead of destroying them.Jul 4, 2026Inside a ransomware negotiation: what actually happens if you engage
Whether or not you intend to pay, someone may need to talk to the attacker. What the process looks like, why professionals run it, and what it can and can't achieve.Jun 30, 2026Crisis communications: what to say when you're breached (and what not to)
The technical response and the communications response run in parallel, and the second one shapes how the incident is remembered. A framework for saying the true thing carefully.Jun 22, 2026Recovery sequencing: the restore order that gets you back safely
Having clean backups is half the battle; restoring in the wrong order — or into an environment the attacker still controls — turns recovery into re-infection.Jun 17, 2026DORA & ransomware: what EU financial firms must prove now
Resilience testing and incident-reporting obligations, in plain English — and why for most firms the gap isn't strategy, it's evidence.Jun 13, 2026When your vendor gets hit: managing third-party ransomware exposure
Your resilience is capped by your least-prepared critical supplier. The two shapes third-party risk takes — and how to map the dependency before it maps you.Jul 9, 2026Cyber insurance and ransomware: what's actually covered (and what voids it)
Policies pay far less often than buyers assume, and the reasons are usually in the fine print you agreed to. What ransomware coverage really includes — and the control requirements that quietly gate it.Jul 7, 2026Reporting ransomware risk to the board: metrics that survive scrutiny
Boards don't want a threat briefing; they want to know if the organization would survive, how exposed it is in money terms, and whether the investment is working. The metrics that answer those questions.Jun 25, 2026Ransomware reporting obligations: who you have to tell, and how fast
A ransomware incident can trigger overlapping notification duties to regulators, customers, and authorities on short clocks. Map them before the clock starts, not after.
Most incidents follow the same arc — initial access, foothold, escalation, lateral movement, exfiltration, detonation. Knowing the arc tells you where you can still win.Jul 5, 2026Ransomware-as-a-service: why the affiliate model makes attacks relentless
The economics behind modern ransomware — and what the division of labor between operators, affiliates, and access brokers means for defenders.Jul 3, 2026The identity attack surface: how initial access brokers get in
Valid accounts, not zero-days, open most enterprise doors. Where initial access brokers find them — and where to look first.Jul 1, 2026The double-extortion playbook has changed — here's what's new
Exfiltration-first attacks now precede encryption in most enterprise cases, which changes both your detection strategy and your negotiation calculus.Jun 24, 2026Threat profile: the groups targeting mid-market manufacturing
Who they are, how they get in, and the controls that stop them — for the segment sitting in ransomware's blind spot between resources and exposure.Jun 12, 2026Why ransomware groups keep 'shutting down' — and coming back
Takedowns and retirements make headlines, but the people, tooling, and affiliates persist. What the rebrand cycle means for how you plan defenses.Jun 10, 2026Backups aren't recovery: the restore gap that sinks response plans
Why “we have backups” and “we can recover” are very different claims — and how the gap between them turns a bad week into a bad quarter.Jul 8, 2026Phishing-resistant MFA: why passkeys and FIDO2 beat the MFA you have
Push-approval and SMS codes stopped the attacks of 2018, not the attacks of 2026. What changed, and how to move the accounts that matter to hardware-backed auth.Jul 6, 2026Network segmentation: the control that decides your blast radius
Segmentation rarely stops the initial breach — but it's the single biggest factor in whether one compromised laptop becomes a company-wide outage.Jul 2, 2026EDR isn't a silver bullet: the ransomware detection gaps it leaves open
Endpoint detection is essential and oversold. Here are the blind spots attackers exploit around it — and what to pair it with so detection fires before encryption.Jun 28, 2026Immutable backups and the 3-2-1-1-0 rule for the ransomware era
The classic 3-2-1 backup rule predates attackers who hunt and delete your backups first. The updated rule — and what 'immutable' actually has to mean.Jun 20, 2026Active Directory is the prize: hardening the identity tier attackers target
Domain admin turns one compromised laptop into every machine you own. Why AD is the center of gravity in enterprise ransomware — and the tiering model that protects it.Jun 16, 2026Patch what faces the internet first: prioritizing the edge attackers actually hit
You can't patch everything at once, and you don't have to. A risk-based approach that closes the internet-facing edge devices ransomware crews exploit for initial access.Jun 27, 2026To pay or not to pay: build the ransom decision framework before you need it
The ransom decision is a board-level call made under extreme pressure. Pre-decide the inputs, the people, and the legal constraints now — not at 2am mid-incident.Jun 20, 2026Run the tabletop before the attacker does
How to design ransomware exercises that surface real gaps instead of confirming the plan you already wrote. A tabletop everyone passes taught you nothing.Jul 11, 2026The first 24 hours: what to do in the moment everything is on fire
A calm, ordered sequence for the worst day — what to touch, what not to touch, and who to call, so the first hours preserve your options instead of destroying them.Jul 4, 2026Inside a ransomware negotiation: what actually happens if you engage
Whether or not you intend to pay, someone may need to talk to the attacker. What the process looks like, why professionals run it, and what it can and can't achieve.Jun 30, 2026Crisis communications: what to say when you're breached (and what not to)
The technical response and the communications response run in parallel, and the second one shapes how the incident is remembered. A framework for saying the true thing carefully.Jun 22, 2026Recovery sequencing: the restore order that gets you back safely
Having clean backups is half the battle; restoring in the wrong order — or into an environment the attacker still controls — turns recovery into re-infection.Jun 17, 2026DORA & ransomware: what EU financial firms must prove now
Resilience testing and incident-reporting obligations, in plain English — and why for most firms the gap isn't strategy, it's evidence.Jun 13, 2026When your vendor gets hit: managing third-party ransomware exposure
Your resilience is capped by your least-prepared critical supplier. The two shapes third-party risk takes — and how to map the dependency before it maps you.Jul 9, 2026Cyber insurance and ransomware: what's actually covered (and what voids it)
Policies pay far less often than buyers assume, and the reasons are usually in the fine print you agreed to. What ransomware coverage really includes — and the control requirements that quietly gate it.Jul 7, 2026Reporting ransomware risk to the board: metrics that survive scrutiny
Boards don't want a threat briefing; they want to know if the organization would survive, how exposed it is in money terms, and whether the investment is working. The metrics that answer those questions.Jun 25, 2026Ransomware reporting obligations: who you have to tell, and how fast
A ransomware incident can trigger overlapping notification duties to regulators, customers, and authorities on short clocks. Map them before the clock starts, not after.