Type Insight: Case study

Legacy Assessments Won’t Prepare You for Modern Ransomware—Here’s Why

Most organizations don’t find out their backup strategy doesn’t work until it’s too late. On the surface, everything seems covered: backups are running, retention policies are in place, recovery plans have been tabletop tested, and someone did an assessment six months ago that said everything looked “adequate.” Maybe even “mature.” But when ransomware hits, those […]

Written by on Apr 10, 2025

Insurers Assess Cyber Risk Every Day. But How Well Are They Managing Their Own?

Property and casualty insurers sit in one of the most unusual positions in cybersecurity. They evaluate risk for a living. They set security requirements as conditions of coverage, and they know better than most what a breach costs. When it comes to their own cyber defenses, however, critical gaps remain. That’s the central finding of […]

Written by on Apr 2, 2026

Look to Security Controls—Not End Users—to Mitigate Risk

Cybersecurity professionals commonly blame the end user for being the top area of risk in securing the organization. In many ways, this is understandable. Systems and software are in our control; but end users are unpredictable. They expand our threat surface to each geographically dispersed user, personal device, and their potential for making errors that impact our security.

Written by on Apr 4, 2023

It’s World Backup Day. Could You Recover If You Had To?

World Backup Day is a well-meaning nudge. It’s a chance to pause, check your backups, and make sure your data is protected. It can be a good reminder to verify that you’ve got the essentials in place. But in our line of work, we’ve unfortunately seen how easily organizations can be lulled into a false […]

Written by on Mar 31, 2025

Post-Mythos Preview: AI-Accelerated Offense and the Recoverability Problem

Anthropic announced Mythos Preview on April 7, then said they wouldn’t release it. The model found thousands of previously unknown vulnerabilities, built working exploit chains without human help, and surfaced bugs that had survived 27 years of manual review in OpenBSD. You already know this. Your inbox has been full of it for weeks. Everyone […]

Written by on Jun 1, 2026

Why Does Recoverability Still Lag Behind Detection in Most Security Programs?

Many ransomware recovery efforts start the same way. Someone pulls up a disaster recovery plan. Someone else calls the backup vendor. And then the plan, which was likely designed with natural disasters or accidental deletion in mind, meets reality and falls apart. The gaps in recovery readiness are remarkably, stubbornly consistent across organizations, even ones […]

Written by on Jun 1, 2026