Tag

Incident Response

Explores the strategies, frameworks, and best practices organizations use to detect, contain, and recover from cybersecurity incidents. Articles cover team roles, communication protocols, forensic analysis, and lessons learned from real-world security breaches.

posts

Ransomware

What Is Ransomware? A Security Pro's Real-World Guide

A Single Click Cost One Hospital Chain $100 Million In 2020, Universal Health Services — a Fortune 500 hospital operator — got hit by the Ryuk ransomware strain. The result: 400 facilities knocked offline, staff reverting to pen and paper, and an estimated $67 million in direct costs plus ongoing damages that

Carl B. Johnson Aug 15, 2026 5 min read
Data Breach Response Plan

Data Breach Response Plan: Build One Before You Need It

The Breach That Proved Most Plans Are Fiction When Uber disclosed in 2022 that it had concealed a 2016 breach affecting 57 million users — and that its former CSO had been convicted of federal obstruction charges for the cover-up — it exposed something uglier than the breach itself. The company had

Carl B. Johnson Aug 14, 2026 5 min read
Data Breach Notification

Data Breach Notification Requirements: A 2026 Guide

In February 2024, Change Healthcare suffered a ransomware attack that exposed the protected health information of roughly 100 million Americans. The fallout wasn't just technical — it was a regulatory nightmare. State attorneys general demanded answers. Congressional hearings followed. And organizations downstream from the breach scrambled to figure out

Carl B. Johnson Aug 12, 2026 6 min read
Data Breach Notification Requirements

Data Breach Notification Requirements: What You Owe

23andMe Proved That Getting Breached Is Bad — But Notifying Wrong Is Worse In late 2023, 23andMe disclosed a breach affecting nearly 7 million users. The breach itself was devastating. But the company's notification missteps — delayed disclosures, shifting blame to users, and inconsistent communications across jurisdictions — turned a security

Carl B. Johnson Aug 11, 2026 6 min read
Ransomware

What Is Ransomware? A Security Pro's Real-World Guide

A Hospital Goes Dark in 90 Seconds In 2024, Change Healthcare — one of the largest health payment processors in the United States — was hit by the ALPHV/BlackCat ransomware group. The attack disrupted pharmacy operations, delayed patient care, and exposed the protected health information of roughly 100 million individuals. UnitedHealth

Carl B. Johnson Jul 16, 2026 5 min read
Ransomware Prevention

How to Prevent Ransomware: A Practical Defense Guide

A Single Click Cost One Hospital Chain $100 Million In 2024, Change Healthcare — one of the largest health payment processors in the U.S. — got hit with a ransomware attack that disrupted pharmacy operations across the entire country. UnitedHealth Group, its parent company, reported costs exceeding $870 million related to

Carl B. Johnson Jul 16, 2026 5 min read
Incident Response

How to Respond to a Cyberattack: A Step-by-Step Plan

In 2023, MGM Resorts lost an estimated $100 million after a social engineering attack that started with a single phone call to their help desk. The threat actor impersonated an employee, gained access to internal systems, and deployed ransomware across the enterprise. The entire operation took roughly 10 minutes to

Carl B. Johnson Jul 11, 2026 5 min read
Data Breach Response Plan

Data Breach Response Plan: Build One Before You Need It

The Breach That Exposed 147 Million People — And a Broken Response When Equifax disclosed its 2017 breach, the technical failure got the headlines. But the real catastrophe was the response. Weeks of delay, a phishing-prone notification website, and executives who dumped stock before the public announcement. The company eventually paid

Carl B. Johnson Jul 09, 2026 5 min read
Data Breach Notification Requirements

Data Breach Notification Requirements: A 2026 Guide

In February 2024, Change Healthcare suffered a ransomware attack that exposed the protected health information of approximately 100 million Americans. The fallout wasn't just technical — it was regulatory. Congressional hearings, state attorney general investigations, and an avalanche of class-action lawsuits followed, largely because stakeholders questioned whether data breach

Carl B. Johnson Jun 27, 2026 6 min read