Tag

Incident Response

Explores the strategies, frameworks, and best practices organizations use to detect, contain, and recover from cybersecurity incidents. Articles cover team roles, communication protocols, forensic analysis, and lessons learned from real-world security breaches.

posts

Ransomware Protection

Ransomware Protection Tips That Actually Work in 2025

The Breach That Changed a Hospital System Overnight In February 2024, Change Healthcare — a subsidiary of UnitedHealth Group — was hit by a ransomware attack that disrupted prescription processing and claims payments for weeks across the U.S. healthcare system. UnitedHealth's CEO later confirmed the company paid a $22

Carl B. Johnson Jul 15, 2025 7 min read
Data Breach Response Plan

Data Breach Response Plan: What Actually Works in 2025

In May 2023, MOVEit Transfer suffered a mass exploitation that ultimately affected over 2,700 organizations and exposed data on roughly 95 million individuals. Some of those organizations had a tested data breach response plan ready to execute. Most didn't. The difference between the two groups wasn'

Carl B. Johnson Jul 15, 2025 7 min read
Data Breach Reporting

How to Report a Data Breach: A Step-by-Step Guide

In February 2024, Change Healthcare suffered a ransomware attack that exposed the protected health information of approximately 190 million people — making it the largest healthcare data breach in U.S. history. The fallout wasn't just the breach itself. It was the weeks of confusion about who had been

Carl B. Johnson Jul 15, 2025 8 min read
Data Breach Notification Requirements

Data Breach Notification Requirements: A 2025 Guide

In May 2023, T-Mobile agreed to a $350 million settlement after a data breach exposed the personal information of roughly 76 million people. A significant chunk of that cost wasn't the breach itself — it was the fallout from notification failures, regulatory scrutiny, and class-action lawsuits that followed. If

Carl B. Johnson Jun 15, 2025 8 min read
Incident Response Plan Template

Incident Response Plan Template: Build Yours in 2025

The Breach That Didn't Have to Be a Disaster In early 2024, Change Healthcare suffered a ransomware attack that disrupted pharmacy operations and claims processing across the entire U.S. healthcare system for weeks. UnitedHealth Group eventually disclosed that the breach affected roughly 100 million individuals — the largest

Carl B. Johnson Jun 14, 2025 7 min read
Incident Response

How to Respond to a Cyberattack: A Step-by-Step Guide

In May 2023, the City of Dallas got hit with Royal ransomware. Police dispatch systems went down. Court services froze. Municipal operations ground to a halt for weeks. The city ultimately spent over $8.5 million on recovery. And here's the part that stings: Dallas had cybersecurity staff

Carl B. Johnson Jun 14, 2025 7 min read
Incident Response

Cyber Incident Response Steps: A Practical 2025 Guide

The Breach That Took 277 Days to Find IBM's 2024 Cost of a Data Breach Report found the global average cost of a breach hit $4.88 million — and organizations that took longer than 200 days to identify and contain a breach paid significantly more. The average lifecycle?

Carl B. Johnson Jun 14, 2025 8 min read
Cybersecurity Incident Examples

Cybersecurity Incident Examples That Changed Everything

The Breach That Cost Change Healthcare $22 Million in Ransom In February 2024, the ransomware group ALPHV/BlackCat crippled Change Healthcare — a company that processes roughly one-third of all U.S. healthcare claims. The attack disrupted pharmacies, hospitals, and billing systems nationwide for weeks. UnitedHealth Group, Change Healthcare's

Carl B. Johnson Jun 14, 2025 7 min read
Cyber Incident Reporting

How to Report a Cyber Incident: A Step-by-Step Guide

The Breach That Nobody Reported for 72 Days In 2023, the SEC charged SolarWinds' CISO with fraud partly because the company allegedly downplayed the severity of a cyber incident and failed to disclose material risks. That case sent shockwaves through every boardroom in America. It proved something I'

Carl B. Johnson Jun 14, 2025 7 min read
Living Off the Land Attacks

When Attackers Removed Legitimate Software to Hide

In February 2024, the Cybersecurity and Infrastructure Security Agency (CISA) issued an advisory about threat actors linked to Volt Typhoon — a Chinese state-sponsored group that had been living inside U.S. critical infrastructure networks for years. One of their signature moves? They removed legitimate security tools and logging mechanisms from

Carl B. Johnson Aug 19, 2024 7 min read