Tag

Ransomware Recovery

Guides organizations through recovering from ransomware attacks, covering backup restoration, system rebuilding, decryption options, and negotiation considerations. Articles also address preventive measures and how to reduce downtime during a ransomware event.

posts

Cyber Incident Response Steps

Cyber Incident Response Steps That Actually Work

The Breach That Exposed a Missing Playbook In 2023, MGM Resorts lost an estimated $100 million after a social engineering attack gave threat actors access to critical systems. The attackers called the help desk, impersonated an employee, and got in. What made the damage so severe wasn't just

Carl B. Johnson May 14, 2026 5 min read
Ransomware Recovery

Ransomware Recovery Steps: A Battle-Tested Playbook

The Clock Starts the Moment You See the Ransom Note In February 2024, Change Healthcare — one of the largest health payment processors in the United States — was hit by the ALPHV/BlackCat ransomware group. The attack disrupted pharmacy operations, delayed insurance claims, and affected an estimated one-third of all Americans&

Carl B. Johnson Apr 14, 2026 5 min read
Incident Response

Cyber Incident Response Steps: A Practical 2025 Guide

The Breach That Took 277 Days to Find IBM's 2024 Cost of a Data Breach Report found the global average cost of a breach hit $4.88 million — and organizations that took longer than 200 days to identify and contain a breach paid significantly more. The average lifecycle?

Carl B. Johnson Jun 14, 2025 8 min read
Ransomware Recovery

Ransomware Recovery Steps: A Battle-Tested Playbook

The Phone Call No One Wants to Get at 3 AM I got the call on a Tuesday morning. A mid-sized logistics company had every file server locked with a .lockbit extension. Their dispatchers couldn't route a single truck. Their accounting team was staring at ransom notes instead

Carl B. Johnson Feb 09, 2024 7 min read
Incident Response

Cyber Incident Response Steps: A Practical Playbook

The 37 Minutes That Cost MGM Resorts $100 Million In September 2023, a threat actor called Scattered Spider social-engineered an MGM Resorts help desk employee. Within 37 minutes, they had enough access to cripple one of the world's largest casino and hotel operators. Slot machines went dark. Hotel

Carl B. Johnson Dec 11, 2023 7 min read
Ransomware Recovery

Ransomware Recovery Steps: A Practical Guide for 2022

Colonial Pipeline Taught Us What Happens Without a Plan In May 2021, Colonial Pipeline paid $4.4 million in ransom after a single compromised password shut down fuel delivery across the Eastern United States. The company had backups. They had resources. They still paid — because their ransomware recovery steps weren&

Carl B. Johnson Mar 18, 2022 7 min read
Ransomware Recovery

Ransomware Recovery Steps: A Practical Playbook

The Colonial Pipeline Wasn't the Wake-Up Call — Your Last Backup Test Was In February 2021, the Cybersecurity and Infrastructure Security Agency (CISA) issued renewed guidance on ransomware after a string of attacks against hospitals, schools, and local governments. The FBI's Internet Crime Complaint Center reported that

Carl B. Johnson Mar 12, 2021 7 min read
Cybersecurity Incident Response

Cybersecurity Incident Response: A Battle-Tested Guide

In July 2020, Twitter lost control of 130 high-profile accounts — including those of Barack Obama, Elon Musk, and Apple — in a social engineering attack that bypassed every technical control the company had. The attackers didn't use a zero-day exploit. They manipulated employees. And Twitter's cybersecurity incident

Carl B. Johnson Dec 20, 2020 7 min read