Breach Autopsy: EY Shows Support Tickets Are a Data Store EY's support-system breach shows why ticketing platforms are data stores, not operational exhaust.
Breach Autopsy: Abbott Shows Legacy Healthcare Systems Carry Their Own Blast Radius Abbott's two-incident investigation shows why healthcare breach scope depends on legacy systems, portals, and inherited data boundaries.
The Docket: The UK's Cyber Resilience Bill Is Not Just NIS2 in a Different Accent The UK's Cyber Security and Resilience Bill matters because it appears to widen the cyber risk perimeter beyond obvious critical infrastructure operators.
Breach Autopsy: Change Healthcare and the $22M Ransom That Broke US Pharmacies When a single ransomware attack on a healthcare clearinghouse disrupts prescriptions nationwide, the third-party risk math changes.
Breach Autopsy: European Commission's Amazon Cloud Account Compromise Exposes Third-Party Infrastructure Risk The European Commission is investigating a breach after an Amazon cloud account was compromised. Government agencies running on vendor infrastructure face unique disclosure complexities.
Breach Autopsy: Balance Autism and the Hidden Cost of Vendor Email Compromises When a vendor's compromised email becomes your class action lawsuit - Balance Autism's settlement shows why vendor access control is a legal liability, not just a security one.
The Docket: When Your Analytics Tool Leaks Everyone's Analytics Google Looker Studio had nine cross-tenant vulnerabilities that could let attackers run SQL on your databases. Tenable found them. Here's what that means legally.