#incident-response
39 stories taggedincident-response · page 2 of 3.

Your ransomware playbook is probably putting the wrong person in charge at 4 a.m.
A growing body of evidence shows that the real damage in ransomware incidents often comes not from the attack itself, but from who gets to decide whether to pull the plug on a business-critical system.

CISOs Are Now Running Business Resilience. Most Companies Haven't Noticed.
Security chiefs are quietly absorbing responsibility for keeping companies alive after a disaster, not just preventing one. Three experienced practitioners explain what that shift actually demands.

What is ransomware and how does an attack actually unfold?
Ransomware locks your files or systems until you pay criminals to restore access. Here is exactly how that happens, step by step.

Ransomware Attacks Rose 25% in a Year. Artificial Intelligence Isn't the Main Driver.
A new report tracked 7,551 victims worldwide between April 2025 and March 2026. The growth came from more criminal groups, weaker targets, and supply-chain shortcuts, not fancy AI tools.

Cyberattack Hits Nichirei, Japan's Frozen Food Giant, Putting Personal Data at Risk
A July 13 attack knocked out warehouses and shipping lines across Japan. Nichirei says personal information may have been stolen, and a regulator report has already been filed.

Your Incident Response Playbook Almost Certainly Does Not Cover AI Failures. That Is a Problem.
Seven in ten organisations have AI plugged into their core systems, yet most security teams are trying to handle AI breakdowns with tools built for a completely different kind of threat.

AI Agents Are Now Running Entire Cyberattacks, Start to Finish
Two separate investigations show that criminals are handing whole attack campaigns to artificial intelligence, cutting the time it takes to ransack a company from weeks to hours.

Japan's biggest taxi firm Nihon Kotsu hit by malware, dispatch system still down
The Tokyo-based operator pulled systems offline over the weekend after detecting unauthorized access. Bookings, phone dispatch and the pregnant-women transfer service remain suspended.

Your AI risk register is a list, not a plan. Here is what organisations are missing.
Documenting AI risks is the easy part. Knowing who can actually shut the system down when something goes wrong is where most programmes fall apart.

Progress tells ShareFile customers to pull the plug amid 'credible' threat
The maker of a widely used file-sharing tool is emailing on-premises customers to shut down their servers now, while it investigates what it calls a credible external threat.

When Attacks Take Minutes, Not Days: The AI Speed Problem Defenders Now Face
Criminals using AI models can now write phishing bait, pick targets and hop between machines faster than most security teams can read the first alert.

One Person, 72 Hours, One Wrecked AWS Account: How AI Handed a Lone Criminal the Keys to a Global Enterprise
Incident-response firm Sygnia says a single attacker used AI to tear through a major cloud environment at a pace that would normally require a full criminal crew. The unnamed victim was extorted.

Your Threat Feed Said One Thing. The Malware Said Another.
A former incident responder spent two years learning that intelligence reports, federal advisories, and foreign government bulletins share the same quiet flaw: the copy most people read is rarely the full story.

The Gentlemen Ransomware Gang Turns Your Own IT Tools Against You
A fast-spreading criminal group is using the software your IT team trusts every day to take over company networks. The real test is not whether they got in. It is what happens next.

Chris Inglis on the Snowden Era: What NSA Got Wrong, and What CISOs Should Still Be Asking
The former NSA Deputy Director reflects on institutional failures, insider threat detection, and why 'enculturation' may matter more than access controls.