Blackbaud Ransomware (July 2020): When Your SaaS Provider Pays the Ransom
In July 2020, Blackbaud — a cloud software provider widely used by nonprofits, universities and healthcare organizations for fundraising and donor...
Insights
Articles in Retrospectives.
In July 2020, Blackbaud — a cloud software provider widely used by nonprofits, universities and healthcare organizations for fundraising and donor...
SaaS vendors hold your data, and their security directly affects yours. Here is a practical approach to assessing SaaS vendors before you sign —...
You can't monitor a SaaS vendor's internal systems, but you can monitor signals that indicate rising risk — and your own exposure if something goes wrong.
The short version: In 2020, Blackbaud — software used by thousands of charities and schools — was hit by ransomware and paid the attackers. Its customers...
In early 2020, as remote work exploded, "Zoom-bombing" entered the vocabulary: uninvited people joined online meetings and classrooms to disrupt them with...
Microsoft Teams meeting policies decide who can join, present and record. Here is how to tighten them without making meetings painful.
Meeting disruption and eavesdropping are rare, but when they happen in sensitive meetings the impact is high. These detections help you spot unusual meeting...
The short version: In 2020, uninvited strangers began crashing online meetings — "Zoom-bombing." It was a wake-up call: video meetings had become as...
In March 2020, the COVID-19 pandemic sent much of the global workforce home almost overnight. Microsoft Teams usage exploded as organizations rushed to keep...
Teams sprawl and forgotten guest access create real security risk. Here is how to put lightweight governance in place without slowing collaboration.
Guest accounts and broad Teams access can quietly expose sensitive data. These detections highlight risky guest activity and sharing.
The short version: When COVID-19 sent everyone home in 2020, companies opened up collaboration tools as fast as possible. Many never tightened them again....
In March 2020, Amazon Detective became generally available. It helps security teams investigate findings from GuardDuty and other sources by automatically...
Amazon Detective helps you answer the key questions after a GuardDuty finding: is it real, what did the identity do, and how far did it go? Here is a...
A short, consistent runbook helps small teams respond to AWS incidents calmly. Use this as a starting template.
The short version: Security tools generate alerts. The value comes from deciding quickly which ones are real. Amazon Detective, launched in 2020, is one of...
In February 2020, personal details of more than 10.6 million MGM Resorts hotel guests were posted on a hacking forum. MGM confirmed the data came from a...
You can't protect customer data you can't find. Here is a practical approach to classifying and monitoring customer data stores across Azure, AWS and...
Data exposures from cloud servers and databases often go unnoticed until data appears for sale. These detections help you spot exposure and unusual data...
The short version: In 2020, personal details of more than 10 million MGM hotel guests appeared on a hacking forum, from an earlier breach of a cloud server....
In January 2020, Microsoft disclosed that a customer support database containing about 250 million records had been exposed on the internet without password...
A single network rule change exposed a Microsoft database to the internet in 2019. Azure Policy and private endpoints let you prevent that class of mistake...
Exposed databases are often found by internet scanners within hours. Detecting public exposure — and unexpected access — quickly is critical.
The short version: In 2020, Microsoft disclosed that a customer support database had been left exposed to the internet after a network setting change. If...