Board Risk
Nutex Health Filed Under 8.01. Seven Days Later It Filed Under 1.05. The Class Action Landed in Between.
Nutex Health filed a cyber incident under SEC Item 8.01, then converted to Item 1.05 seven days later. A class action arrived in between. What the sequence means for boards.
Take-Two Lost $2.8 Billion. The Hacker Cashed Out $250,000. Nobody Ever Sent a Ransom Note.
CyberLeek leaked GTA VI, pumped a memecoin, and cashed out $250K without ever demanding a ransom. What the first market-monetized extortion means for boards and deal teams.
Three Breaches, Three Years. Client Tax Records in a Hacker's Hands. EY Still Won't Name the Platform That Failed.
EY was breached a third time in three years, and this time the stolen files are client tax records. What boards and PE deal teams should be asking now.
Acquisition Agreements Get Signed on Cyber Reps Nobody Verified. That Becomes the GC's Problem.
Acquisition agreements get signed on cyber reps no one independently verified. When the deal closes, the gap between what was repped and what's true becomes the buyer's liability and the GC's problem. What deal counsel should require first.
What CISA's CI Fortify Guidance Actually Means, and Why It Reads Like a Confession
CISA's CI Fortify guidance tells critical infrastructure to plan for months running cut off from its own networks, on the assumption the adversary is already inside. Why that reads like a confession.
Still Inside: Why the Senate Says Salt Typhoon Was Never Fully Evicted
Salt Typhoon breached at least nine US carriers and the wiretap systems built for law enforcement. The Senate now says China's hackers were never fully evicted.
.png)