Subtitle Icon
Blog Category

Executive Risk & Board Advisory

Blog Meta Icon
July 28, 2026
Blog Meta Icon
9 minute read

Three Breaches, Three Years. Client Tax Records in a Hacker's Hands. EY Still Won't Name the Platform That Failed.

EY was breached a third time in three years, and this time the stolen files are client tax records. What boards and PE deal teams should be asking now.

Blog Meta Icon
June 21, 2026
Blog Meta Icon
11 minute read

Amazon's One Medical Confirms a "Limited" Breach. ShinyHunters Claims 8.8 Terabytes and a Deadline. Only One of Those Is Verified.

On June 13, One Medical disclosed unauthorized access to a third-party file storage system holding archived records from its legacy Iora Health and One Medical Seniors patients, describing the scope as a limited subset of files at nine named clinics. Days earlier, on June 18, ShinyHunters posted One Medical to its dark-web leak site, claimed 8.8 terabytes of stolen data, and gave the company until June 22 to begin negotiating before publication. ShinyHunters has released no sample data, so the claim is unverified. This is the same actor, the same playbook, and the same trust gap Cloudskope documented in the Canvas/Instructure breach: a company describing the smallest defensible version of events while a threat actor describes the largest. For boards in healthcare and any regulated-data business, the lesson is not which number to believe. It is to treat both as unproven until the evidence settles it, and to plan for the larger one.

No items found.
Blog Meta Icon
June 19, 2026
Blog Meta Icon
15 minute read

Drift. Gainsight. Now Klue. And This Time, It Wasn't ShinyHunters.

For the third time in ten months, attackers drained Salesforce data through a trusted app. The first two were ShinyHunters. This one wasn’t — and that is why it matters.

Blog Meta Icon
June 7, 2026
Blog Meta Icon
6 minute read

Five Cyber Questions That Change What a Deal Is Worth.

Cyber due diligence is usually a checkbox near the end of the process. Five specific questions turn it into a deal-pricing input, surfacing the risks that actually move valuation and post-close cost.

Blog Meta Icon
June 7, 2026
Blog Meta Icon
6 minute read

Acquisition Agreements Get Signed on Cyber Reps Nobody Verified. That Becomes the GC's Problem.

Acquisition agreements get signed on cyber reps no one independently verified. When the deal closes, the gap between what was repped and what's true becomes the buyer's liability and the GC's problem. What deal counsel should require first.

Blog Meta Icon
June 7, 2026
Blog Meta Icon
7 minute read

The First 100 Days After Close Decide Your Cyber Risk for the Whole Hold.

Cyber due diligence is a screen, not a clean bill of health. The day a deal closes, every undetected weakness becomes the sponsor's problem, and the first 100 days are the only window with the leverage to fix it.