Topic · 12 articles
Audit & Forensics
The per-operation record that turns scoping from a guess into a query.
Spans Federal & Defense, Threat Brief, RackTop Perspective, Executive Briefing and Practitioner Guide.

CJIS Security Changes for 2026 and 2027: What State and Local Agencies Need to Know
Two dates now shape CJIS planning for state and local agencies: the FIPS 140-2 sunset on September 21, 2026, and the end of the zero-cycle period on September 30, 2027. Here is what each one actually requires, and why so much of the work lands on storage.
11 min read

Valid logins, an MFA bypass, and 678,000 records: the French tax breach
France’s tax administration disclosed that an attacker used a staff account and a contractor account, plus a multi-factor bypass, to consult and extract data on 678,000 people and businesses. Nothing was encrypted. Every query looked like work.
5 min read

Six terabytes, allegedly: the hospital breach nobody can yet bound
A ransomware crew says it took six terabytes of the most sensitive records a health system holds. The health system says the claim is unverified. Weeks after the attack, both statements can still be true, and that gap is the leverage.
5 min read

Before the ransom note: what hackers learn from your files
Ransomware is the loudest threat to unstructured data, but it is not the first one. Hackers and APTs read your files long before they encrypt anything, and what they learn shapes the entire attack. Cyberstorage exists because protection has to start at the read, not the ransom note.
5 min read

Six days inside, three months to say what left: the CareCloud breach
Attackers had access to a CareCloud electronic health record environment for six days in March. It took until late June to determine what they took, and until the end of July for at least 345,000 people to be told. The gap between intrusion and answer is an audit problem.
6 min read

The Craneware breach: when attackers read your file names before your files
Healthcare revenue-cycle vendor Craneware says attackers viewed and exfiltrated a significant volume of file names, plus a percentage of employee data and a subset of customer records, before it contained the intrusion. Nothing was locked. The detail worth sitting with is that enumerating a file estate at scale is itself a storage-layer event, and it happens on live data long before anyone notices.
5 min read

Two exabytes, and no one agrees who owns it: the AI World Cup and the data layer
The 2026 World Cup is projected to generate roughly 90 petabytes of tournament data, and some two exabytes overall. Almost none of it is rows in a database. The harder problem is not storing it: ownership is a bundle of contractual rights, and only the data layer can prove who actually touched what.
6 min read

The breach that does not trip the alarm
Ransomware is loud. Data theft is quiet. A credentialed insider or a patient attacker can read sensitive files for months while every dashboard stays green, because nothing is watching the data itself. Data Centric Zero Trust and Cyberstorage exist to change that.
7 min read

Your security stack watches everything except the data
Endpoints, networks, identities, email, cloud posture: modern security programs instrument all of it. The one thing almost nobody instruments is the file data attackers are actually after.
5 min read

One stolen token, 700,000 files: what the Novo Nordisk breach says about the data layer
An extortion group says it copied roughly 1.3 TB, more than 700,000 files, from Novo Nordisk after finding a single access token, then spent more than two months reading source code, research, and manufacturing data. No systems were locked. The leverage was the files themselves.
4 min read

Recovery time is now a disclosure question
Regulators, insurers, and customers increasingly ask the same two questions after an incident: how fast were you back, and what exactly was taken? Both answers are determined at the data layer, before the incident ever happens.
2 min read

File activity telemetry: what your SOC actually needs from storage
Most NAS audit feeds were designed for compliance checkboxes, not threat detection. Here is what detection-grade file activity telemetry looks like, how to wire it into SIEM and SOAR workflows without drowning the license, and the two tests that prove the integration is real.
5 min read
See data-layer defense in your environment
In a 30-minute demo we’ll show Active Defense stopping an attack inline, immutable recovery, and surgical rollback — mapped to your data and your threats.
