Skip to content
Artwork for Security by Default
Security by Default · Monday · 32 min

When a Simple Breach Became a Crisis: Lessons We Learned | Lukas Hlavicka

I discuss with Lukas Hlavicka how ordinary security incidents can escalate into full-blown crises when organizations lack preparation, reliable backups, and secure deployment pipelines. We share stark war stories, from backups that were never actually taken to compromised software deployment systems and a ransomware attack that exposed six months of bank fraud. Lukas draws on over a decade of incident response experience, including leadership of a national CSIRT and work in the private sector. We describe common failure points: unknown assets and third‑party links, intertwined IT and OT systems, missing evidence, unclear roles for decision and containment, and compromised CI/CD. We stress clear, practical steps: maintain offline incident plans and backups, map assets and dependencies, secure and monitor deployment pipelines, and practice response with defined authorities. This episode targets any organization that thinks “it won’t happen to us” and seeks concrete lessons to prevent incidents from becoming crises. Takeaways: I learned that many incidents become crises because organizations do not know what assets they own or how they connect to third parties. We must keep offline backups and verify that backups are actually taken and restorable before incidents occur. I saw attackers abuse cloud managed security products and deployment pipelines to gain full network access quickly. We found that unclear roles and slow approval processes delay containment and allow the attacker to spread further. I observed that organizations often destroy evidence or change systems in ways that hinder forensic investigations. We recommend practicing incident response, keeping plans offline, and retaining institutional memory to avoid repeating past mistakes. I noted cases where ransomware accidentally revealed long running fraud and showed the need to follow financial trails in investigations. We must monitor CI/CD and software supply chains continuously because compromise there can implant persistent backdoors.

0:00 · Chapter 1-32:15

transcript

No transcript — this publisher did not publish one.

show notes

I discuss with Lukas Hlavicka how ordinary security incidents can escalate into full-blown crises when organizations lack preparation, reliable backups, and secure deployment pipelines. We share stark war stories, from backups that were never actually taken to compromised software deployment systems and a ransomware attack that exposed six months of bank fraud. Lukas draws on over a decade of incident response experience, including leadership of a national CSIRT and work in the private sector. We describe common failure points: unknown assets and third‑party links, intertwined IT and OT systems, missing evidence, unclear roles for decision and containment, and compromised CI/CD. We stress clear, practical steps: maintain offline incident plans and backups, map assets and dependencies, secure and monitor deployment pipelines, and practice response with defined authorities. This episode targets any organization that thinks “it won’t happen to us” and seeks concrete lessons to prevent incidents from becoming crises.

Takeaways:

  • I learned that many incidents become crises because organizations do not know what assets they own or how they connect to third parties.
  • We must keep offline backups and verify that backups are actually taken and restorable before incidents occur.
  • I saw attackers abuse cloud managed security products and deployment pipelines to gain full network access quickly.
  • We found that unclear roles and slow approval processes delay containment and allow the attacker to spread further.
  • I observed that organizations often destroy evidence or change systems in ways that hinder forensic investigations.
  • We recommend practicing incident response, keeping plans offline, and retaining institutional memory to avoid repeating past mistakes.
  • I noted cases where ransomware accidentally revealed long running fraud and showed the need to follow financial trails in investigations.
  • We must monitor CI/CD and software supply chains continuously because compromise there can implant persistent backdoors.

chapters

7 chapters