Notes from the phone tree, not a marketing calendar.
Short, occasional writing from whichever Block Captain had something worth saying that month.
Why we still call it a "drill."
Somewhere along the way, the security industry decided "drill" sounded old-fashioned and started calling the same exercise a "tabletop simulation" or a "readiness assessment." We never stopped calling it a drill, because that's what it is: the same steps, run enough times that nobody has to think about them when it actually matters. The point of a fire drill was never the drill. It was making sure that when the actual smoke shows up, your body already knows where the exit is before your brain has finished being afraid. Ransomware works the same way. The organizations that handle it well aren't the ones with the best documentation. They're the ones who've run the drill enough times that the documentation is basically muscle memory.
The word "unprecedented" should be retired.
We looked back through a decade of vendor threat reports for this one, and "unprecedented" shows up an average of four times per document, attached to things that, on inspection, had fairly close precedents. Most attacks are a familiar technique against a familiar gap, executed by people who read the same public writeups everyone else did. Calling everything unprecedented isn't just imprecise, it's bad for preparedness: if every incident is framed as a once-in-a-lifetime anomaly, nobody builds the muscle memory for the ordinary version that's actually coming next Tuesday. We'd rather tell a client "this is the third time we've seen this exact playbook this year" than make them feel like they got struck by lightning. Lightning, you can't drill for. This, you can.
What a phone tree can teach you about ransomware.
A phone tree is not a glamorous piece of technology. It is, however, one of the only pieces of incident response infrastructure that still works when your email, your Slack, and your ticketing system are all encrypted and unavailable, which is exactly the moment you need it most. Most of the incident response plans we review have a beautiful flowchart and no actual answer to the question "if nobody can log into anything, how does the fourth person on this list find out they need to show up." We've been maintaining some version of a phone tree since before some of our clients' companies existed. It has never once needed a software update, mostly because it doesn't run on software.
A brief history of us being slightly behind, on purpose.
We were late to calling it "threat intelligence." We were late to several subsequent rebrands of the same basic idea. This isn't an accident — we've found that the vendors chasing the newest term for the discipline are usually the ones who haven't finished the unglamorous version of the old term yet. Patch management isn't exciting. Neither is a phone tree, or a drill you've run forty times, or writing the same daily briefing for six years running. We'd rather be the last ones to adopt a new name for readiness and the first ones who actually have it.