@mia-lindqvist
Community member since Jul 2026
Threat intel in financial services. Most days it's campaign exposure and the 'freeze or disclose' call. Opinionated about how boards get told the risk.
Shared decisions
Recommended CISO decision: do **not** perform blind global GitHub token revocation as the first click. Revocation and rotation are mandatory tonight, but the panel recommends a controlled 30–45 minute containment sprint first because researcher reporting on the Hades/Shai-Hulud lineage describes a plausible…
Board memo recommendation: do **not** pull the entire 2027 OT segmentation programme into H2 2026; approve a **targeted H2 2026 acceleration** of OT boundary segmentation, OT DMZ/remote-access control, network-device management-plane isolation, and compensating monitoring. The panel’s view is that…
TRM’s reported H1 2026 figure — about $643M in North Korea-linked crypto theft out of roughly $972M total losses — is strong enough to justify a DPRK-focused validation capability, but not a full in-house replacement for a blockchain tracing vendor. The panel’s consensus is to build a 90-day internal control…
As the MSSP advising client leadership, decide whether to invoke emergency change windows across all fourteen managed clients running on-premises SharePoint — m
Patch prioritizationDecision: do not frame this as “all fourteen immediately” versus “only the six internet-facing.” Because CVE-2026-45659 is listed in CISA KEV for active exploitation and Microsoft/MSRC guidance describes a SharePoint Server RCE requiring authorized low-privilege access, the defensible MSSP recommendation is to…
Board memo recommendation: fund a hybrid programme this fiscal year — immediate high-risk data minimization for stale identity documents and driver’s license data, paired with targeted encryption, access-control, and monitoring upgrades for data that must remain. A controls-only approach should be accepted only as…
A ShinyHunters-linked Canvas breach lands two weeks before term. Advising a university's leadership, the panel weighs pausing the Canvas–student-information-system integration sync until scope is clear against continuing with rotated tokens and enhanced monitoring.
As the vulnerability analyst, decide whether to emergency-patch our two legacy ColdFusion applications against CVE-2026-48282 this week or contain them behind t
Patch prioritizationDecision: emergency-patch both legacy ColdFusion applications this week. Do not rely on WAF containment until quarter-end replatforming; the panel assesses WAF containment may buy only limited short-term time while patching, and only if controls are validated. CISA KEV lists CVE-2026-48282, while reviewed reporting…
**Board memo — decision:** Allocate the remaining **€800,000** to a **90-day data-exfiltration detection and extortion-resilience programme**. Identity enrollment hardening and OT network segmentation are both important, but under the strict one-programme rule they are deferred to next year as capital programmes.…
SOC decision: freeze now, but narrowly. Treat this as a SEV-2 fund-containment incident, not an attribution case: reported BonkDAO treasury-drain activity justifies urgent escalation, but public reporting alone is not freeze-ready address evidence. Apply asset-specific holds only where internal telemetry,…
Recommendation: declare an internal SEV-2 security incident now — “suspected TeamPCP-related CI/CD credential-theft exposure” — and activate scoped response for CI/CD, identity, cloud, source control, registries, and build provenance. Do not call it confirmed compromise, breach, or a VECT ransomware incident…
Board memo: adopt **refusal to pay as the default posture**, but not because Novo Nordisk proves refusal “worked.” The public evidence supports a narrower conclusion: Novo confirmed limited unauthorized access and exposure of pseudonymized clinical-trial-related data, while broader claims of 1TB+ theft, source…