Skip to main content

White Paper Library

Major incident failures, interpreted through a resilience lens.

Each paper helps boards, CISOs, and resilience leaders understand what failed, why the impact spread, and what should be rehearsed.

Incident White Paper

When Invisible Infrastructure Became the Largest Data Theft in History

How Cl0p exploited a single zero-day in MOVEit Transfer to compromise 2,700+ organisations and 93 million individuals — without encrypting a single file — and what it reveals about silent supply chain exposure.

Jul 25, 2025 8 min read Frank Kahle
Incident White Paper

When a Phone Call Bypassed Every Control

How Scattered Spider social-engineered a third-party help desk to breach Marks & Spencer, triggering a £300M profit impact, a 46-day online shutdown, and spreading to Harrods and Co-op.

Aug 20, 2025 8 min read Frank Kahle
Incident White Paper

When the Monitoring Tool Was the Compromise

How Russia's SVR compromised SolarWinds' build process to push a trojanised update to 18,000 organisations — and why the trust model that software supply chains depend on became the attack surface.

Jun 10, 2025 9 min read Frank Kahle
Incident White Paper

When a Business Process Dependency Shut Down National Infrastructure

How a ransomware attack on Colonial Pipeline's billing systems — not the pipeline itself — triggered a six-day fuel crisis across 17 US states and what it reveals about unmapped business process dependencies.

Mar 15, 2025 8 min read Frank Kahle
Incident White Paper

When Collateral Damage Went Global

How a Russian cyberweapon targeting Ukrainian tax software destroyed $10 billion in value across global shipping, pharma, and logistics — and why Maersk's entire recovery depended on a single server that survived by accident.

Jan 8, 2025 9 min read Frank Kahle
Incident White Paper

What the CDK Global Attack Proved About Sector-Wide Dependency Failure

How a single vendor compromise paralysed an entire industry vertical and what it reveals about sector-wide dependency concentration and recovery planning.

Apr 8, 2026 6 min read Frank Kahle
Incident White Paper

What the Synnovis Breach Proved About Healthcare Dependency and Recovery

How a pathology services attack cascaded through the NHS and what it reveals about healthcare supply chain fragility, clinical dependency mapping, and recovery sequencing.

Apr 1, 2026 6 min read Frank Kahle
Resilience Guide

What the Stryker Acquisition Reveals About the Next Wave of Disruption

How large-scale M&A activity introduces systemic integration risk and what resilience leaders should rehearse before operational consolidation begins.

Mar 19, 2026 6 min read Frank Kahle
Incident White Paper

What the Change Healthcare Breach Proved About Concentration Risk

How a single-point-of-failure in healthcare payments processing exposed systemic concentration risk and what it means for critical service dependency mapping.

Mar 10, 2026 6 min read Frank Kahle
Incident White Paper

What the CrowdStrike Failure Proved About Modern Operational Resilience

How a trusted security tool became a synchronised global business failure and what it reveals about concentration risk, leadership readiness, and dependency failure.

Mar 3, 2026 6 min read Frank Kahle
Incident White Paper

What the MGM Resorts Breach Proved About Identity and Operational Chaos

How a social engineering attack escalated into a full-scale operational shutdown and what it reveals about identity control, lateral movement, and crisis leadership under pressure.

Feb 18, 2026 6 min read Frank Kahle
Incident White Paper

What the NATS Failure Proved About National Infrastructure Resilience

How a flight plan processing failure grounded UK aviation and what it reveals about single points of failure in national infrastructure and the limits of redundancy design.

Feb 4, 2026 6 min read Frank Kahle
Incident White Paper

What the Rogers Outage Proved About National-Scale Dependency Failure

How a single routing configuration error took an entire country's communications offline and what it reveals about cascading dependency failure at national scale.

Jan 14, 2026 6 min read Frank Kahle
Incident White Paper

What the AWS Route 53 Outage Proved About DNS Outage Analysis

How a DNS infrastructure failure cascaded across cloud-dependent services and what it reveals about hidden single points of failure in modern architectures.

Oct 21, 2025 6 min read Nick Taylor
Incident White Paper

What the Vodafone Outage Proved About Telecom Outage Lessons

How a major telecommunications failure disrupted services at scale and what it reveals about infrastructure redundancy, customer communication, and recovery prioritisation.

Oct 15, 2025 6 min read Nick Taylor
Resilience Guide

Building an Incident Response Plan That Works Under Pressure

Why most incident response plans fail when they are needed most and how to build plans that survive first contact with a real crisis through structured rehearsal and realistic testing.

Sep 28, 2025 6 min read Nick Taylor
Incident White Paper

When Transformation Becomes the Incident

How TSB's botched IT migration locked 1.9 million customers out of their accounts, cost £330M+, and forced the CEO to resign — with no attacker involved. What it reveals about self-inflicted operational crisis.

Nov 12, 2024 8 min read Frank Kahle

Go deeper

Turn insight into rehearsed readiness.

Each white paper maps directly to scenarios you can rehearse on the CrisisLoop platform. Move from understanding what failed to proving your team can respond.