Security | Threat Detection | Cyberattacks | DevSecOps | Compliance

Anatomy of a Cyber Incident: Why Recovery Fails When Personas Aren't Aligned

Despite their complexities, cyber incidents often start in a very similar manner. There is a helpdesk ticket that appears routine, a slightly unusual login attempt or a system that might just need a restart. By the time an organization formally declares an incident, the attacker has likely already been inside for hours, sometimes longer, moving quietly through cloud platforms, SaaS applications and identity systems long before anyone notices the warning signs.

A New Compliance Discipline: Key Insights from Building the Kroll Cyber Resilience Act Framework

From September 11, 2026, any manufacturer, importer or distributor of hardware and software products with digital elements made available on the EU market must comply with the Cyber Resilience Act (CRA). The harmonized standards under the CRA are still being drafted, and the first will not be finalized before manufacturers need to act.

SEC Advances Crypto Asset Capital Formation Framework

On August 18, 2026, the SEC proposed Regulation Crypto Assets1, a new regulatory framework intended to create a tailored registration exemption regime for certain crypto asset offerings while maintaining core investor protection requirements. The proposal represents a significant evolution in the SEC's approach to digital assets and could provide the clearest pathway to date for crypto issuers seeking to raise capital in the United States.

Elevating Global MDR: A Modernized, Agentic Managed Security Service

How Kroll transformed its global Managed Detection and Response (MDR) service to Kroll Responder MDR by utilizing CrowdStrike Falcon to deliver faster onboarding, deeper expertise and proactive resilience on a global scale. In December 2025, Kroll and CrowdStrike announced a multiyear strategic partnership to elevate MDR services worldwide.

The Industrialized Fraud Hiding in Plain Sight

To read more on this story and the significance of Business Email Compromise (BEC), visit The Wall Street Journal where Dave Burg was interviewed (subscription required). A few months ago, scammers hijacked a routine infrastructure project in Surfside Beach, South Carolina, costing the small town $545,000. The scheme stemmed from a single spoofed email sent from a lookalike domain, instructing the town to switch payment from check to ACH.

June Threat Intelligence Spotlight Report

Each month, our Cyber Threat Intelligence team compiles data from our engagements to determine key industry trends. We look at the initial access methods threat actors are using to gain entry into a network, types of incidents most commonly impacting organizations, which sectors are being more heavily targeted, and which threat groups are most prevalent.

Quick-Service Restaurant Sector: Enterprise-Grade Security in Under 24 Hours

A fully managed, end-to-end CrowdStrike deployment delivered at enterprise scale by Kroll A global quick-service restaurant brand needed to establish consistent, enterprise-grade protection and centralized visibility to quickly strengthen its security posture. It had to move fast without disrupting global operations or overburdening a lean IT team.

Kroll Conversations: Meet the Cyber Strategy and Advisory Experts

In a fast-moving threat landscape, finding the answers to complex security challenges can be fraught with unknowns. Asking the right questions can make all the difference, as Steven Escobar and Ben Habing know well through their work in the Assessments and Advisory practice within Cyber and Data Resilience at Kroll.