Skip to content

Cybersecurity Office Hours: Breaches, Bans, and Backdoors: How to Handle a Breach (and How Not To)

 

 

Optimize your Company's Security

Secure your organization with confidence, no matter your budget, we’re here to help you optimize your cybersecurity. Fill out the form to take the first step toward stronger protection and peace of mind. Let’s work together to stay ahead of threats!

Resources Mentioned

Have I been Pwned: https://haveibeenpwned.com/ 

Fundamentals Training: https://get.endsight.net/monthly-cybersecurity-fundamentals-training 

AI Office Hours: https://www.endsight.net/development/webinar 

Last Security Office Hours: https://www.endsight.net/sec/ai-and-phishing-in-cybersecurity 

Security Video Library: https://www.endsight.net/security-shorts 

Endsight YouTube Channel: https://www.youtube.com/@EndsightIT 

Anthropic Mythos/Fable Access Update: https://www.anthropic.com/news/fable-mythos-access

Risk Assessment Cybersecurity Short: https://www.endsight.net/security-shorts/risk-assessment

Canvas Breach Overview: https://www.staysafeonline.org/articles/canvas-data-breach

Canvas Breach Guidance for Educational Institutions: https://www.fisherphillips.com/en/insights/insights/the-canvas-breach-what-educational-institutions-need-to-know-and-how-you-can-respond

Credit Bureau Freeze Tip: https://www.reddit.com/r/YouShouldKnow/comments/1qfiyrd/ysk_freezing_just_the_big_3_credit_bureaus_isnt

Windows Defender Zero-Day Research Note: https://labs.cloudsecurityalliance.org/research/csa-research-note-defender-zero-days

Video Explainer: https://www.youtube.com/watch?v=phsRA-_DDwE

Huntress Klue Breach Investigation: https://www.huntress.com/blog/klue-breach-investigation

3 Pillars of Cybersecurity: https://www.endsight.net/security-shorts/3-pillars-of-cybersecurity 

Cybersecurity Winery Video: https://www.endsight.net/security-shorts/ransomware-and-wineries-the-real-target-isnt-your-wine 

Overview

Quarterly Office Hours + Q&A

On-Demand Recording | July 23rd 2026

Breaches, Bans, and Backdoors: How to Handle a Breach (and How Not To)

Every week brings another alarming security headline: a breach, an attack, a government crackdown. Most of them generate more fear than understanding, and that gap is exactly where leaders make bad calls. In this session of Cybersecurity Office Hours, Endsight's Cybersecurity Practice Manager, Stephen Hicks, broke down the stories that actually matter and explained what they mean for your business, in plain language and without the fear-mongering.
 
This quarter centered on a lesson worth internalizing: you can't prevent every breach, especially when it starts with a vendor you rely on. What you can control is how you prepare and respond. Stephen used Huntress as a model of a third-party breach handled right, then looked at what the Canvas attack, the Anthropic restrictions, and the latest Windows Defender zero-days mean for the way you manage risk.


Agenda

  • The Canvas (Instructure) breach. How a ransomware attack exposed student data, from IDs to private messages, and what to do when your information is already out there.
  • The U.S. government vs. Anthropic's AI models. Why restricting the Mythos and Fable models to U.S. citizens was a supply-chain risk story, not just an AI one.
  • The Klue breach and Huntress. How a third-party breach got handled the right way, and what to take from it.
  • The Windows Defender zero-day standoff. One researcher, Microsoft, and a patch race that never quite ends.
  • Resources to go deeper. The articles and advisories worth reading on each story.
  • Live Q&A. Stephen answered attendee security questions live.

What You'll Learn

  • What changed in the threat landscape: A breakdown of the most relevant cybersecurity trends and incidents from the past quarter.
  • Why those changes matter: Context around how new threats, vulnerabilities, and attack patterns impact your organization.
  • Where organizations were most at risk: Common gaps across people, process, and technology.
  • How attackers are evolving: Insight into how tactics, tools, and strategies continue to shift.
  • What to focus on next: Practical cybersecurity tips and recommendations based on current trends.
  • How to think about security strategically: Moving beyond reactive fixes toward a more structured approach.

 

Speaker

thumbnail_StephenHicksHeadShotWDog

Stephen Hicks

Security Practice Manager @ Endsight

Stephen has spent his entire professional career in the technology industry. He holds an MBA from Saint Mary's College and just over a dozen technical certifications including advanced cybersecurity certifications CISSP and CISM. He has a second-degree black belt in Shito Ryu Karate and loves to scuba and ski.