top of page




When Identity Becomes the Attack Path, Recovery Must Restore Control
Microsoft’s Storm-2949 research shows how identity compromise can become a cloud-wide breach across Microsoft 365, Azure resources, Key Vault secrets, storage, SQL databases and virtual machines. This article explains why identity recovery must restore a known-good control state, not just access.
Daniel Smith
May 257 min read


Jaguar’s Cyber Breach: When Identity Fails, Recovery Must Begin at Tier-Zero
Jaguar’s 2025 cyber breach showed what happens when identity fails: production stops, data is stolen, trust collapses. This case study unpacks the attack chain, the AD ↔ Entra ID recursion risk, and why CPS 230 & Essential Eight demand proof of recovery across both planes - ExaGrid for workloads, Keepit for SaaS and identity.

David Long
Sep 25, 20257 min read
bottom of page