EXTEND Resources

EXTEND Resources EXTEND Resources delivers efficient, cost-effective information security and data privacy services. Fresh perspectives. Holistic problem solving.

Pressure to improve results, enhance client loyalty, and meet specialized requirements—all while managing business with shrinking budgets—often leave companies without the experienced, cost-effective resources they need to make data-driven decisions and achieve their performance goals. Enterprises need a new approach to business and legal support services—one where experienced, multi-disciplinary

leaders deliver long-term solutions to clients. By bringing together the capabilities of De Novo Perspectives, American Discovery, and Nighthawk Global, and partnering with a select group of complementary organizations, EXTEND Resources delivers proven business process optimization, legal support services, and compliance solutions to clients worldwide.

Healthcare distributor McKesson is responding to a cyberattack that affected its third-party applications and caused tem...
08/31/2026

Healthcare distributor McKesson is responding to a cyberattack that affected its third-party applications and caused temporary service delays. The extortion group ShinyHunters claims it accessed company systems by making phone calls to employees while pretending to be IT support staff. The criminal group claims to have stolen a 284 million patient records.

This incident highlights a growing danger for modern businesses: cybercriminals are increasingly targeting people rather than software flaws to gain entry into cloud applications.

Protecting your business requires strong identity checks, clear data privacy rules, and regular review of third-party software risks.

https://hubs.ly/Q04vZr8j0

The pharmaceutical and healthcare technology company McKesson informed regulators it is in the early stages of investigating a cybersecurity incident involving an unnamed third-party application.

A federal court has officially approved a $117.5 million settlement against Comcast following a major 2023 data breach a...
08/25/2026

A federal court has officially approved a $117.5 million settlement against Comcast following a major 2023 data breach affecting 31.7 million individuals. The breach, triggered by the exploitation of the "Citrix Bleed" vulnerability, stands as one of the largest and most legally complex data breach cases to date.

Key corporate takeaways from the ruling include:

• Third-party software vulnerabilities can expose organizations to multi-million-dollar class action liabilities.
• Unpatched systems create significant exposure under both state common law and federal statutory frameworks.
• Courts are increasingly scrutinizing the duty of care owed by both enterprise software customers and vendor providers.

Protecting corporate assets requires moving beyond perimeter defenses to implement rigorous third-party risk management and rapid patch governance.

EXTEND Resources assists executive leaders in optimizing data privacy, information security, and governance strategies. Contact us to learn how.

A federal judge has approved a $117.5 million data breach settlement against Comcast Cable Communications. The agreement represents one of the largest

[LINK IN COMMENTS] A report from the World Economic Forum highlights a critical disconnect in modern corporate leadershi...
08/14/2026

[LINK IN COMMENTS] A report from the World Economic Forum highlights a critical disconnect in modern corporate leadership: 73% of companies view cybersecurity as a key priority, but only 59% of boards back that priority with dedicated budget allocation. Furthermore, just 50% of boards fully grasp the cybersecurity risks associated with artificial intelligence.

As cyber threats become more sophisticated and AI-driven, treating security as an isolated IT function is no longer viable. True resilience requires board-level oversight, aligned funding, continuous talent upskilling, and strict AI governance framework implementation.

A major enterprise cyber incident demonstrates how quickly operational disruptions can turn into data privacy events. Co...
08/11/2026

A major enterprise cyber incident demonstrates how quickly operational disruptions can turn into data privacy events. Coca-Cola has confirmed that a ransomware attack on its Fairlife subsidiary involved unauthorized access and the theft of company data.

Although business continuity plans helped restore facility production and protect inventory, the situation underscores why executive teams and legal counsel must prepare for complex exfiltration scenarios before an incident occurs.

Are your business continuity and incident response plans aligned to handle double-extortion ransomware? Check the first comment for the link to the complete article.

The Anubis cybercrime group has taken credit for the attack and is threatening to leak data.

Corporate wind-downs and bankruptcy do not shield organizations from severe data breach liabilities. Former employees of...
08/05/2026

Corporate wind-downs and bankruptcy do not shield organizations from severe data breach liabilities. Former employees of shuttered trucking giant Yellow Corp. have filed a class action lawsuit following a cyber incident that exposed thousands of worker records, including 20 years of Social Security numbers.

The lawsuit alleges a 15-month gap between the initial network compromise and victim notification. For executives, legal directors, and risk officers, this serves as a clear lesson on the importance of maintaining data protection protocols and transparent incident response procedures across every stage of the business lifecycle.

Is your enterprise managing legacy data retention risks before they turn into costly litigation? Check the first comment to access the full report and governance insights.

A $4.02 million settlement agreement offers a stark warning for healthcare leadership, risk managers, and corporate lega...
07/21/2026

A $4.02 million settlement agreement offers a stark warning for healthcare leadership, risk managers, and corporate legal teams. ApolloMD Business Services has agreed to create a multi-million-dollar fund to resolve a class action lawsuit following a May 2025 ransomware intrusion that compromised the data of more than 626,000 individuals. This case proves once again that managing third-party business associates requires far more than basic contract language—it demands proactive, continuous risk governance.

Is your organization doing enough to evaluate vendor security before a breach occurs? View the first comment to access the full article.

A look at the biggest data breaches of 2026 so far shows that human vulnerability remains a primary target for cybercrim...
07/17/2026

A look at the biggest data breaches of 2026 so far shows that human vulnerability remains a primary target for cybercriminals. Prominent organizations, including Carnival, ADT, and Panera Bread, have faced massive exposures this year, with millions of customer and employee records leaked.

The common thread among these major incidents is a reliance on credentials that were compromised through social engineering and phishing. For executive leadership and risk officers, this highlights a pressing need to move beyond basic security checklists and focus on implementing phishing-resistant authentication and tighter administrative privileges.

Is your business prepared to handle the operational and reputational fallout of a credential-based attack? Check out the TechRepublic analysis of these incidents. Then, work with EXTEND Resources to address modern access vulnerabilities. Link in comments.

European retail giant Lidl recently confirmed that a cyberattack at one of its IT service providers exposed customer dat...
07/13/2026

European retail giant Lidl recently confirmed that a cyberattack at one of its IT service providers exposed customer data, including names, phone numbers, emails, and dates of birth. The breach did not compromise billing systems, but it leaves customers facing increased risks of sophisticated phishing attempts.

For corporate board members and security executives, the takeaway is clear: your digital perimeter extends far beyond your own internal infrastructure. Relying entirely on internal defenses overlooks the data risks hiding across your external supply chain.

A proactive risk strategy means prioritizing continuous vendor assessments, building strict data minimization policies, and staying prepared for incident response alongside your partners.

EXTEND Resources assists organizations in identifying supply chain weak points and deploying robust risk management solutions. Learn more about protecting your enterprise.

https://bit.ly/44sRhgt

Customers in three countries have had some of their data stolen but so far, it hasn't surfaced anywhere.

A newly discovered 8-terabyte database exposed online contains 24 billion records, exposing plain text usernames, passwo...
06/18/2026

A newly discovered 8-terabyte database exposed online contains 24 billion records, exposing plain text usernames, passwords, and login URLs to the public web. Compiled from 36 different sources, this massive data leak presents an immediate threat of widespread account takeovers across global industries.

For corporate board members and risk management professionals, a leak of this scale is a reminder that cyber risks are often born outside your corporate firewall. Employees utilizing corporate passwords on compromised external sites create silent pathways for corporate intrusion.

Maintaining a strong risk posture requires ongoing education, strict identity governance, and the implementation of multi-factor authentication across all enterprise entry points. Discover how EXTEND Resources helps organizations identify vulnerabilities, build resilient privacy policies, and manage enterprise security risks effectively.

https://bit.ly/43IiWcY

The exposed database, weighing approximately 8 terabytes, was compiled from 36 different sources, including Telegram channels, previous data breach collections, and data exported from live servers.

The FBI’s classification of this intrusion as a “major incident” may involve a government system, but the lessons reach ...
04/10/2026

The FBI’s classification of this intrusion as a “major incident” may involve a government system, but the lessons reach well beyond government.

The article reports that access appeared to come through a commercial ISP’s vendor infrastructure. For private-sector security leaders, that raises important questions about third-party access, sensitive operational data, system segmentation, and incident escalation.

This federal cybersecurity story is also a reminder that vendor exposure and governance gaps can create serious consequences in any organization with high-value systems and sensitive data.

https://bit.ly/4mb8NxE

The Federal Bureau of Investigation (FBI) communicated to Congress that a recent cyber intrusion into one of its internal surveillance systems has formally been classified as a "major incident" under federal data security law. This cybersecurity incident represents one of the most serious breach cla...

Address

Stamford, CT

Alerts

Be the first to know and let us send you an email when EXTEND Resources posts news and promotions. Your email address will not be used for any other purpose, and you can unsubscribe at any time.

Contact The Business

Send a message to EXTEND Resources:

Shortcuts

Share