Aniket Bhardwaj
speaker
57 appearances
1 recordings
1 series
first heard Apr 2025
last heard Apr 2025
Aniket Bhardwaj’s voice in public audio — every appearance, attributed to the second.
Trend
recordings per month · last 12 monthsNo recordings in the last 12 months.Older appearances are listed below; set an alert to hear about the next one.
Appearances
Now, beyond the money aspect, what people often miss is that it's not just about the payout. It's about readiness. And from our perspective, the best carriers and brokers work with clients to run simulations or improve their IT and security controls and really reduce the risk before anything happens. So yes, from my perspective, you absolutely need it.
not because it replaces cybersecurity, but because it really reinforces that. So just like you wouldn't drive without car insurance, you shouldn't run a digital business without cyber coverage.
So incident response trends, definitely a growing economy at scale with respect to multiple incidents that are really being impacted. So from our perspective, the key trends that we really observe are really in the space of geopolitical activity. As I briefly mentioned, the whole cyber espionage efforts or state actors,
continuously targeting the overall organizations across the globe, which continues to be the key element when we are seeing different threat actors operating. We are also seeing a noticeable shift in both the frequency and really the complexity of incidents. So again, it's no longer just about
ransomware, you are really talking about multi-pronged attacks that blend extortion, data theft, and supply chain compromise all in one hit. So, tradactors are really more calculated. They're spending weeks inside networks and learning about different business models, or let's say, understanding vendor relationships, and then really striking with different surgical procedure, for instance.
One major trend maybe I should talk about is the rise in targeted extortion without encryption in ransomware events. So in these cases, threat actors slightly exfiltrate sensitive data and skip the whole encryption phase. So no splashy ransom notes, not that it happens a lot, but still just a quiet threat to publish unless paid.
And that really changes how executives think about visibility and response because It's not about recovering systems anymore. It's really about the brand, the trust, and the overall legal exposure. The other trend maybe I should also cover is around the legal and regulatory stakes. They are again getting higher and higher.
So every response is now a coordinated play involving outside counsel, insurance, privacy regulators, and really the law enforcement agencies. Their involvement is key to the whole response process. But ultimately the timelines are shrinking and at the same time, expectations are growing. And one more I should maybe highlight is the overall identity, which is again, becoming the new perimeter.
So we are seeing compromise after compromise that starts with meek multi-factor authentication or sale administrative accounts or overprivileged service accounts or identities. So again, it's not flashy, but that's where the real risk lives. So we used to really think of incident response as a fire drill.
Now it's more like crisis leadership and companies that do well, they're the ones who already rehearsed the play. And maybe I'll just say this in the end, the most prepared clients are rarely the ones calling us for the first time.
Yes, I mean, I think now you're getting in one of the most uncomfortable truths of ransomware, paying the ransom again doesn't guarantee closure. So really, I mean, I think we could spend hours and hours discussing this, but from my perspective, paying the ransom might stop the bleeding in the moment, but it doesn't mean that the tractor is gone for good.
In fact, we have seen multiple cases where the same group or ransomware affiliate returns within months, sometimes even weeks, either because the organization didn't fully close the back door or worse, because word got out that they were willing to pay. Think of it like this.
If a burglar breaks into your house and you quietly pay them to leave, but you don't change the locks, what stops them from coming back? Now, sometimes it's not even the same group. The data from the first breach might be resold on underground forums. And a second group sees you as an easy target. Now, in the event of cyber sort of like underground, for instance, a willing pair
becomes a high value lead. So that's why a critical part of any ransomware response isn't just recovery, it's hardening, making sure you have a solid IT security hygiene, you have full understanding of your digital ecosystem, full understanding of how many assets you have in the environment. Are they patched? Are they vulnerable? Are you taking enough steps in a timely manner so that
threat actors don't end up exploiting those vulnerabilities, you know, really identify, clean up network segmentation, visibility, threat hunting to really ensure that you are ahead of the game before a threat actor successfully infiltrates your environment.
So all of that needs to happen quickly after the whole containment, because if it doesn't, you're not just closing out an incident, you're opening the door to the sequel.
Absolutely. So at Charles River Associates, within the incident response practice, we work with clients across the full spectrum of cyber events, from urgent breach response to proactive resilience planning. A big part of our work is helping organizations navigate the technical, the legal, and business dimensions of an incident all in real time.
So we are not just fixing systems, we are helping leaders make high-impact decisions under pressure. So let me share a few examples. In one case, a global manufacturing company was hit by ransomware that crippled their operations across three continents. Every hour offline was costing millions. Our team helped prioritize system restoration.
coordinated with the forensics and legal teams and supported the overall executive communications and even the insurer reporting. So once again, we weren't just restoring IT, we were helping the business survive the whole critical moment. In another matter, we worked with a private equity firm assessing a potential portfolio company.
Everything looked fine on the surface, but our review uncovered weak identity controls, shadow IT, and traces of past compromise. That was a big one. That really changed the entire valuation discussion and gave the acquirer critical leverage to really protect their investment. And then there was a sensitive case involving suspected ties to North Korean IT workers posing as remote contractors.
Showing 21–40 of 57 · page 2 of 3
← Previous
Next →