Primary Domain
Risk and Accountability
Within the Primary Domain facet, Risk and Accountability intelligence groups reporting by primary domain so readers can follow a focused area of internet infrastructure, governance, connectivity markets, or digital capital. The page brings together related articles, public evidence, institutions, companies, people, regional exposure, operating dependencies, and market context that may otherwise sit across separate category pages. It explains the domain, the likely actor class, the market or governance context, and the source material readers should use when comparing signals. Operators, analysts, and governance readers can see how the same domain appears across events, profiles, market shifts, public-source evidence, regional dependencies, and longer-cycle infrastructure decisions over time.

Global National Telecom
Rogers made carrier control-plane fragility a public-service accountability problem
Rogers' July 2022 outage began inside a carrier routing change, but its accountability record belongs to everyone who discovered that phone calls, debit payments, emergency access, municipal operations, transport coordination, wholesale service, and small-business continuity…

Global National Telecom
Telstra made emergency-call fallback a third-party trust boundary
Telstra's July 2026 mobile outage showed that a carrier can declare broad restoration while emergency callers, welfare-check teams, transport operators, merchants, carers, and regulators still need a harder form of proof: that the public-service chain depending on the network has…

Global Cloud Services
Google Cloud's Belgium disk loss showed where locality stops being resilience
The 2015 Google Compute Engine Persistent Disk loss in Belgium was tiny by percentage and large by lesson: choosing a local cloud zone can satisfy latency or residency aims while still leaving the customer without an independent, recoverable copy when the physical failure domain…

Global Cloud Services
AWS made US-East-1 notice quality a cloud-dependency accountability record
AWS customers can choose regions, zones, data planes, recovery patterns, and even other providers, but a major US-East-1 control-plane event still forces one immediate question: can the provider tell customers, precisely and in time, whether their continuity plan is failing or…

Global Cloud Services
GitHub made host-key rotation a contract-versus-control accountability test
GitHub's March 2023 RSA SSH host-key replacement was a small cryptographic event with a large governance signal. The company could describe the service as provided under narrow contractual warranties, but developers and businesses still had to treat GitHub's host identity as a…

Global Institutional
23andMe made relatives a common-mode privacy dependency
The 23andMe credential-stuffing incident was not only an account-takeover case. It was a demonstration that a relationship feature can make one compromised account a common-mode exposure path for many people who did not reuse that account's password, did not approve the hostile…

Global Cloud Services
Snowflake made verifiable repair the test of shared cloud responsibility
The 2024 Snowflake customer credential-theft campaign did not require a demonstrated breach of Snowflake's production platform. That boundary matters, but it is not the end of accountability. The durable question is whether shared responsibility became measurable repair: stronger…

Global Institutional
Marriott made Starwood's reservation database a third-party trust boundary
Marriott did not create the original Starwood reservation-system intrusion, but it bought the company whose live reservation database carried that hidden compromise. The accountability problem is acquisition as a third-party trust boundary: business ownership can close before the…

Global National Telecom
T-Mobile made repeated breach harm an operational-control accountability test
T-Mobile's public breach record is not one incident repeated with one technique. It is a pattern across lab access, credentials, employee identity, remote sales tools, and API permissions that repeatedly turned customer data into harm potential. The accountability question is…

Global Cloud Services
Uber made delayed breach disclosure an enforcement-accountability record
Uber's 2016 breach is now less useful as a simple warning about exposed credentials than as a record of how delayed notice becomes enforceable fact. The decisive accountability question is who controlled the path from confirmed intrusion to legal escalation, rider and driver…

Global Cloud Services
Atlassian Confluence made patch timing a common-mode dependency test
Confluence vulnerabilities are not only product defects. In self-managed deployments, they test whether thousands of organizations can find, isolate, upgrade, investigate, and restore the same collaboration layer before attackers turn a shared knowledge platform into a shared…

Global Cloud Services
Kaseya made managed-service detection delay a downstream accountability problem
The Kaseya VSA ransomware incident showed that detection delay in a managed-service control plane is not contained at the vendor or provider layer. When the product that administers many customers becomes the delivery path, small businesses and public bodies can inherit notice…

Global Cloud Services
Maersk showed how NotPetya could move revenue continuity into operational control
NotPetya did not need to seize ships to damage Maersk's business. By making identity, booking, terminal, cargo-information, and customer channels unreliable, destructive malware turned revenue continuity into an operational-control question: who could keep the shipping network…

Global Cloud Services
Norsk Hydro made manual recovery evidence part of control-plane accountability
Norsk Hydro's 2019 ransomware response is often praised for transparency and manual production. Its deeper accountability lesson is stricter: when digital systems fail in industrial operations, manual fallback, public capacity updates, backup-led rebuilding, insurance recovery…

Global Cloud Services
Toyota made supplier IT a third-party production trust boundary
Toyota's one-day Japan production halt in March 2022 was short, but it exposed a durable accountability problem. A supplier-side technology failure can become a manufacturer-side control event when ordering, sequencing, and recovery workflows sit at the edge of lean production.…

Global Cloud Services
Southwest made crew-scheduling control an operational-harm accountability test
Southwest's December 2022 holiday collapse began in severe winter weather, but the accountability record did not stop with the storm. The harder question is how quickly an airline can reestablish truthful crew location, aircraft assignment, customer notice, baggage flow, refund…

Global Cloud Services
Delta made vendor-outage notice quality an enforcement-risk question
The CrowdStrike outage began as a defective security update, but Delta's longer recovery made the public accountability question broader: when a supplier fault disables an airline's machines, the airline still controls passenger notice, recovery sequencing, refund evidence, and…

Global Institutional
NHS WannaCry made old software a common-mode public-service dependency
WannaCry is remembered as ransomware, but the NHS accountability lesson is wider: old operating systems, uneven patching, local trust variation, and unclear ownership turned a known software weakness into a shared public-service dependency that could cancel care across many…

Global Cloud Services
Dyn made DNS dependency a revenue-continuity accountability problem
The October 2016 attacks against Dyn showed that a business can keep its servers running and still lose public reachability when DNS resolution fails upstream; the accountability question is who had practical control over provider concentration, DDoS absorption, failover design…

Global Cloud Services
Fortinet made edge-appliance patching a customer-risk accountability test
Fortinet's FortiGate vulnerability record is not only a story about one critical CVE or one emergency patch cycle. It is a test of how a security appliance vendor, customers, managed-service providers, and government responders prove that a product placed at the edge of the…
