Primary Domain
Risk and Accountability
Within the Primary Domain facet, Risk and Accountability intelligence groups reporting by primary domain so readers can follow a focused area of internet infrastructure, governance, connectivity markets, or digital capital. The page brings together related articles, public evidence, institutions, companies, people, regional exposure, operating dependencies, and market context that may otherwise sit across separate category pages. It explains the domain, the likely actor class, the market or governance context, and the source material readers should use when comparing signals. Operators, analysts, and governance readers can see how the same domain appears across events, profiles, market shifts, public-source evidence, regional dependencies, and longer-cycle infrastructure decisions over time.

Global Institutional
Delta turned the CrowdStrike outage into a recovery-duty and supplier-liability test
Delta Air Lines did not cause the faulty security-content update that disabled Windows endpoints across the world on July 19, 2024. That fact matters, but it is not the end of the accountability question. Delta's slower recovery turned a supplier incident into an airline…

Global Cloud Services
Fujitsu Horizon and the supplier record behind a public-accounting scandal
The Horizon scandal is often told as a Post Office prosecution story, and that is right as far as the human harm and institutional power are concerned. But it is also a supplier-accountability story. Fujitsu and its predecessors operated the system, support knowledge, defect…

Global Institutional
NHS England and WannaCry: the patching failure that became a care-continuity test
WannaCry did not expose a single forgotten patch so much as a distributed accountability system that could issue guidance, detect danger, and still fail to prove that local organisations had acted before patient care depended on it. The NHS England case matters because the outage…

Global Cloud Services
Dyn showed that DNS outsourcing can become a common-mode failure
The 2016 Dyn attack did not take down the internet. It did something narrower and more instructive: it made many otherwise healthy services unreachable because a shared authoritative DNS provider was overwhelmed. The accountability question is therefore not only who launched a…

Global Cloud Services
Akamai and the false positive that made edge security an availability risk
A protective control can fail in two directions. It can miss hostile traffic, or it can misclassify legitimate traffic and make a working site unreachable to the people it is supposed to protect. Akamai's public record now contains both kinds of accountability signal: a 2026 Bot…

Global National Telecom
Pakistan Telecom and the YouTube route hijack that escaped a national filter
The 2008 YouTube route hijack began as a national blocking instruction and became a global routing failure because the internet's control plane accepted a more specific announcement from the wrong origin. Pakistan Telecom originated a route for part of YouTube's address space.…

Global Institutional
JBS made ransomware a food-supply continuity question
The 2021 JBS ransomware incident was not only a corporate extortion case. It was a short, sharp test of how a concentrated meat processor, public agencies, producers, workers, retailers and customers absorb uncertainty when plant operations depend on centralized digital trust.…

Global Institutional
Viasat KA-SAT and the satellite outage that exposed wartime dependency
The 2022 KA-SAT disruption showed that satellite broadband is not an abstract space asset once it is used for war-zone connectivity, rural internet service, wind-farm operations and government dependency. The satellite itself did not have to be destroyed for the service to fail.…

Global Institutional
Garmin and the ransomware outage that turned wearables into service infrastructure
Garmin's July 2020 cyberattack was remembered as a ransomware outage, but the more durable lesson is about service infrastructure hidden inside consumer devices. Fitness users could keep recording workouts, pilots could keep using installed avionics, and marine and outdoor…

Global Institutional
Medibank made health insurance data a continuing accountability record
Medibank's 2022 cyberattack was not a one-day privacy event. It became a continuing record of who controlled remote access, sensitive data retention, customer notification, ransom refusal, identity support, regulator evidence, sanctions attribution and litigation risk after…

Global National Telecom
Optus and the outage that made emergency calling a carrier accountability test
Optus did not merely lose connectivity on 8 November 2023. It showed how a national carrier's internal network-change controls, emergency-call fallback assumptions, out-of-band management design, customer communications, reseller coordination, and regulator-facing evidence can…

Global Cloud Services
CDK Global showed how dealer software becomes local business infrastructure
The CDK Global cyberattack was not only a software vendor outage. It was a live test of how much local commerce, dealership finance, repair scheduling, parts inventory, customer records, automaker workflows, and employee productivity had been concentrated inside a…

Global Institutional
Johnson Controls turned building technology ransomware into a continuity question
The 2023 Johnson Controls ransomware incident was not only an enterprise IT event. It was a test of how a global building-technology supplier proves resilience when its internal systems, customer-facing platforms, product assurance obligations and public-facility customers all…

Global Institutional
Travelex and the ransomware outage that exposed outsourced currency-service dependency
The 2020 Travelex ransomware disruption was not only a story about a foreign-exchange brand knocked offline at the worst possible time. It was a dependency failure for banks, supermarkets, airport desks, travelers, employees, creditors and outsourced service customers who…

Global Institutional
Honda and the ransomware interruption that linked office IT to factory continuity
Honda's June 2020 cyberattack was not only an office-network event and not only a plant-floor story. Honda later told investors that the attack widely affected personal computers when they accessed Honda's internal system and temporarily suspended business operations at several…

Global Institutional
Merck and NotPetya: when malware loss became an insurance accountability test
Merck's NotPetya record is not another generic malware morality play. It is a pharmaceutical-continuity and insurance-wording case with unusually concrete public evidence: SEC filings quantified sales and manufacturing effects; a New Jersey appellate opinion described the malware…

Global Institutional
FedEx TNT and NotPetya: the logistics cost of inheriting cyber risk
FedEx did not merely suffer a malware incident at a newly purchased subsidiary. The June 2017 NotPetya attack exposed the governance problem that comes with buying a live logistics network before its identity, booking, finance, customer-service and recovery controls have been…

Global Institutional
Nissan's cyber incident made customer-data governance part of automotive resilience
Nissan's Australia and New Zealand cyber incident was not only a regional ransomware-and-data story. It showed how vehicle retail, finance, insurance, service history, identity documents, outsourced call-center support and global brand governance can become one accountability…

Global Institutional
ICANN made the DNSSEC root key rollover a public test of operational accountability
ICANN's first DNSSEC root key-signing-key rollover was not only a cryptographic maintenance event. It was a rare global exercise in changing a shared trust anchor while millions of recursive resolvers, public agencies, enterprises, software vendors, registries, ISPs and end users…

Global Cloud Services
DigiCert's revocation deadline turned certificate validation into an uptime accountability test
DigiCert's 2024 domain-validation bug was not only a certificate-authority compliance episode. It showed how one missing underscore in a DNS-based validation path could force thousands of organizations to choose, under a public Web PKI deadline, between rapid certificate…
