Explore every episode of the podcast Behind the Breach
| Title | Pub. Date | Duration | |
|---|---|---|---|
| The Help Desk Call That Cost $24 Million | 30 Jun 2026 | 00:14:22 | |
A locked account. A routine help desk call. A password reset that appeared to follow the process. Then $24 million in insurance payments went to the wrong account. In this episode of Behind the Breach, host Amber Wuollet follows an anonymized healthcare scenario involving a large organization where a threat actor gains access through a help desk call, moves through internal systems, and changes payment information inside an insurance portal. She’s joined by DJ Hoeksema, Head of Managed Security Services at SpearTip, a Zurich company, to walk through how the incident unfolded — from the initial password reset, to the payment diversion, to the investigation that followed. Together, they explore why identity-based attacks can be difficult to detect, how attackers take advantage of trusted workflows, and what organizations can learn from a case where each individual step appeared routine until the financial impact became impossible to ignore. In this episode:
Behind the Breach is a Cowbell podcast exploring what happens inside a cyber incident — and what organizations can learn before one happens to them. Guest: DJ Hoeksema, Head of Managed Security Services, SpearTip, a Zurich company Host: Amber Wuollet, Director of Product & Lifecycle Marketing, Cowbell Disclaimer: This episode is for informational purposes only and does not constitute legal, insurance, or cybersecurity advice. | |||
| The Week Before Christmas | 22 May 2026 | 00:12:39 | |
The week before Christmas is the busiest time of year for BrightSpark Toys. Orders are moving, warehouses are running around the clock, and every delay carries a cost. Then systems start going down. In this episode of Behind the Breach, host Amber Wuollet follows a fictionalized ransomware scenario involving a mid-sized toy manufacturer and distributor during its peak holiday season. She’s joined by Dominik Cvitanovic, breach counsel and attorney at Wilson Elser, to walk through the first seven days of the incident — from the first signs of trouble, to ransomware confirmation, attacker communication, legal considerations, and the pressure of restoring operations under uncertainty. Together, they explore what happens when a ransom note appears, data may be at risk, and the threat actor suddenly goes silent mid-negotiation. In this episode:
Behind the Breach is a Cowbell podcast exploring what happens inside a cyber incident — and what organizations can learn before one happens to them. Guest: Dominik Cvitanovic, Attorney at Law, Wilson Elser Host: Amber Wuollet, Director of Product & Lifecycle Marketing, Cowbell Disclaimer: This episode is for informational purposes only and does not constitute legal, insurance, or cybersecurity advice. | |||
| Inside the First 24 Hours of a Breach | 15 Apr 2026 | 00:12:33 | |
When a ransomware attack hits, the first 24 hours shape how an organization responds. In this episode of Behind the Breach, we walk through a simulated cyber incident in real time — following a fictional company from initial detection through containment, investigation, and the path toward stability. Joined by Cowbell’s Resiliency Services leaders, Matthieu Chan Tsin and Joe Hoosech, this episode explores what actually happens inside an organization during a breach — not in theory, but in practice. You’ll hear:
This is a narrative walkthrough designed to help brokers and business leaders better understand how cyber incidents unfold — and how response takes shape in real time. Behind the Breach is a Cowbell podcast exploring what happens inside a cyber incident — and what organizations can learn before one happens to them. Guest: Matthieu Chan Tsin, Head of Resiliency Services, Cowbell, and Joe Hoosech, Principal, Cowbell Resiliency Services–Incident Response Host: Amber Wuollet, Director of Product & Lifecycle Marketing, Cowbell Disclaimer: This episode is for informational purposes only and does not constitute legal, insurance, or cybersecurity advice. | |||