<?xml version="1.0" encoding="UTF-8"?><?xml-stylesheet href="https://feeds.captivate.fm/style.xsl" type="text/xsl"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0" xmlns:googleplay="http://www.google.com/schemas/play-podcasts/1.0" xmlns:itunes="http://www.itunes.com/dtds/podcast-1.0.dtd" xmlns:sy="http://purl.org/rss/1.0/modules/syndication/" xmlns:podcast="https://podcastindex.org/namespace/1.0"><channel><atom:link href="https://feeds.captivate.fm/behind-the-breach/" rel="self" type="application/rss+xml"/><title><![CDATA[Behind the Breach]]></title><podcast:guid>756fe0f2-4c38-52f7-9711-2ead46d0cc6a</podcast:guid><lastBuildDate>Tue, 08 Sep 2026 15:00:21 +0000</lastBuildDate><generator>Captivate.fm</generator><language><![CDATA[en]]></language><copyright><![CDATA[Copyright 2026 Cowbell]]></copyright><managingEditor>Cowbell</managingEditor><itunes:summary><![CDATA[Behind the Breach takes you inside the moments that define a cyber incident.  Each episode walks through a real or simulated breach step by step — from detection to containment to recovery — with insights from incident response experts on what actually happens when systems go down and decisions matter most.  Designed for insurance brokers, business leaders, and anyone responsible for managing cyber risk, the series explores not just how breaches unfold, but what organizations can do to respond with clarity and control.]]></itunes:summary><image><url>https://artwork.captivate.fm/d035e16b-b893-42ca-a4c6-0063e3ab1aef/CB-PodcastThumbnail-2800px.png</url><title>Behind the Breach</title><link><![CDATA[https://behind-the-breach.captivate.fm]]></link></image><itunes:image href="https://artwork.captivate.fm/d035e16b-b893-42ca-a4c6-0063e3ab1aef/CB-PodcastThumbnail-2800px.png"/><itunes:owner><itunes:name>Cowbell</itunes:name></itunes:owner><itunes:author>Cowbell</itunes:author><description>Behind the Breach takes you inside the moments that define a cyber incident.  Each episode walks through a real or simulated breach step by step — from detection to containment to recovery — with insights from incident response experts on what actually happens when systems go down and decisions matter most.  Designed for insurance brokers, business leaders, and anyone responsible for managing cyber risk, the series explores not just how breaches unfold, but what organizations can do to respond with clarity and control.</description><link>https://behind-the-breach.captivate.fm</link><atom:link href="https://pubsubhubbub.appspot.com" rel="hub"/><itunes:subtitle><![CDATA[Real cyber incidents, unpacked for brokers and business leaders.]]></itunes:subtitle><itunes:explicit>false</itunes:explicit><itunes:type>episodic</itunes:type><itunes:category text="Business"></itunes:category><itunes:category text="Business"><itunes:category text="Management"/></itunes:category><podcast:locked>no</podcast:locked><podcast:medium>podcast</podcast:medium><item><title>The Ransomware Negotiation Leaked to the Press</title><itunes:title>The Ransomware Negotiation Leaked to the Press</itunes:title><description><![CDATA[<p>Orders are missing. Customers are asking questions. Online rumors begin spreading before the company fully understands what has happened.</p><p>Then investigators confirm ransomware.</p><p>In this episode of <em>Behind the Breach</em>, host Amber Wuollet follows a fictionalized ransomware scenario involving a major retailer as an internal incident becomes increasingly public. Employee and customer data is released online. Frontline employees are expected to answer questions while dealing with the exposure of their own personal information. Then the company’s private negotiation with the threat actor is leaked to the press.</p><p>She’s joined by Callum Laidlaw, Partner at Kekst CNC, to walk through the communications challenges that emerge over the following months—from early customer speculation and regulatory communications to data exposure, customer notifications, leaked negotiations, and the unexpected arrival of law enforcement.</p><p>Together, they explore how organizations can communicate under pressure without moving ahead of the facts, support employees who are both responders and victims, and maintain trust as new developments repeatedly bring the incident into public view.</p><p>In this episode:</p><ul><li>What organizations should be monitoring before a crisis begins</li><li>Why communicating too quickly can create additional problems</li><li>How communications teams work alongside legal counsel and regulators</li><li>What customer-facing employees need to respond clearly and consistently</li><li>How to support employees when their personal data is exposed</li><li>How to respond when a private ransom negotiation is leaked</li><li>Why organizations may be judged less for experiencing a cyber incident than for how they handle it</li></ul><br/><p><em>Behind the Breach</em> is a Cowbell podcast exploring what happens inside a cyber incident—and what organizations can learn before one happens to them.</p><p><strong>Guest:</strong> Callum Laidlaw, Partner, Kekst CNC</p><p><strong>Host:</strong> Amber Wuollet, Director of Product &amp; Lifecycle Marketing, Cowbell</p><p><strong>Disclaimer:</strong> This episode is for informational purposes only and does not constitute legal, insurance, or cybersecurity advice.</p>]]></description><content:encoded><![CDATA[<p>Orders are missing. Customers are asking questions. Online rumors begin spreading before the company fully understands what has happened.</p><p>Then investigators confirm ransomware.</p><p>In this episode of <em>Behind the Breach</em>, host Amber Wuollet follows a fictionalized ransomware scenario involving a major retailer as an internal incident becomes increasingly public. Employee and customer data is released online. Frontline employees are expected to answer questions while dealing with the exposure of their own personal information. Then the company’s private negotiation with the threat actor is leaked to the press.</p><p>She’s joined by Callum Laidlaw, Partner at Kekst CNC, to walk through the communications challenges that emerge over the following months—from early customer speculation and regulatory communications to data exposure, customer notifications, leaked negotiations, and the unexpected arrival of law enforcement.</p><p>Together, they explore how organizations can communicate under pressure without moving ahead of the facts, support employees who are both responders and victims, and maintain trust as new developments repeatedly bring the incident into public view.</p><p>In this episode:</p><ul><li>What organizations should be monitoring before a crisis begins</li><li>Why communicating too quickly can create additional problems</li><li>How communications teams work alongside legal counsel and regulators</li><li>What customer-facing employees need to respond clearly and consistently</li><li>How to support employees when their personal data is exposed</li><li>How to respond when a private ransom negotiation is leaked</li><li>Why organizations may be judged less for experiencing a cyber incident than for how they handle it</li></ul><br/><p><em>Behind the Breach</em> is a Cowbell podcast exploring what happens inside a cyber incident—and what organizations can learn before one happens to them.</p><p><strong>Guest:</strong> Callum Laidlaw, Partner, Kekst CNC</p><p><strong>Host:</strong> Amber Wuollet, Director of Product &amp; Lifecycle Marketing, Cowbell</p><p><strong>Disclaimer:</strong> This episode is for informational purposes only and does not constitute legal, insurance, or cybersecurity advice.</p>]]></content:encoded><link><![CDATA[https://behind-the-breach.captivate.fm]]></link><guid isPermaLink="false">618b23be-db3c-479e-8524-46baf581d145</guid><itunes:image href="https://artwork.captivate.fm/d035e16b-b893-42ca-a4c6-0063e3ab1aef/CB-PodcastThumbnail-2800px.png"/><pubDate>Tue, 08 Sep 2026 10:00:00 -0500</pubDate><enclosure url="https://episodes.captivate.fm/episode/618b23be-db3c-479e-8524-46baf581d145.mp3" length="21535938" type="audio/mpeg"/><itunes:duration>14:56</itunes:duration><itunes:explicit>false</itunes:explicit><itunes:episodeType>full</itunes:episodeType><itunes:season>1</itunes:season><itunes:episode>4</itunes:episode><podcast:episode>4</podcast:episode><podcast:season>1</podcast:season></item><item><title>The Help Desk Call That Cost $24 Million</title><itunes:title>The Help Desk Call That Cost $24 Million</itunes:title><description><![CDATA[<p>A locked account. A routine help desk call. A password reset that appeared to follow the process.</p><p>Then $24 million in insurance payments went to the wrong account.</p><p>In this episode of Behind the Breach, host Amber Wuollet follows an anonymized healthcare scenario involving a large organization where a threat actor gains access through a help desk call, moves through internal systems, and changes payment information inside an insurance portal.</p><p>She’s joined by DJ Hoeksema, Head of Managed Security Services at SpearTip, a Zurich company, to walk through how the incident unfolded — from the initial password reset, to the payment diversion, to the investigation that followed.</p><p>Together, they explore why identity-based attacks can be difficult to detect, how attackers take advantage of trusted workflows, and what organizations can learn from a case where each individual step appeared routine until the financial impact became impossible to ignore.</p><p>In this episode:</p><ul><li>Why social engineering is effective against help desk workflows</li><li>How exposed personal information can weaken identity verification</li><li>What threat actors look for once they gain access to an account</li><li>Why changes inside business portals can be difficult to detect</li><li>How delayed discovery can make fund recovery harder</li><li>What incident responders look for when reconstructing the timeline</li><li>How organizations can strengthen help desk processes after an incident</li></ul><br/><p>Behind the Breach is a Cowbell podcast exploring what happens inside a cyber incident — and what organizations can learn before one happens to them.</p><p><strong>Guest: </strong>DJ Hoeksema, Head of Managed Security Services, SpearTip, a Zurich company</p><p><strong>Host: </strong>Amber Wuollet, Director of Product &amp; Lifecycle Marketing, Cowbell</p><p><strong>Disclaimer: </strong>This episode is for informational purposes only and does not constitute legal, insurance, or cybersecurity advice.</p>]]></description><content:encoded><![CDATA[<p>A locked account. A routine help desk call. A password reset that appeared to follow the process.</p><p>Then $24 million in insurance payments went to the wrong account.</p><p>In this episode of Behind the Breach, host Amber Wuollet follows an anonymized healthcare scenario involving a large organization where a threat actor gains access through a help desk call, moves through internal systems, and changes payment information inside an insurance portal.</p><p>She’s joined by DJ Hoeksema, Head of Managed Security Services at SpearTip, a Zurich company, to walk through how the incident unfolded — from the initial password reset, to the payment diversion, to the investigation that followed.</p><p>Together, they explore why identity-based attacks can be difficult to detect, how attackers take advantage of trusted workflows, and what organizations can learn from a case where each individual step appeared routine until the financial impact became impossible to ignore.</p><p>In this episode:</p><ul><li>Why social engineering is effective against help desk workflows</li><li>How exposed personal information can weaken identity verification</li><li>What threat actors look for once they gain access to an account</li><li>Why changes inside business portals can be difficult to detect</li><li>How delayed discovery can make fund recovery harder</li><li>What incident responders look for when reconstructing the timeline</li><li>How organizations can strengthen help desk processes after an incident</li></ul><br/><p>Behind the Breach is a Cowbell podcast exploring what happens inside a cyber incident — and what organizations can learn before one happens to them.</p><p><strong>Guest: </strong>DJ Hoeksema, Head of Managed Security Services, SpearTip, a Zurich company</p><p><strong>Host: </strong>Amber Wuollet, Director of Product &amp; Lifecycle Marketing, Cowbell</p><p><strong>Disclaimer: </strong>This episode is for informational purposes only and does not constitute legal, insurance, or cybersecurity advice.</p>]]></content:encoded><link><![CDATA[https://behind-the-breach.captivate.fm]]></link><guid isPermaLink="false">358d9c63-ba1c-41ce-b269-adc184859e3d</guid><itunes:image href="https://artwork.captivate.fm/d035e16b-b893-42ca-a4c6-0063e3ab1aef/CB-PodcastThumbnail-2800px.png"/><pubDate>Mon, 29 Jun 2026 20:25:00 -0500</pubDate><enclosure url="https://episodes.captivate.fm/episode/358d9c63-ba1c-41ce-b269-adc184859e3d.mp3" length="20774381" type="audio/mpeg"/><itunes:duration>14:22</itunes:duration><itunes:explicit>false</itunes:explicit><itunes:episodeType>full</itunes:episodeType><itunes:season>1</itunes:season><itunes:episode>3</itunes:episode><podcast:episode>3</podcast:episode><podcast:season>1</podcast:season></item><item><title>Crisis the Week Before Christmas</title><itunes:title>Crisis the Week Before Christmas</itunes:title><description><![CDATA[<p>The week before Christmas is the busiest time of year for BrightSpark Toys. Orders are moving, warehouses are running around the clock, and every delay carries a cost.</p><p>Then systems start going down.</p><p>In this episode of <em>Behind the Breach</em>, host Amber Wuollet follows a fictionalized ransomware scenario involving a mid-sized toy manufacturer and distributor during its peak holiday season. She’s joined by Dominik Cvitanovic, breach counsel and attorney at Wilson Elser, to walk through the first seven days of the incident — from the first signs of trouble, to ransomware confirmation, attacker communication, legal considerations, and the pressure of restoring operations under uncertainty.</p><p>Together, they explore what happens when a ransom note appears, data may be at risk, and the threat actor suddenly goes silent mid-negotiation.</p><p>In this episode:</p><ul><li>Why incident response planning matters before systems go offline</li><li>How cyber insurance can help connect organizations with expert support</li><li>Why ransomware response involves legal, financial, operational, and reputational decisions</li><li>What organizations should consider before engaging with a threat actor</li><li>Why the first week can shape the direction of the response</li></ul><br/><p><em>Behind the Breach</em> is a Cowbell podcast exploring what happens inside a cyber incident — and what organizations can learn before one happens to them.</p><p><strong>Guest:</strong> Dominik Cvitanovic, Attorney at Law, Wilson Elser</p><p><strong>Host:</strong> Amber Wuollet, Director of Product &amp; Lifecycle Marketing, Cowbell</p><p><strong>Disclaimer:</strong> This episode is for informational purposes only and does not constitute legal, insurance, or cybersecurity advice.</p>]]></description><content:encoded><![CDATA[<p>The week before Christmas is the busiest time of year for BrightSpark Toys. Orders are moving, warehouses are running around the clock, and every delay carries a cost.</p><p>Then systems start going down.</p><p>In this episode of <em>Behind the Breach</em>, host Amber Wuollet follows a fictionalized ransomware scenario involving a mid-sized toy manufacturer and distributor during its peak holiday season. She’s joined by Dominik Cvitanovic, breach counsel and attorney at Wilson Elser, to walk through the first seven days of the incident — from the first signs of trouble, to ransomware confirmation, attacker communication, legal considerations, and the pressure of restoring operations under uncertainty.</p><p>Together, they explore what happens when a ransom note appears, data may be at risk, and the threat actor suddenly goes silent mid-negotiation.</p><p>In this episode:</p><ul><li>Why incident response planning matters before systems go offline</li><li>How cyber insurance can help connect organizations with expert support</li><li>Why ransomware response involves legal, financial, operational, and reputational decisions</li><li>What organizations should consider before engaging with a threat actor</li><li>Why the first week can shape the direction of the response</li></ul><br/><p><em>Behind the Breach</em> is a Cowbell podcast exploring what happens inside a cyber incident — and what organizations can learn before one happens to them.</p><p><strong>Guest:</strong> Dominik Cvitanovic, Attorney at Law, Wilson Elser</p><p><strong>Host:</strong> Amber Wuollet, Director of Product &amp; Lifecycle Marketing, Cowbell</p><p><strong>Disclaimer:</strong> This episode is for informational purposes only and does not constitute legal, insurance, or cybersecurity advice.</p>]]></content:encoded><link><![CDATA[https://behind-the-breach.captivate.fm]]></link><guid isPermaLink="false">c274c3b3-d4e3-4752-a7e6-c8b2394b77f0</guid><itunes:image href="https://artwork.captivate.fm/d035e16b-b893-42ca-a4c6-0063e3ab1aef/CB-PodcastThumbnail-2800px.png"/><pubDate>Fri, 22 May 2026 14:30:00 -0500</pubDate><enclosure url="https://episodes.captivate.fm/episode/c274c3b3-d4e3-4752-a7e6-c8b2394b77f0.mp3" length="18322325" type="audio/mpeg"/><itunes:duration>12:39</itunes:duration><itunes:explicit>false</itunes:explicit><itunes:episodeType>full</itunes:episodeType><itunes:season>1</itunes:season><itunes:episode>2</itunes:episode><podcast:episode>2</podcast:episode><podcast:season>1</podcast:season></item><item><title>Inside the First 24 Hours of a Breach</title><itunes:title>Inside the First 24 Hours of a Breach</itunes:title><description><![CDATA[<p>When a ransomware attack hits, the first 24 hours shape how an organization responds.</p><p>In this episode of <em>Behind the Breach</em>, we walk through a simulated cyber incident in real time — following a fictional company from initial detection through containment, investigation, and the path toward stability.</p><p>Joined by Cowbell’s Resiliency Services leaders, Matthieu Chan Tsin and Joe Hoosech, this episode explores what actually happens inside an organization during a breach — not in theory, but in practice.</p><p>You’ll hear:</p><ul><li>What the earliest signs of an attack look like</li><li>How teams move from detection to containment</li><li>The role of incident response planning in the first hours</li><li>How forensic investigations begin</li><li>What stability looks like after the initial disruption</li></ul><br/><p>This is a narrative walkthrough designed to help brokers and business leaders better understand how cyber incidents unfold — and how response takes shape in real time.</p><p><em>Behind the Breach</em> is a Cowbell podcast exploring what happens inside a cyber incident — and what organizations can learn before one happens to them.</p><p><strong>Guest:</strong> Matthieu Chan Tsin, Head of Resiliency Services, Cowbell, and Joe Hoosech, Principal, Cowbell Resiliency Services–Incident Response</p><p><strong>Host:</strong> Amber Wuollet, Director of Product &amp; Lifecycle Marketing, Cowbell</p><p><strong>Disclaimer:</strong> This episode is for informational purposes only and does not constitute legal, insurance, or cybersecurity advice.</p>]]></description><content:encoded><![CDATA[<p>When a ransomware attack hits, the first 24 hours shape how an organization responds.</p><p>In this episode of <em>Behind the Breach</em>, we walk through a simulated cyber incident in real time — following a fictional company from initial detection through containment, investigation, and the path toward stability.</p><p>Joined by Cowbell’s Resiliency Services leaders, Matthieu Chan Tsin and Joe Hoosech, this episode explores what actually happens inside an organization during a breach — not in theory, but in practice.</p><p>You’ll hear:</p><ul><li>What the earliest signs of an attack look like</li><li>How teams move from detection to containment</li><li>The role of incident response planning in the first hours</li><li>How forensic investigations begin</li><li>What stability looks like after the initial disruption</li></ul><br/><p>This is a narrative walkthrough designed to help brokers and business leaders better understand how cyber incidents unfold — and how response takes shape in real time.</p><p><em>Behind the Breach</em> is a Cowbell podcast exploring what happens inside a cyber incident — and what organizations can learn before one happens to them.</p><p><strong>Guest:</strong> Matthieu Chan Tsin, Head of Resiliency Services, Cowbell, and Joe Hoosech, Principal, Cowbell Resiliency Services–Incident Response</p><p><strong>Host:</strong> Amber Wuollet, Director of Product &amp; Lifecycle Marketing, Cowbell</p><p><strong>Disclaimer:</strong> This episode is for informational purposes only and does not constitute legal, insurance, or cybersecurity advice.</p>]]></content:encoded><link><![CDATA[https://behind-the-breach.captivate.fm]]></link><guid isPermaLink="false">c9357837-e533-46c6-95fe-3ba776ef665c</guid><itunes:image href="https://artwork.captivate.fm/d035e16b-b893-42ca-a4c6-0063e3ab1aef/CB-PodcastThumbnail-2800px.png"/><pubDate>Wed, 15 Apr 2026 16:30:00 -0500</pubDate><enclosure url="https://episodes.captivate.fm/episode/c9357837-e533-46c6-95fe-3ba776ef665c.mp3" length="18132736" type="audio/mpeg"/><itunes:duration>12:33</itunes:duration><itunes:explicit>false</itunes:explicit><itunes:episodeType>full</itunes:episodeType><itunes:season>1</itunes:season><itunes:episode>1</itunes:episode><podcast:episode>1</podcast:episode><podcast:season>1</podcast:season></item></channel></rss>