Normal Monitoring

No active threats. Standard operations.

Threat Posture · All Phases

Attackers do not take days off. Neither should your defenses.

Threat actors exploit disruption. Phishing surges, credentials drift, and verification weakens precisely when staff is distracted. The defenders who win are the ones who hardened before, watched during, and verified after.

Phishing surge during storms

3–5x baseline

Median dwell time during chaos

11 days

Cost difference: drilled vs. not

60% lower

01 · Threat landscape

The storm-period threat matrix

What attackers actually do when your business is distracted.

ThreatLikelihoodImpact

Storm-themed phishing

Impersonation of insurance carriers, utilities, FEMA, and your own IT department. Volume spikes 3–5x baseline.

HighHigh

Credential stuffing on remote access

Attackers know staff is working from unusual locations. They test reused credentials against VPN and SaaS portals.

HighCritical

Business email compromise

Urgent wire transfer requests citing storm disruption. Bypasses normal approval because 'leadership is unreachable'.

MediumCritical

Ransomware during recovery

Attackers detonate during restoration when monitoring is degraded and pressure to restore overrides verification.

MediumCritical

Insider error under stress

Misconfigurations, accidental data exposure, and approval shortcuts taken by exhausted staff. Often more damaging than external attacks.

HighMedium

02 · Defensive depth

Six control layers worth hardening

Defense in depth means an attacker has to beat all of these — not just one.

Identity

  • Enforce MFA on every remote access path — no exceptions
  • Disable legacy auth protocols (IMAP, POP, basic auth)
  • Pre-rotate privileged credentials before landfall
  • Block sign-ins from anomalous geographies via conditional access

Email & Comms

  • Tighten inbound filtering thresholds 72 hours before landfall
  • Banner external email; quarantine domain look-alikes
  • Pre-brief staff on storm-themed lures with named examples
  • Require out-of-band verification for all wire and ACH changes

Endpoints

  • Confirm EDR healthy on every device that will go remote
  • Patch externally-facing systems before staff disperse
  • Block USB and unmanaged removable media
  • Force full-disk encryption on every mobile device

Data & Backups

  • Snapshot immutable backups within 24 hours of landfall
  • Verify offline / air-gapped copy of critical data
  • Test restore at least one critical system before the event
  • Document data classification and retention exceptions

Detection

  • Raise SOC alerting fidelity; reduce noise thresholds
  • Watch for impossible-travel and new device enrollments
  • Monitor for mass-download patterns from collaboration platforms
  • Hold change freeze on non-essential production deployments

Response

  • Pre-stage incident response retainer with named contacts
  • Confirm cyber insurance carrier notification path
  • Print incident runbook — do not rely on cloud-only access
  • Identify external counsel for breach communications

03 · By phase

What to do, when to do it

Each phase has its own posture. The wrong move at the wrong time costs you.

Before

Hardening window

T-7 days to T-24h

  • Run targeted phishing simulation with storm theme
  • Snapshot immutable backups; verify restore tested
  • Rotate all privileged and service account credentials
  • Brief every employee on the top 3 lures they will see

During

Vigilance window

Landfall to all-clear

  • Active SOC monitoring with reduced alert thresholds
  • Out-of-band verification on any financial change request
  • Change freeze — no non-essential production deploys
  • Hourly executive briefing on threat posture and anomalies

After

Verification window

All-clear to T+14 days

  • Forensic review of all logs across the event window
  • Rotate privileged credentials and revoke temporary access
  • Verify backup integrity and re-test restore on critical systems
  • After-action review with detection rule updates and lessons logged

Want a hardening review before the next named storm?

Our team will pressure-test your identity, backup, and detection posture against the storm-period threat matrix.