Identity
- Enforce MFA on every remote access path — no exceptions
- Disable legacy auth protocols (IMAP, POP, basic auth)
- Pre-rotate privileged credentials before landfall
- Block sign-ins from anomalous geographies via conditional access
Normal Monitoring
No active threats. Standard operations.
Normal Monitoring
No active threats. Standard operations.
Threat Posture · All Phases
Threat actors exploit disruption. Phishing surges, credentials drift, and verification weakens precisely when staff is distracted. The defenders who win are the ones who hardened before, watched during, and verified after.
Phishing surge during storms
3–5x baseline
Median dwell time during chaos
11 days
Cost difference: drilled vs. not
60% lower
01 · Threat landscape
What attackers actually do when your business is distracted.
| Threat | Likelihood | Impact | Window |
|---|---|---|---|
Storm-themed phishing Impersonation of insurance carriers, utilities, FEMA, and your own IT department. Volume spikes 3–5x baseline. | High | High | T-72h through T+14d |
Credential stuffing on remote access Attackers know staff is working from unusual locations. They test reused credentials against VPN and SaaS portals. | High | Critical | During active storm |
Business email compromise Urgent wire transfer requests citing storm disruption. Bypasses normal approval because 'leadership is unreachable'. | Medium | Critical | T-24h through recovery |
Ransomware during recovery Attackers detonate during restoration when monitoring is degraded and pressure to restore overrides verification. | Medium | Critical | T+1d through T+30d |
Insider error under stress Misconfigurations, accidental data exposure, and approval shortcuts taken by exhausted staff. Often more damaging than external attacks. | High | Medium | All phases |
02 · Defensive depth
Defense in depth means an attacker has to beat all of these — not just one.
03 · By phase
Each phase has its own posture. The wrong move at the wrong time costs you.
Before
T-7 days to T-24h
During
Landfall to all-clear
After
All-clear to T+14 days
Our team will pressure-test your identity, backup, and detection posture against the storm-period threat matrix.