Jamie Tolles, Jamie Elbert, Nicholas Cramer

Session Time: Fri, Nov 6, 2026: 11:30 AM-12:30 PM

Nothing was encrypted. Nothing went down. Nothing broke. It is still a full-scale legal event: notification obligations, regulatory exposure, an extortion demand, and a cyber claim that looks nothing like the ransomware scenario the response plan was written for. Attackers now steal and extort without deploying ransomware, moving through compromised identities, legitimate applications, and trusted third parties. An incident responder, breach counsel, and a cyber claims professional follow one modern intrusion from initial access to notification.
Discussion topics include:
  • How attackers bypass identity controls through help desk social engineering, vishing, MFA resets, adversary-in-the-middle phishing, and session token theft, and what that does to the MFA attestation on your insurance application
  • Investigating data theft across SaaS platforms and third-party providers, where evidence is fragmented, logging is thin, and the attacker’s activity is indistinguishable from authorized use
  • Why data scoping becomes the largest line item in the response, and the cost of “we could not rule it out”: over-notification, review expense, and regulatory scrutiny
  • Which provisions in a traditional response plan assume encryption and business interruption, and how to rewrite them for identity compromise, SaaS data theft, and extortion without a decryptor

Jamie Tolles, Vice President, Incident Response, IDX
Nicholas Cramer, Vice President, Cyber Solutions, IDX
Jamie Elbert, Director, ZwillGen

Reading Materials:

 

Jamie Elbert

Attorney
ZwillGen

Jamie Tolles

Vice President, Incident Response
IDX

Nicholas Cramer

Vice President, Cyber Solutions
IDX