Obsidia Casebooks
Authoritative public case studies of the world's most consequential cybersecurity incidents, built so the field can stop repeating its disasters.
Colonial Pipeline Casebook
Our first Obsidia Casebook is in final preparation. It will pair the public-record case study with recommendations, practitioner perspectives, and a companion tabletop exercise.
What a case study contains
Every Obsidia report follows the same anatomy so the library is comparable, citable, and teachable.
Executive summary
The concise account of what happened, why it matters, and what the report concludes.
Background and context
The operating, policy, and threat environment needed to understand the incident.
Verified timeline
A dated sequence of public-record facts, separated from inference and uncertainty.
The decisions
The material choices leaders and responders faced as the incident unfolded.
Findings on root cause
The technical, organizational, and governance conditions that made the event possible.
What worked
The controls, judgments, partnerships, and practices that reduced harm.
Open questions
The facts the public record does not yet answer, kept visible rather than filled in.
Recommendations
Practical lessons for boards, security teams, policymakers, and educators.
Practitioner perspectives
Field-tested interpretation from security leaders who have managed comparable risks.
Discussion questions
Prompts for classrooms, boardrooms, and tabletop exercises.
Appendices and source list
The cited record behind the analysis, organized for review and correction.
The opening body of work.
Colonial Pipeline
The ransomware attack that shut fuel delivery to the American Southeast and brought ransomware into every household conversation. The opening Obsidia report pairs the full case study with a companion tabletop exercise.
Salt Typhoon
The telecommunications compromise whose federal investigation was halted when the Cyber Safety Review Board was dissolved. The Casebook will preserve and update the public record as it develops.
SolarWinds
The campaign that prompted the federal board's creation, with a rich public record across testimony, litigation, and policy response.
Change Healthcare
The ransomware attack that disrupted American healthcare payments nationwide and made the human cost of cyber incidents visible at national scale.
MOVEit
The mass exploitation of a single file-transfer product across thousands of organizations, with deep litigation and disclosure records.
CrowdStrike Outage
A non-attack disaster with published root-cause analysis, testimony, and litigation. Its inclusion makes the safety-board lineage plain: the lesson matters more than the villain.