The Founding Program

Obsidia Casebooks

Authoritative public case studies of the world's most consequential cybersecurity incidents, built so the field can stop repeating its disasters.

Inaugural Casebook

Colonial Pipeline Casebook

Our first Obsidia Casebook is in final preparation. It will pair the public-record case study with recommendations, practitioner perspectives, and a companion tabletop exercise.

Coming Soon!
Open the Colonial Pipeline Casebook

What a case study contains

Every Obsidia report follows the same anatomy so the library is comparable, citable, and teachable.

Report Section

Executive summary

The concise account of what happened, why it matters, and what the report concludes.

Report Section

Background and context

The operating, policy, and threat environment needed to understand the incident.

Report Section

Verified timeline

A dated sequence of public-record facts, separated from inference and uncertainty.

Report Section

The decisions

The material choices leaders and responders faced as the incident unfolded.

Report Section

Findings on root cause

The technical, organizational, and governance conditions that made the event possible.

Report Section

What worked

The controls, judgments, partnerships, and practices that reduced harm.

Report Section

Open questions

The facts the public record does not yet answer, kept visible rather than filled in.

Report Section

Recommendations

Practical lessons for boards, security teams, policymakers, and educators.

Report Section

Practitioner perspectives

Field-tested interpretation from security leaders who have managed comparable risks.

Report Section

Discussion questions

Prompts for classrooms, boardrooms, and tabletop exercises.

Report Section

Appendices and source list

The cited record behind the analysis, organized for review and correction.

Year One Slate

The opening body of work.

2021
Inaugural Full Case Study

Colonial Pipeline

The ransomware attack that shut fuel delivery to the American Southeast and brought ransomware into every household conversation. The opening Obsidia report pairs the full case study with a companion tabletop exercise.

2024 to present
Preliminary Public Record Report

Salt Typhoon

The telecommunications compromise whose federal investigation was halted when the Cyber Safety Review Board was dissolved. The Casebook will preserve and update the public record as it develops.

2019 to 2021
Supply Chain Espionage

SolarWinds

The campaign that prompted the federal board's creation, with a rich public record across testimony, litigation, and policy response.

2024
Healthcare Concentration Risk

Change Healthcare

The ransomware attack that disrupted American healthcare payments nationwide and made the human cost of cyber incidents visible at national scale.

2023
Mass Exploitation

MOVEit

The mass exploitation of a single file-transfer product across thousands of organizations, with deep litigation and disclosure records.

2024
Systemic Failure

CrowdStrike Outage

A non-attack disaster with published root-cause analysis, testimony, and litigation. Its inclusion makes the safety-board lineage plain: the lesson matters more than the villain.

Opening report: Colonial Pipeline launches the format end to end, including the full case study, recommendations, practitioner perspectives, and a companion tabletop exercise.
The Obsidia Project
Independent public-interest infrastructure for cybersecurity learning.
info@obsidiaproject.org
obsidiaproject.org