Independent Cyber Safety Casebooks

The field's public record, assembled in the open.

The Obsidia Project is an independent 501(c)(3) nonprofit dedicated to honoring the people who defend the digital world. Its founding program, the Obsidia Casebooks, creates authoritative public case studies of consequential cybersecurity incidents.

Why It Exists

Aviation learns from disaster because someone writes the report.

Cybersecurity has asked for this learning function for more than three decades. The Obsidia Casebook fills the empty seat with a nonprofit, public-record institution that outlives administrations and sells nothing.

Each report assembles the timeline, decisions, root causes, what worked, what remains unknown, and what the field should learn. Every factual claim is cited. Every judgment is attested. Every gap is admitted.

What We Produce

The Casebook turns scattered public records into working assets.

Full Reports

Authoritative Case Studies

Twenty-five to forty-five page case studies built from litigation, disclosures, testimony, advisories, post-mortems, journalism, and other public sources.

Teaching Editions

Classroom-Ready Cases

Condensed decision-forcing editions for university courses, professional training, and board education, licensed for free classroom use.

Tabletops

Monday-Morning Practice

Companion exercises drawn from real incidents so teams can test detection, decisions, communications, and recovery against events that already happened.

Each Casebook gives boards, security teams, policy leaders, and educators the same public-record account: what happened, why it mattered, what worked, and what should change.

Founding Slate

Six cases anchor the first year.

2021
Inaugural Full Case Study

Colonial Pipeline

The ransomware attack that shut fuel delivery to the American Southeast and brought ransomware into every household conversation. The opening Obsidia report pairs the full case study with a companion tabletop exercise.

2024 to present
Preliminary Public Record Report

Salt Typhoon

The telecommunications compromise whose federal investigation was halted when the Cyber Safety Review Board was dissolved. The Casebook will preserve and update the public record as it develops.

2019 to 2021
Supply Chain Espionage

SolarWinds

The campaign that prompted the federal board's creation, with a rich public record across testimony, litigation, and policy response.

2024
Healthcare Concentration Risk

Change Healthcare

The ransomware attack that disrupted American healthcare payments nationwide and made the human cost of cyber incidents visible at national scale.

2023
Mass Exploitation

MOVEit

The mass exploitation of a single file-transfer product across thousands of organizations, with deep litigation and disclosure records.

2024
Systemic Failure

CrowdStrike Outage

A non-attack disaster with published root-cause analysis, testimony, and litigation. Its inclusion makes the safety-board lineage plain: the lesson matters more than the villain.

Governance

Four editorial bodies, one standard.

01Editors write and own the work.
02Advisory Board members attest to facts and findings.
03Practitioners translate the case into current defense.
04Counsel guards the fairness and corrections process.
The Obsidia Project
Independent public-interest infrastructure for cybersecurity learning.
info@obsidiaproject.org
obsidiaproject.org