After the Ceasefire: Cyber Threats from Nation-State Actors Persist, but Security Basics can Help Protect Your Business

Goering Center Blog

2026

After the Ceasefire: Cyber Threats from Nation-State Actors Persist, but Security Basics can Help Protect Your Business

After the Ceasefire: Cyber Threats from Nation-State Actors Persist, but Security Basics can Help Protect Your Business

During my years in the FBI’s Cyber Division, we had a mantra that we repeated hundreds if not thousands of times, “Cybersecurity is national security.” At this point it is well-established that government-backed hackers are targeting the private sector just as much as our government networks. For example, in March of 2026, the pro-Iran hacking group “Handala” was linked to the cyberattack on medical equipment and technology provider, Stryker. The intent behind this “wiper” attack, which erased data but did not seek an extortion payment, appears to have been purely retaliatory. Within the last six months alone, federal cybersecurity agencies have issued public warnings about Russia-affiliated groups targeting the wastewater, food and agriculture, and energy sectors and Chinese-government linked covert networks built from compromised small-office-home-office (SOHO) routers, Internet of Things (IoT), and smart devices. 

For a family business, it can be daunting to think your cybersecurity challenges include going up against some of the most sophisticated government-sponsored hackers on earth. Protecting your business and your customers breaks down into two categories; prevention and response.

Applying Cybersecurity Fundamentals is an Effective Defense

Cyber-resilience planning and security remain a highly effective risk-management strategy—no matter who the adversary is. Here are five steps your business can start today to strengthen your security and resilience:

  • Build a comprehensive inventory of your data “crown jewels” like proprietary intellectual property or personally identifiable information.
  • Eliminate the use of default or shared passwords on devices like home-office routers or IoT devices.
  • Encrypt data at rest and in transit.
  • Educate your employees on how to spot phishing or social engineering attempts and what to do when they happen.
  • Invest in planning how your business will respond to and recover from a cyber incident.

Responding to a Cyber Incident

Even when you seemingly make all the right moves to protect your networks, compromises can and do still happen. If you know or suspect your network has been breached, you can act quickly to control the damage by:

  • Activating your incident response plan. Don’t wait until you are “sure” you have a breach. If it’s reasonable to suspect a compromise has occurred, then activate the plan—you can always stand down.
  • Simplifying the response by making decisions ahead of time. There are many parts of an incident response that can be set up ahead of time establishing who within the company will make key decisions, anticipating and preparing communications to employees or customers, and identifying the team members inside and outside the organization who will need to be involved.
  • Immediately notifying key external team members who can help. A call to trusted, experienced cyber breach attorneys and your cyber insurance carrier is an excellent place to start.
  • Moving to out-of-band communications channels for conversations about the breach. If the threat actor has compromised your email system, then they are reading your communications and they know your response strategy.

Protecting your networks and your data from malicious cyber activity is a complicated endeavor, which requires a team approach. Should you have any questions or needs related to data privacy and cybersecurity, please do not hesitate to reach out to one of our data privacy and cybersecurity attorneys at Dinsmore.