Trick or Treating, Cyber Villains, and Coffee: My Time on Counsel Brew

I recently had the pleasure of joining Shereen El Domeiri and Nicola Hobeiche on their fantastic podcast, Counsel Brew, for Episode 36: “Trick or Treat – Shawn Tuma.” Let me tell you—it was an absolute blast! From the moment we hit record, it felt like catching up with old friends over a strong French roast. …

Privilege Requires Precision: Sixth Circuit’s Reminder for Internal Investigations

In a recent decision, the Sixth Circuit offered a timely reminder for legal teams conducting internal investigations: attorney-client privilege is powerful—but only when used with precision. In In re FirstEnergy Corp., No. 24-3654, 2025 WL 1234567 (6th Cir. Aug. 7, 2025), the court examined whether FirstEnergy could shield communications related to its internal investigation into alleged misconduct. …

DFW Area Friends – Join Me to Talk Real World Cyber Incident Response and Preparation at Tech Titans’ Cybersecurity Forum

Your organization has been breached, now what? That’s the title of our discussion at Tech Titans’ Cybersecurity Forum this Thursday, December 14, 2023, from 3:30 – 6:00 PM in Richardson, Texas. This event is available for both members of Tech Titans and non-menbers and you can register at this link: https://business.techtitans.org/events/details/cybersecurity-forum-december-14-2023-4826?calendarMonth=2023-12-01 I will be moderating …

HHS Releases HPH Sector Cybersecurity Framework Implementation Guide to Help Healthcare Organizations Leverage NIST Cybersecurity Framework

On March 8, 2023, the U.S. Department of Health and Human Services (HHS) released its HPH Sector Cybersecurity Framework Implementation Guide (the Guide) to help healthcare organizations leverage the NIST Cybersecurity Framework. This Guide is not only a must-read for all healthcare “covered entities,” especially small and midsize organizations, but it is excellent advice for …

FBI, CISA, MS-ISAC Joint Cybersecurity Advisory – #StopRansomware: LockBit 3.0

The Federal Bureau of Investigation (FBI), the Cybersecurity and Infrastructure Security Agency (CISA), and the Multi-State Information Sharing & Analysis Center (MS-ISAC) routinely release a Joint Cybersecurity Advisory (CSA) as part of an ongoing #StopRansomware effort to publish advisories for network defenders that detail ransomware variants and ransomware threat actors. On March 16, 2023, they …

OCR Releases Video Guidance on Recognized Security Practices for National Cybersecurity Awareness Month

On October 31, 2022, the U.S. Department of Health and Human Services Office of Civil Rights provided guidance titled OCR Releases New Recognized Security Practices Video. This guidance is not only a must-read for all healthcare “covered entities,” especially small and midsize organizations, but it is excellent advice for all organizations — healthcare and non-healthcare …

OCR Guidance on HIPAA Security Rule Security Incident Procedures for National Cybersecurity Awareness Month

On October 25, 2022, the U.S. Department of Health and Human Services Office of Civil Rights in its October 2022 OCR Cybersecurity Newsletter provided guidance titled HIPAA Security Rule Security Incident Procedures. This guidance is not only a must-read for all healthcare “covered entities,” especially small and midsize organizations, but it is excellent advice for …

Security Incidents and Your Board Pt.3 – The Above Board Show

“Data is the hot potato!” – Shawn Tuma It was great to be a guest on The Above Board Show hosted by my friends Gary Latham, Raf Los, and Grant Sewell where we discussed what “The Board” needs to know about security incidents and getting prepared for the worst day ever for the company. The …

Cyber Incident Response Preparation and Your Board Pt.2 – The Above Board Show

“Amateurs talk about strategy and tactics. Professionals study logistics.” – General Omar Bradley It was great to be a guest on The Above Board Show hosted by my friends Raf Los and Grant Sewell where we discussed what “The Board” needs to know about security incidents and getting prepared for the worst day ever for …

Security Incidents and Your Board Pt.1 – The Above Board Show

It was great to be a guest on The Above Board Show hosted by my friends Raf Los and Gary Latham where we discussed what “The Board” needs to know about security incidents and getting prepared for the worst day ever for the company. The video linked below was part 1 of a 3 part …