ACTIVE INCIDENT? CONTACT US
ACTIVE INCIDENT? ENGAGE TEAM
Sector Threat Briefings

Threat Models
Don't Read Org Charts.

A hospital, a factory floor, and a law firm fail in completely different ways under attack. We map the real breach patterns hitting your sector, then close the specific gaps — not generic ones.

$7.42M avg. healthcare breach cost +56% YoY rise in manufacturing ransomware $725M lost to cargo theft in 2025 20% of law firms hit in the past year €10M max NIS2 fine for essential entities 88% of SMB breaches involve ransomware 279 days avg. healthcare breach dwell time 98% encryption rate when government is hit

Healthcare

Securing the heartbeat of connected medicine.

A HIPAA binder and a GDPR policy won't stop a ransomware affiliate already inside your EHR. We test, harden, and respond to the specific way attackers hit hospitals, clinics, and health-tech vendors.

The Reality
Average cost of a healthcare data breach — highest of any industry
Ransomware incidents reported against U.S. healthcare in 2025
Individuals affected by one 2024 ransomware attack on a claims platform
Average time to detect and contain a healthcare breach

One compromised login without multi-factor authentication took a national prescription-processing network offline for weeks and cost its parent company north of $3 billion in direct response spend. The same failure mode — a single privileged account, no MFA, no segmentation — is sitting in most hospital networks today.

Where it actually breaks
  • ▸ Business-associate and vendor blast radius — third-party involvement in healthcare breaches has doubled in a year.
  • ▸ Legacy connected medical devices and imaging systems that can't run modern endpoint agents.
  • ▸ "We passed our HIPAA audit" mistaken for "we are secure" — paperwork and adversarial reality diverge fast.
  • ▸ Short-staffed IT teams running 24/7 clinical operations with no dedicated security function.

EU / EEA note: Healthcare is named an essential entity under the NIS2 Directive — qualifying providers and health-tech vendors face fines up to €10M or 2% of global turnover for inadequate security, plus personal liability for management. Patient data breaches simultaneously trigger GDPR Article 9 exposure given its "special category" classification.

Manufacturing

Zero downtime. Zero compromise.

Your production line doesn't care about your ISO certificate. It cares whether the PLC controlling it can be reached from an unpatched laptop on the same flat network.

The Reality
Ransomware attacks on manufacturers in 2025 — up 56% year over year
Of all global ransomware incidents now land on manufacturing
Average cost of one hour of production downtime
Of financial loss driven by ransomware, despite being only 12% of claims

Across five years of manufacturing insurance claims data, the single most expensive point of failure wasn't a zero-day or a nation-state exploit — it was multi-factor authentication that was deployed but misconfigured. Attackers don't need to be sophisticated when the basics are missing.

Where it actually breaks
  • ▸ IT/OT convergence without segmentation — one compromised office laptop reaches the factory floor.
  • ▸ Legacy PLCs and SCADA systems that can't be patched without halting production.
  • ▸ Third-party remote access tools installed for vendor maintenance, never audited again.
  • ▸ Flat, unsegmented networks engineered for uptime, not containment.

EU / EEA note: Most manufacturers fall under NIS2 as "important entities" (up to €7M or 1.4% of turnover). Producers of medical devices, electronics, and machinery are frequently classified as essential — the same €10M / 2% exposure as critical infrastructure.

Logistics

Supply chains never sleep. Neither do the threats.

A load board doesn't check IDs. Neither does your carrier onboarding form — and attackers know exactly how to exploit that gap.

The Reality
Lost to cyber-enabled cargo theft in the US/Canada in 2025, +60% YoY
Ransomware attacks on transport & logistics firms in 2025 alone
Of sector ransomware victims were trucking and freight operators
Of all sector attacks came from just four ransomware groups

A 158-year-old UK logistics operator collapsed into administration after a ransomware attack that began with one weak password. Backups were encrypted along with everything else. 700 jobs lost, 500 trucks disabled overnight — the company could neither meet the ransom nor operate without its systems.

Where it actually breaks
  • ▸ Fragmented broker/carrier ecosystems and load boards with little identity verification.
  • ▸ Real-time GPS and OT tracking systems exposed to spoofing and takeover.
  • ▸ Sprawl of EDI, customs, and warehouse-management integrations — each its own attack surface.
  • ▸ Near-zero tolerance for downtime creates outsized pressure to pay ransom fast.

EU / EEA note: Transport is a named essential-entity sector under NIS2 — full €10M / 2% turnover exposure, with a mandatory 24-hour initial incident notification window, stricter than GDPR's 72 hours.

Prof. Services

Defending the vault of privileged intelligence.

Law firms, accountants, and consultancies hold concentrated secrets — deal terms, financials, privileged strategy — defended by teams sized for a much smaller threat model.

The Reality
Of ransomware victims in late 2025 were professional-services firms — the most-targeted sector
Of law firms report being targeted in the past year; 56% of those lost client data
Average breach cost at a law firm, up 10% year over year
Of firms have a tested incident response plan in place

Threat actors now call staff directly, posing as internal IT, and simply talk them through installing a remote access tool. No malware, no exploit — just a convincing phone call. Firms that vet their own people with the same scrutiny they'd apply to a software vendor catch this before data ever leaves the building.

Where it actually breaks
  • ▸ The "trusted advisor" blind spot — firms hold crown-jewel client data but are rarely security-vetted like a vendor would be.
  • ▸ Vishing and callback phishing that bypasses email filters entirely.
  • ▸ Reliance on plain email over secure client portals for sensitive document exchange.
  • ▸ Thin or absent incident response planning relative to the sensitivity of what's stored.

EU / EEA note: GDPR exposure is acute given the volume of client and case-related personal data firms hold. NIS2's supply-chain provisions increasingly pull professional-services firms into the compliance obligations of the essential and important entities they advise.

Public Sector

Hardening the foundation of civil infrastructure.

Public bodies carry the heaviest regulatory exposure in Europe and some of the thinnest security budgets anywhere. NIS2 was written with this sector specifically in mind.

The Reality
Maximum NIS2 fine — public administration is a named essential entity
Data-encryption rate when government ransomware attacks succeed — highest of any sector
YoY rise in ransomware against government bodies, H1 2025
Formal compliance notices issued by one national authority in a single quarter

A national legal aid agency's breach forced its digital services offline entirely — no online applications, no payments, no case processing — until systems were manually restored. When public infrastructure fails, there's no competitor for citizens to switch to.

Where it actually breaks
  • ▸ Legacy, monolithic systems running mission-critical services with no modern segmentation.
  • ▸ Procurement cycles too slow to react to a fast-moving threat landscape.
  • ▸ No dedicated CISO or security function across many mid-sized agencies and municipalities.
  • ▸ Political pressure to restore services fast, sometimes overriding sound incident response.

EU / EEA note: NIS2 Article 20 makes management personally liable for cybersecurity governance failures — including temporary bans from management functions in cases of gross negligence. This sits directly on top of existing GDPR obligations for citizen data.

Not Listed?

Attackers don't check your NAICS code either.

Ransomware groups don't target "industries." They target exposed RDP ports, reused passwords, and unpatched CVEs — wherever they find them. If you run critical operations, hold client data, or simply can't afford downtime, this applies to you.

Of small and mid-sized business breaches now involve ransomware
Growth in supply-chain attacks 2021–2023; now 30% of all breaches involve a third party
Average global cost of a data breach in 2025, regardless of sector
Also under active coverage
SaaS & Technology Retail & E-commerce Financial Services & Fintech Real Estate Hospitality & Travel Education Energy & Utilities Nonprofits & NGOs Construction Media & Entertainment

We build the threat model around your actual attack surface — your identity stack, your vendor list, your exposed services — not a generic template pulled from your industry code.

Get A Straight Answer

Send This To Us

Talk Through Your Threat Model.

Whatever's on your industry badge, we start the same way: mapping the specific way your organization could actually be breached, then closing that gap first.

Location Tallinn, Estonia • Remote First
Coverage All Sectors, EU/EEA Focus
Response Initial response within 8-12 hours

Direct Inquiry

Encrypted & Standard Channels
Primary Contact
contact@sc.consulting
Signal Protocol
Element Matrix
Initiate Assessment