A mid-size medical practice lost more than $700,000 and exposed 12,000 patients' protected health information because their IT company built an environment that worked but was never secured. Open RDP. A departed employee's active account. No MFA. No monitoring. No cyber insurance. The attacker didn't need to be good. The door was open.
A commercial mechanical contractor was never broken into and never had a dollar stolen from its accounts. A phished field-tech password, a domain anyone could forge, and an IT vendor who sold configuration as though it were a product turned the company's own email into a weapon against its customers, its suppliers, its bank, and its attorney. The abuse kept going after every password was changed. The controls that would have stopped it were almost all free. Nobody was there to say so.
An 85-employee manufacturer lost $287,000, a $1.4 million annual client, and an insurance claim. The controls that would have caught it were a line item nobody signed.