Damage Tolerance in IT: Finding the Weaknesses Before Attackers Do
In late April 2026, Instructure’s Canvas platform suffered a cybersecurity incident that resulted in unauthorized access to user data and service disruptions.
Canvas is used by schools and universities around the world to manage coursework, assignments, and grades.
The incident affected thousands of educational institutions, including universities and school systems in multiple countries. Attackers claimed to have stolen data from hundreds of millions of users – including messages between teachers and students, ranging from elementary school students to university students – and threatened to release it unless a ransom was paid.[Wikipedia Article]
The attackers claimed that the breach affected over 9,000 educational institutions around the world, including:[list]
Los Angeles Unified School District
University of California system
Harvard University
IBM Education
Queensland University (Australia)
University of Amsterdam (Netherlands)
Schools and other institutions responded by disabling access to Canvas, resulting in students being unable to access their coursework, submit assignments, or view grades for one or more days.
Breaches Aren’t Just a Problem for Large Organizations
Breaches aren’t limited to big targets like Instructure. Small companies are breached every day.
In August 2019, Wood Ranch Medical, a small medical practice in Simi Valley, CA, was attacked by ransomware. Patient data for 5,835 patients and the practice’s backups were encrypted. Unable to recover the data, Wood Ranch Medical permanently closed.
Wood Ranch wasn’t the only small company that shut down after a ransomware attack. Brookside ENT and Hearing Center in Battle Creek, MI, permanently closed in April 2019 after a ransomware attack in which the attackers demanded a $6,500 ransom that was not paid.[Security Week]
Financially motivated cybercriminal groups increasingly conduct campaigns targeting specific industries, including:[Lawfare]
Real Estate
Healthcare
Insurance
Transportation
Hospitality
Private Equity
Law firms
No matter your size, no matter your industry, your company is a target.
What Would a Breach Cost You?
How much would it cost you to be down for a day? A week?
Most organizations back up on a schedule, commonly daily. How much would it cost you to permanently lose a day’s worth of work?
Could you afford to have your emails and files – client data, source code, strategy notes, and other business information – stolen and sold to the highest bidder?
Could your company survive if all its data and backups were encrypted?
How do you prevent this before it happens?
Finding and Fixing Weaknesses Before They Become Failures
The Damage Tolerance philosophy of engineering addresses this problem. The idea is simple: assume weaknesses exist, continuously look for them, and fix them before they become failures. This philosophy is why airplanes, bridges, and other engineered systems are designed with regular inspections to detect problems before they become failures.
Inspecting an F-16 (source)
In IT, finding these weaknesses begins with vulnerability assessments and continues through ongoing monitoring and remediation.
Vulnerability assessments analyze your environment for missing security updates, outdated software, exposed services, misconfigurations, overprivileged accounts, and other conditions that attackers can exploit.
Attack path analysis builds on vulnerability assessments to identify chains of vulnerabilities that could allow an attacker to move from an initial foothold to administrative access on critical systems and infrastructure, enabling them to disrupt operations, sell your data to the highest bidder, or encrypt your systems to hold them for ransom.
Attack path analysis helps IT teams focus remediation efforts on vulnerabilities that create realistic attack paths instead of simply prioritizing based on severity scores.
After identifying vulnerabilities, the second step in reducing the risk of a breach is remediating them.
Patch management can automate testing, approving, and applying patches to fix software vulnerabilities. It reduces the need for administrators to log into individual computers to patch system and application software manually, speeding up deployment of updates, easing the load on IT staff, and reducing the amount of time your systems are vulnerable.
Of course, not all vulnerabilities can be fixed by just patching. A skilled IT team is necessary to interpret vulnerability assessments, understand attack paths, correct misconfigurations, and patch complex software. SIA helps organizations understand their security risks and remediate the weaknesses that expose them to attack.
Vulnerability assessments find the open doors. Attack path analysis shows how attackers can use those doors. Patch management helps close the doors before attackers can exploit them. A skilled IT team closes the doors that patches cannot close.