With the month closed, the documented incidents have different origins and converge on a small set of measures that would have changed the outcome in nearly all of them.
The first is an integration inventory. In several cases the entry path was a connected supplier, and the problem starts when nobody can list which integrations are active and what each one reaches.
The second is backups tested with a full restore. A backup never restored is a hypothesis, and the moment to discover that can't be during the incident.
The third is decisions taken in advance: whether you negotiate, who authorises switching off a system, who speaks to customers, and what gets said while the size of the problem is still unknown.
The fourth is the calendar. Systems have known, public seasonality, and attackers choose the window where it hurts most. Maintenance and testing have to happen off-peak, and the ability to operate in degraded mode has to exist before the window opens.
None of these measures requires a large company's budget, and none of the month's cases would have been prevented by a new tool alone.
