Security professionals monitor computer systems in a data center beside icons representing compliance, law, and governance.
Restoring systems after a ransomware attack is a milestone—not a certificate that the crisis is over. In the final installment of Halcyon’s 22 Days of Hell series, Kevin Gee turns attention to the work that survives the outage: security remediation, regulatory scrutiny, legal proceedings, insurance matters, and the pressure placed on the people handling them. The central warning is straightforward: business operations can resume while incident-related responsibilities continue for years.

Blackbaud’s experience gives that warning substance, but also requires a correction. Its records support a years-long aftermath, not a neat five-year endpoint at which every consequence disappeared. The distinction matters for enterprise IT leaders planning what happens after the recovery dashboard turns green.

Three workstreams, not one finish line​

Halcyon describes its final recovery phase as three overlapping burdens:

  • Hardening: addressing the weaknesses exposed by the incident.
  • Regulatory work: responding to inquiries and investigations.
  • Legal and insurance matters: handling claims and scrutiny of the response.

Gee also highlights a staffing problem: responders must absorb this work alongside ordinary security duties and the backlog accumulated during the emergency. Exhaustion and departures can make continuity harder just when the organization needs a reliable account of what happened. These are Halcyon’s operational observations, rather than quantified findings about every ransomware victim.

The useful management question is therefore not simply, “Are the systems back?” It is, “Who owns the remaining work, and what evidence will demonstrate that it is complete?”

Blackbaud’s aftermath had several different endpoints​

Independent records show how separate parts of a ransomware incident can remain active on different schedules.

Disclosure failures brought an SEC penalty​

On March 9, 2023, the Securities and Exchange Commission announced that Blackbaud had agreed to pay a $3 million civil penalty over misleading disclosures concerning its 2020 ransomware attack, which affected more than 13,000 customers. Blackbaud settled without admitting or denying the SEC’s findings.

The SEC found that Blackbaud initially said the attacker had not accessed donor bank-account information or Social Security numbers. Employees subsequently learned that such information had been accessed and exfiltrated, but that knowledge did not reach senior management responsible for public disclosures. An August 2020 quarterly filing then omitted the material information.

That finding adds an important lesson beyond backup restoration: technical discoveries need a dependable escalation path into corporate communications and disclosure decisions. In this case, the SEC identified a breakdown in that handoff—not merely the existence of a cyberattack.

State and federal settlements followed separate tracks​

Blackbaud announced another resolution on October 5, 2023: a $49.5 million settlement with 49 state attorneys general and the District of Columbia, including commitments to improve cybersecurity programs and tools. That announcement resolved the multistate investigation, not every incident-related matter.

The Federal Trade Commission subsequently finalized its order on May 20, 2024. The FTC described a settlement over allegations that security failures allowed a breach involving consumers’ personal information. Its requirements included deleting personal data Blackbaud no longer needed to retain.

Recovery, in other words, can involve reducing unnecessary retained data as well as improving defenses.

Class-action closure did not mean every claim was closed​

Blackbaud’s 2025 Form 10-K states that the court definitively closed the U.S. multidistrict litigation on September 22, 2025, resolving all customer-constituent class actions related to the incident. However, the same filing reported two customer-insurer subrogation cases still pending. Those statements describe the filing’s reporting point, not a verified October 2026 litigation status.

The narrower, supported conclusion is that the class-action proceedings extended into 2025 after the 2020 attack. Halcyon’s description of an aftermath resolved in “nearly five years” is too tidy: different matters ended at different times, and the annual filing still identified unresolved claims.

The financial record reinforces the distinction. As of December 31, 2025, Blackbaud reported $178.235 million in cumulative gross incident-related expenses, offset by $50 million in recognized insurance recoveries, leaving $128.235 million in cumulative net expense. These are Blackbaud’s reported figures—not a typical ransomware bill or an estimate of what another organization should expect.

What enterprise IT should carry into the handoff​

Official recovery guidance supports treating restoration and post-incident improvement as connected but distinct activities. CISA’s #StopRansomware Guide recommends restoring critical services carefully, preventing reinfection of clean systems, and documenting lessons learned to refine policies, response plans, procedures, and future exercises. It also emphasizes preserving volatile or retention-limited evidence, explicitly including Windows Security logs. Evidence preservation belongs during the response, not as an afterthought once machines have been rebuilt.

For Windows and enterprise administrators, the following is a practical management synthesis of that guidance and the documented Blackbaud experience—not a mandatory legal checklist:

  1. Separate operational restoration from remediation closure. Report restored services and unresolved security findings as different categories.
  2. Give each remaining finding an owner. Record its priority, target date, verification evidence, and any accepted residual risk.
  3. Maintain a discovery-to-disclosure handoff. Route material new findings to designated legal, communications, and executive owners rather than assuming an incident ticket reaches them.
  4. Preserve an accessible incident record. Keep the timeline, decisions, investigation findings, recovery validation, and supporting evidence together under appropriate access controls.
  5. Plan continuity beyond the original responders. Assign deputies and document unresolved questions so that a personnel change does not erase the organization’s memory of the incident.

The goal is not more paperwork for its own sake. It is a recovery process that another qualified person can understand, continue, and verify.

Keep the warning—but avoid the absolutes​

Halcyon’s broader assertions about lawsuits routinely arriving within days and CISOs often losing their jobs should not be treated as measured industry trends on the strength of this post alone. Nor do these records establish that a procedural mistake automatically produces an insurance denial or regulatory penalty.

Blackbaud provides strong evidence for a more precise conclusion: ransomware’s operational, regulatory, legal, and financial consequences can persist long after service restoration, with each following its own timetable. It does not establish that preparation is futile or that every organization faces the same duration and cost.

“Back online” should be a recovery milestone, not the organization’s only definition of closure. The better endpoint is a documented handoff: services restored, remaining risks understood, responsibilities assigned, and the people doing the work given a sustainable plan.

 

References

  1. Everyone Thinks the Attack Is Over. It Isn't. Not for Years - Halcyon.AI Halcyon.AI 2026-10-01T00:00:00+00:00
  2. #StopRansomware Guide | CISA cisa.gov
  3. Blackbaud Resolves Multi-State Attorneys General Investigation of 2020 Security Incident - Blackbaud blackbaud.com