When Boom Hits: A Battle-Tested Blueprint for Cyber Resilience

By Haines Eason

Oct 3, 2025

Share this post

Cyberattacks aren’t a possibility—they’re a certainty. The real question is what happens next. At ChannelCon 2025, Trevor Hardy, CEO, NEXTGen IT, a disabled combat veteran and a man the industry calls “The Cyber Cowboy,” drove home one message: Survival depends less on technology and more on leadership.

“Cybersecurity resilience isn't a technology challenge; it’s fundamentally a leadership one. Your organization's ability to withstand and thrive through a cyber incident depends directly on the proactive leadership, a cultural preparedness and discipline execution of a robust cybersecurity strategy,” Hardy said.

Through hard-edged case studies and battle-tested practices, Hardy drew a sharp line between organizations that prepared and those that didn’t. The difference, he argued, is measured in millions of dollars, months of downtime and sometimes the very survival of a business.

Resilience Is a Leadership Test, Not a Tech Puzzle

Hardy’s framing borrows from military doctrine: “Left of Boom” and “Right of Boom.” “Boom” is the breach—the ransomware hit, the phishing email that gets through, the moment defenses fail. Left of Boom is preparation; Right of Boom is response.ChannelCon2025_2088-lowres (1) (1)

The key, Hardy argued, is accepting that boom is inevitable and preparing accordingly.

“If we can't get our own house in order, how do we get the house in order for our clients?” he asked.

For IT service providers (ITSPs), Hardy said this means moving beyond sales pitches about tools. It means enforcing tested backups, defining incident response roles and running regular war games.

Leadership—not luck—determines whether the lights stay on.

Related Content: ITSP in the Mirror: Do You Manage Your Security the Same You Do Your Clients?

Florence, Alabama: A City Brought to its Knees

Hardy relays a painful example: The City of Florence, Alabama, population 40,000. On June 5, 2020, ransomware from the DoppelPaymer group locked every city system by mid-afternoon. Emails stopped. Servers froze. The 911 system failed. Police dispatch shut down.

“By 2:00 p.m., every system—and I mean every system in this city—is now displaying a message telling visitors to go to a .onion site and deposit 33 Bitcoin,” Hardy recalled.

The disaster wasn’t just bad luck. It was compounded by negligence:

  • - The IT director himself opened the phishing email—while logged in as global admin
  • - Servers ran on unpatched 2008 software
  • - Backups were nothing more than Walmart-bought hard drives plugged directly into the network, also encrypted by the attack
  • - Alerts were ignored—even after cybersecurity journalist Brian Krebs personally called the city to warn that Florence’s credentials were for sale on the dark web.
  •  

Hardy says it took Florence 23 days to decide whether to pay ransom. They eventually paid—only to be hit again weeks later with a double extortion demand.

“Delayed responses are costly,” Hardy warned. Florence’s total fallout ran into millions, with Hardy bluntly calling it “The day the city went dark.”

Alliance Packaging: 20 Minutes From Panic to Productivity

Contrast Florence’s chaos with Alliance Packaging, a manufacturer in the same region that faced the exact same ransomware group.

“When the owner called, my wife answered the phone—and he was nearly screaming: ‘I need to speak to Trevor now.’ What he didn’t know is that our tools had already alerted us,” Hardy recalled.

Alliance Packaging’s fate flipped because of preparation:

  • - Immutable, incremental backups
  • - Defined response roles and regular disaster recovery tests
  • - Immediate virtualization of compromised servers
  •  

“They were fully operational in 20 minutes. Their only complaint was things were a little slow. Well, no kidding, you’re running off of a virtual machine in the cloud right now,” Hardy said, arms wide and laughing along with the audience.

What cost Florence millions cost Alliance less than $7,000—including the backup service subscription. Hardy notes the owner initially fought him for months over paying “a hundred-something dollars a month” for the backup box. But when ransomware hit, that small investment saved the business.

Counts Brothers: A Small Shop Learns the Hard Way

Hardy then spotlighted Counts Brothers, a family-run music store that had resisted backup solutions for years.

“He was dead set. He was not doing backups. I put in file-level backups and did not tell him about it,” Hardy admitted.

When ransomware locked the store’s systems, Counts Brothers was down for the weekend. But thanks to Hardy’s covert safeguard, they were back by Monday morning. The experience converted the owner instantly: “His immediate ask was, ‘Can I sign up for that now?’”

The lesson, Hardy said, is that no business is too small to be a target. Attackers don’t care if you’re a city, a manufacturer or a music shop. Every ITSP client must be treated as a target.

The Stats That Should Keep Every ITSP Awake at Night

Hardy punctuated his talk with industry stats that underscore the inevitability of attack:

  • - 86% of SMBs will suffer a cyberattack during their lifetime
  • - Only 20-40% will recover and remain profitable
  • - The average cost of an incident in the United States is $9.36 million
  • - The average lifecycle of a breach: 277 days
  • - Florence’s attackers were inside the city’s systems for 173 days before detection
  • - The average ransom payment now tops $2.7 million—yet paying often doubles the damage, as victims face secondary extortion
  •  

“These aren’t edge cases,” Hardy stressed.

“If you’ve got more than about 10 clients, it means you’ve got about an 800% chance that you’re going to run through an attack in your business at some point.”

Turning Chaos Into Discipline: Tabletop Drills, War Games and Real Playbooks

Preparation, Hardy argued, must be constant and disciplined. Annual tabletop exercises aren’t enough.

“We should be doing a tabletop exercise every quarter inside of your ITSP. You should be choosing one of your businesses at random during that. And once a year do a full scenario,” Hardy said.

Hardy’s approach is military-inspired: Flip the switch, kill the network and test whether people know their roles.

“We do war games so that if we find problems, we can fix problems before they become problems on a real battlefield,” he explained.

Hardy’s 90-day roadmap:

  • - Assign a clear cybersecurity lead within the ITSP.
  • - Audit and verify backups ensuring they’re immutable and ransomware-proof.
  • - Conduct internal disaster recovery tests.
  • - Schedule client tabletop exercises.
  • - Establish client communication plans for crisis response.
  •  

Vendor risk management also loomed large. Florence’s collapse spread to neighboring municipalities because of connected systems. Hardy warns ITSPs to vet third-party vendors just as aggressively as they secure their own networks.

Related Content: The Importance of Realistic Tabletop Exercises

Beyond the Breach: Thriving Right of Boom

In closing, Hardy underscored that perfection is impossible. With AI accelerating threats and ransomware groups evolving daily, the only path is continuous improvement.

“There is no such thing as perfection. It’s just going to be getting better and improving. That’s the best we can do,” Hardy said. The differentiator, he argued, is trust. ITSPs who invest in training, testing and teaching will retain clients; those who cut corners will be the next Florence.

“Resilience is leadership. Remember, cybersecurity resilience isn't a technology challenge. It's fundamentally a leadership one. Take charge, empower your teams and commit to continual learning,” Hardy said.

For ITSPs, that’s the only way to ensure that when boom happens—and it will—you bounce back stronger.

GTIA Members: Download Cybersecurity Guidebook for ITSPs: Tabletop Exercises to Build Customer Resilience and Preparedness on the Member Portal. 

Related Posts:

Crystal Conkle accepts the GTIA Spotlight Award
By GTIA / Apr 3, 2026

5 Questions with Crystal Conkle: 2026 GTIA Advancing Women in Technology Leadership Award Winner

Crystal Conkle’s leadership isn’t defined by a single initiative, but by the intentional, everyday work of expanding what’s possible for women in the IT channel. As the 2026 GTIA Advancing Women in Technology Leadership Spotlight Award winner in North America, she represents a new era of influence—one where visibility, authenticity and service-driven leadership are reshaping the industry from the inside out.
wooden people figures standing in a circle
By Pete Busam / Jan 7, 2026

Why Vendor-Agnostic Associations Strengthen the Tech Community

A vendor-agnostic technology association creates a space where learning, collaboration and leadership emerge from shared experience rather than commercial influence. In today’s channel ecosystem, where messaging is often guided by product interest or sales intent, the value of a community-first, vendor-neutral environment has never been more important.