1 min read
The Importance of Event Logging in Cybersecurity: A Guide to Best Practices
With a growing range of cyber threats, from ransomware to sophisticated phishing schemes, organizations must develop a comprehensive cybersecurity...
4 min read
Totalcare IT
:
Updated on July 9, 2026
The phrase comes from the military — specifically from IED response training, where "the boom" is the detonation event. Everything you do before the explosion is Left of Boom: intelligence gathering, route planning, detection, prevention. Everything after is Right of Boom: casualty response, forensics, lessons learned.
Security teams adopted the framework because it maps cleanly onto the two fundamentally different jobs in cybersecurity. And for a business owner trying to think through whether their defenses are actually complete, it's one of the most useful mental models available.
Most businesses are lopsided. They've invested in Left of Boom — firewalls, antivirus, maybe some training — and have almost nothing Right of Boom. No tested incident response plan. No clean, verified backup. No documented breach notification process. They've built a wall but no plan for what happens if someone gets over it.
The goal is balance. Here's what each side actually looks like for an operationally-critical business in Idaho.
Left of Boom is everything you do before an attack lands. The goal isn't perfection — no environment is impenetrable — it's making your business hard enough to breach that attackers move on to easier targets.
According to Verizon's 2026 Data Breach Investigations Report, software vulnerabilities are now the leading cause of breaches, surpassing stolen credentials for the first time. Unpatched operating systems, applications, and network firmware are open doors. Left of Boom means having a systematic process — not manual, not "when someone remembers" — for keeping endpoints, servers, and network devices current.
For manufacturers with industrial equipment connected to your IT network, this includes OT firmware. If your CNC machines, PLCs, or SCADA systems are running outdated software and connected to your office network, they're a vulnerability.
The principle is simple: employees should only have access to what they need for their job, and every access point should require more than a password. Multi-factor authentication on email, VPN, cloud applications, and your ERP is a baseline control that cyber insurance carriers now require and that eliminates a significant percentage of credential-based attacks.
Least-privilege access also matters when an employee leaves. If offboarding isn't immediate and complete — all accounts disabled, all access revoked — you have an ongoing exposure with every departure.
Traditional antivirus matches known threats against a signature database. Modern malware is often designed specifically to evade signature-based detection. EDR tools monitor behavioral patterns instead — flagging suspicious activity even from threats that have never been seen before. For businesses that have had antivirus installed for years and assumed they were covered, EDR is a meaningful upgrade.
If every device on your network can communicate with every other device, a compromised laptop has a path to your server, your ERP, your backup system, and your production equipment. Segmentation limits that blast radius. It's especially important in manufacturing environments where IT and OT systems share physical infrastructure but have very different security profiles.
Most breaches start with a human decision — someone clicked something, entered credentials somewhere they shouldn't have, or got socially engineered into a wire transfer. Regular training combined with realistic phishing simulations is measurably more effective than annual checkbox training. The goal is building a reflex to pause and verify, not just inform people of the rules once a year.
Your Left of Boom controls only cover your environment. If a software vendor, equipment supplier, or IT contractor has remote access to your systems, their security posture becomes part of yours. Vendor risk management — knowing who has access, what they can reach, and what their security practices look like — is a Left of Boom discipline that most businesses underinvest in.
Right of Boom is everything that happens after an incident occurs. The goal isn't to avoid the situation — you can do everything right on the Left side and still get hit. The goal is to minimize damage, restore operations fast, and come out stronger.
The most expensive mistakes in a breach happen in the first hour, made by people who aren't sure what they're supposed to do. An incident response plan documents the decisions in advance: who gets called, in what order, what gets isolated, what gets preserved, who has authority to make calls.
Without a plan, a ransomware event turns into a chaotic all-hands situation where someone turns off the infected server (destroying forensic evidence), someone else pays the ransom without legal counsel, and nobody notifies affected parties until days later — when notification windows have closed.
A plan doesn't have to be long. It has to exist, be tested, and be findable when you need it.
Backups are Right-of-Boom infrastructure. Their entire purpose is what happens after something goes wrong. And they're only as useful as the recovery speed they enable.
Two questions matter: how current is your last clean backup (your RPO — recovery point objective), and how fast can you restore full operations from it (your RTO — recovery time objective)? For a manufacturer mid-production run, a two-day recovery is a crisis. Know your numbers and make sure your backup architecture actually supports them. Tested, image-based backups that can be spun up remotely are the difference between recovering in hours and recovering in days.
After a security incident, you likely have obligations that start running from the moment of discovery — not from when you've finished the investigation. Idaho's breach notification law, HIPAA's 60-day notification window for healthcare organizations, and CMMC requirements for defense contractors all have specific timelines and notification requirements.
Understanding these obligations before an incident — not during one — is Right of Boom preparation. It belongs in your incident response plan and should involve your legal counsel.
After containment and recovery, the most valuable thing you can do is understand exactly what happened: how the attacker got in, how long they were present, what they accessed, and what controls failed. That forensic analysis closes the vulnerabilities that led to the breach and informs your Left-of-Boom investments going forward.
Boom is also a feedback loop. The Right side feeds back into the Left.
Most businesses, if they examined their cybersecurity posture honestly, would find they have partial Left-of-Boom coverage and almost no Right-of-Boom infrastructure. Some have a firewall and antivirus and call it done. Some have backups but haven't tested them in a year. Almost none have a documented, tested incident response plan.
The businesses that recover well from incidents aren't necessarily the ones that had perfect prevention. They're the ones that knew what to do when it happened.
TotalCare IT provides managed cybersecurity services for manufacturers, engineering firms, and other operationally-critical businesses in Boise, Idaho Falls, and throughout the Treasure Valley and East Idaho — covering both sides of the boom. Talk to our team if you want an honest look at where your gaps are.
1 min read
With a growing range of cyber threats, from ransomware to sophisticated phishing schemes, organizations must develop a comprehensive cybersecurity...
1 min read
The recent Supreme Court decision to overrule the Chevron Doctrine has introduced significant uncertainty into the regulatory landscape, particularly...
1 min read
In the digital age, data is the lifeblood of businesses. It fuels operations, decision-making, and customer interactions. But there is a dark...