The Thread
Four stories logged this week look unrelated: ransomware crews hunting backup infrastructure, OneSpan pushing electronic signature deeper into bank workflows, Anthropic loosening classifier restrictions for vetted security teams, and an extortion hack at Asos that reached customers directly. The common thread is that the security industry's implicit trust assumptions - that backups are out of reach, that a signature marks the end of a process, that safety classifiers can be tuned without cost, that an internal system breach stays internal - are the actual attack surface. Attackers and defenders are now contesting those assumptions rather than the products built on top of them.
Backups Stop Being a Refuge
BleepingComputer's report on ransomware groups targeting backup infrastructure is the clearest expression of the pattern. For years, the standard recovery advice assumed backups sat outside the blast radius. Ransomware operators have inverted that: rather than only encrypting production systems, they go after the recovery path itself, removing the victim's alternative to paying. Kaseya's guidance - isolated, immutable, and regularly tested backups - is not new advice, but the fact that it needs restating in 2026 indicates how many organizations still treat backup as a storage problem rather than a security boundary.
The implication for US technology companies is that "we have backups" is no longer a meaningful answer to a board or an insurer. The meaningful questions are whether those backups are reachable from the same identity plane as production, whether they can be deleted or encrypted by a compromised admin account, and whether anyone has actually restored from them recently. Backup vendors have spent years selling capacity and speed. The market is now being asked to sell isolation and immutability, which are architectural properties, not features.
Signatures Are a Step, Not a Solution
OneSpan's update to its Sign service, as reported by SiliconANGLE, is a smaller story with the same shape. The company is explicitly aiming at "the parts of the agreement process that slow down banks," acknowledging that electronic signing has become expected and therefore no longer differentiating. The value has moved to the workflow around the signature: identity verification, approvals, audit trails, and the handoffs between systems that still run on manual effort.
That is the same lesson as the backup story in a different register. The signature was never the security guarantee; it was a marker that a process had reached a certain point. Banks and their vendors are now being pushed to secure the process itself. For US financial institutions, which operate under overlapping state and federal expectations about records and authentication, this matters because the compliance question is shifting from "was this signed electronically" to "can you demonstrate who approved what, in what order, and under whose authority." Vendors that only handle the signing step are selling a commodity.
Safety Classifiers Meet Dual-Use Reality
Anthropic's expansion of its Cyber Verification Program into three tiers, folding in Project Glasswing, is the most interesting entry because it is a vendor conceding that a control it built is misaligned with a legitimate use case. SiliconANGLE reports that the company treats cybersecurity as dual use, so generally available models carry conservative classifiers, and the new tiers grant vetted security teams progressively fewer blocks on cybersecurity work.
This is the trust-assumption pattern applied to AI. The assumption behind conservative classifiers is that restricting output is cheap and safe. In practice, security teams doing legitimate defensive work - and, plausibly, offensive research under contract - hit those restrictions constantly, which pushes them toward models with fewer guardrails or toward self-hosted alternatives. The tiered structure is an attempt to preserve the safety posture while recovering the professional market. Whether tiering works depends entirely on verification: who vets the teams, against what standard, and what happens when a vetted team's access is abused. None of that is answered by the announcement itself, and US enterprises evaluating AI vendors for security work should treat the verification process, not the tier names, as the thing to scrutinize.




