A security program can look complete while critical exposures remain. Policies may exist without consistent enforcement. Assessments may miss systems, dependencies, or failure scenarios. The cases below were selected for their documented business consequences—not ranked as equivalent measures.
Consequences take different forms.
Change Healthcare, 2024
UnitedHealth’s 2024 annual report records $2.2 billion in direct response costs and an estimated $867 million in business disruption impacts—approximately $3.1 billion combined for that year. Provider loan principal should not be added as if it were a loss.
Leadership question: Have critical dependencies, control coverage, and recovery assumptions been demonstrated across the acquired environment?
UnitedHealth 2024 Form 10-KMGM Resorts, 2023
MGM estimated an approximately $100 million negative impact on September adjusted property EBITDAR and reported less than $10 million in one-time expenses incurred during the quarter. The figures were preliminary, and the company expected insurance coverage.
Leadership question: Does the risk view account for operational interruption—not only data exposure?
MGM October 5, 2023 Form 8-KEquifax, 2017
The 2019 global settlement required at least $575 million, potentially up to $700 million. Shares closed down 13.7% on September 8, 2017, following disclosure. A short-term share-price reaction is not proof of permanent loss attributable solely to the breach.
Leadership question: Can the organization demonstrate coverage, escalation, and accountability—not only policy intent?
FTC Equifax case summaryYahoo / Verizon, 2017 transaction
The acquisition price was reduced by $350 million following disclosed breaches. Verizon’s subsequent annual report states that the 2013 breach affected all Yahoo accounts.
Leadership question: Could cyber findings change transaction economics, risk allocation, or the integration plan?
Amended transaction announcementMarriott / Starwood, disclosed 2018
Marriott shares fell 5.6% on November 30, 2018. The disclosed intrusion began in 2014, before Marriott acquired Starwood in 2016. Marriott subsequently revised the original affected-record estimate.
Leadership question: What inherited exposure could remain in an acquired environment before and after close?
Marriott incident announcementThe deeper question is what was demonstrated.
Public evidence points to specific control and governance gaps. UnitedHealth’s CEO acknowledged missing multifactor authentication on the access point implicated in the Change Healthcare attack. The FTC alleged failures at Equifax to confirm critical patching and maintain adequate segmentation. The SEC found Yahoo failed to maintain adequate disclosure controls and appropriately assess breach information that reached senior management and legal personnel.
These records do not justify claiming that every company had a mature program, knowingly accepted the same risks, or received an incorrect assessment. Severe outcomes can reflect unknown risk, poor assumptions, inadequate remediation, weak execution, or genuine residual risk.
From reporting to decision-quality evidence.
The practical lesson is not that policies, metrics, and assessments lack value. It is that leadership needs to understand their boundaries: which assets were covered, what evidence was tested, how exceptions are handled, whether failure scenarios have been rehearsed, and what remains uncertain.
Independent scrutiny is most useful when it does more than assign a score. It should clarify what is known, what is assumed, what is outside scope, and what decision should follow.