When seven different responders and law firms were thrown into the same ransomware negotiation chat by a threat actor, Eder Ribeiro, Director of Global Incident Response at TransUnion, it became his framework for managing global incident response: map the data, map the people, and look as holistically as possible before acting. To do this, executive trust must be built long before the 3AM phone call requiring million-dollar decisions. Eder breaks down complex security issues "Barney style" and with empathy, remembering that instruction works best when adapted to how the audience receives it, not how the teacher wants to give it.
For emerging AI risks, he's tracking prompt injection as the attack vector that creates a more linear path to data, particularly in enterprise bundle add-ons that sit in the gray zone between public tools and properly isolated solutions. When investigations spiral, he returns to "control the controllables," reset without finger-pointing, and compress what should take weeks into days. His military-informed leadership philosophy centers on generating agency and freedom for his team, accepting that incident response inherently lacks balance and compensating through daily autonomy.
Learning holistic incident response through multi-responder ransomware coordination requiring collaborationBuilding executive trust through "Barney style" communication that adapts technical concepts to how leadership receives informationDeveloping IR leaders through time-based training requiring exposure to diverse stakeholder reactions rather than seeking unicorn hiresMapping both data and people as critical incident response variables beyond traditional digital tooling and endpoint visibilityControlling the controllables during spiraling incidents by resetting without blame and compressing investigation timelinesTracking prompt injection as emerging AI attack vector creating linear data access paths through enterprise bundle add-onsGenerating agency and freedom as leadership philosophy compensating for incident response's inherent lack of work-life balanceRetraining security awareness beyond grammar errors as AI-powered phishing eliminates traditional detection indicators