From Health 201FailSystems

how automated healthcare fails, how you'd know, and what to do at each tier — every claim sourced, reviewed continuously


Layer 3 of 5

Devices & electronics

The monitors, pumps, ventilators, sensors and analyzers that measure and act on patients, and the software and updates that run them.

Reviewed 26 September 2026Sources checked when written 26 September 2026 Involved in 13 of 39 incidents58 sources (54 primary or secondary)

What this layer is

This layer is the equipment at the bedside, in the lab and in the patient's home: physiologic monitors, pulse oximeters, infusion pumps, ventilators, continuous glucose monitors, point-of-care and lab analyzers, and the endpoint software (operating systems, security agents, interface adapters) that now runs on or beside them. Nearly all of it is software-driven, networked, and updated by a vendor after installation.

Devices fail in two ways. Loud failures stop the device, raise an alarm or crash the workstation; staff notice and fall back to another device or to manual care. Quiet failures keep producing numbers that look normal and are wrong: a pulse oximeter that reads high on darker skin, a glucose sensor that reads low, a lead analyzer that under-reports, a pump that loads a stale order. The quiet kind never triggers a downtime procedure.

In a paper-era hospital a device error reached one patient through one clinician who could see the device. In an automated hospital device outputs feed EHR flowsheets, early-warning scores, auto-programmed infusions and remote monitoring, and a single vendor update can reach every unit at once. The same connectivity that lets a pump receive an order from the EHR lets a faulty update or a compromised firmware image reach thousands of endpoints in minutes.

FailSystems viewA device that stops is a tier-2 problem you can plan for; a device that keeps reporting wrong numbers is the one that hurts people, because nothing in the system tells anyone to change tier. Automation makes this worse in two directions. It amplifies quiet error, because downstream scores, alerts and auto-programming consume the bad value without a human looking at the device. And it synchronizes loud failure, because fleet-wide updates (security agents, firmware, interface software) turn one vendor mistake into simultaneous failure across a hospital or a country. Defense in this layer is less about redundancy of boxes and more about independent cross-checks of values and control over when changes land.

How it fails

Systematic sensor bias in a subgroup

A sensor is accurate on the population it was validated on and biased on others. Pulse oximeters overestimate saturation in patients with darker skin, so hypoxemia is missed and treatment thresholds are crossed later. The device reports normally and nothing alarms.[1,2,3]

Warning signs

  • SpO2-SaO2 gaps that differ by patient group when paired values are audited
  • Validation data from the manufacturer that does not report performance by skin tone
  • Therapy eligibility or escalation rates that differ by group at the same recorded SpO2

Seen inPulse oximeters overestimate oxygen saturation in patients with darker skin

Manufacturing or design defect producing plausible wrong values

A batch or design flaw makes a device report values in the normal range that are wrong: glucose sensors reading low, blood lead analyzers reading low. Users act on the number. Detection depends on someone comparing against an independent method, and on the manufacturer reporting promptly, which can fail.[4,5]

Warning signs

  • Clinical picture that does not match the device value
  • Discrepancies between point-of-care and reference lab results
  • Clusters of complaints about one lot or serial range
  • Changes to instructions for use without a clear safety notice

Seen inFreeStyle Libre 3 sensors report falsely low glucose, LeadCare blood lead analyzers return falsely low results; malfunction concealed

Fleet-wide faulty update

A vendor pushes a software, firmware or content update to every installed endpoint at once. If the update is faulty, every device or workstation that takes it fails together, and recovery is limited by hands-on remediation per machine. Security agents with kernel access are the extreme case because they update often and without customer staging.[6,7,8]

Warning signs

  • Endpoint agents or device firmware set to auto-update with no ring or delay
  • No inventory of which clinical devices run which agents
  • Recovery runbook that assumes remote management works

Seen inCrowdStrike Falcon content update crashes Windows hosts, including hospital systems

Stale or queued commands across a device integration

When EHR-to-device integrations (infusion auto-programming, order interfaces) back up, a queued command can arrive late and be applied to the device as if it were current. The value looks legitimate on the pump screen.[9]

Warning signs

  • Interface engine queue depth or latency rising
  • Pump parameters that differ from the current order
  • Clinicians reporting 'the pump got the old order'

Seen inAlaris infusion interoperability backlog can load outdated pump orders

Alarm failure and alarm fatigue

Alarms fail to sound (a low-battery alarm that does not fire, wrong priority), sound falsely (spurious power-loss alarms that stop therapy), or sound so often that staff tune them out. The Joint Commission counted 98 alarm-related sentinel events, 80 of them deaths, from 2009 to mid-2012.[10,11,12,13]

Warning signs

  • High non-actionable alarm rates per bed per day
  • Alarm limits left at defaults
  • Vendor corrections that mention alarm behavior
  • Near misses where an alarm was heard but not acted on

Seen inPhilips Respironics ventilator, BiPAP and CPAP recall over degrading sound-abatement foam, Alaris infusion interoperability backlog can load outdated pump orders

Insecure or unsupported networked device

Devices that can connect to a network but no longer receive security updates, or that ship with hidden functions, provide a path to alter device behavior or reach the wider network. The only mitigation may be to disconnect, which removes remote monitoring.[14,15,16,17,18,19]

Warning signs

  • Devices on end-of-support operating systems
  • No SBOM or vulnerability disclosure contact from the vendor
  • Unexpected outbound traffic from device VLANs
  • Devices on flat networks with clinical workstations

Seen inContec CMS8000 patient monitors: hidden remote-access function disclosed by CISA and FDA

Latent hardware hazard with slow recall remediation

A material or component degrades inside devices already in use, with no alarm. Once found, remediation depends on replacement supply, locating every unit (often in patients' homes) and clear communication, and can take years.[20,21,22]

Warning signs

  • Recall notices without a tracked list of your affected serial numbers
  • Home-use devices issued without a registry
  • Replacement timelines measured in months

Seen inPhilips Respironics ventilator, BiPAP and CPAP recall over degrading sound-abatement foam

Recall and safety notice not reaching the user

Recalls are posted, but the notice does not reach the clinician, biomed team or home patient using the device, or arrives without clear action. FDA posting dates reflect classification, which can lag the firm's action.[16,23,20]

Warning signs

  • No single owner for recall intake and closure
  • Recalls closed without serial-number reconciliation
  • Home devices supplied by third parties outside the hospital's view

Seen inFreeStyle Libre 3 sensors report falsely low glucose, Philips Respironics ventilator, BiPAP and CPAP recall over degrading sound-abatement foam

Incidents

CrowdStrike Falcon content update crashes Windows hosts, including hospital systems

A faulty Rapid Response Content update to CrowdStrike's Falcon sensor crashed about 8.5 million Windows devices worldwide. Outside-in measurement found disrupted services at 759 of 2,232 US hospitals studied.[6,7,31,8,32,33,34]

PathDevices → Connectivity & data → Human handoff

How you'd know

  • Audit paired device vs reference values (SpO2 vs SaO2, point-of-care vs lab glucose or lead) at least quarterly and break the gap down by patient group.[1,2]
  • Subscribe to the FDA Medical Device Recalls database and MAUDE for every device model in your inventory, remembering MDR counts do not establish cause or rate.[23,50]
  • Subscribe to CISA ICS medical advisories and match them against your device inventory by model and firmware version.[15]
  • Monitor device integration queues (EHR-to-pump auto-programming, interface engines) for latency and backlog, and alert on growth.[9]
  • Track alarm load and non-actionable alarm rates per unit; rising rates predict missed actionable alarms.[10,51]
  • Measure external reachability of your own clinical services; the CrowdStrike study showed internet scanning detected outages at 34% of hospitals.[8]

What to do, tier by tier

What should already be in place at each degradation tier for this layer. Tier 0 is normal automated running; tier 3 is paper, batteries and judgement.

These are practices reported or recommended in the cited sources, gathered for reference. They are not a prescription for your organisation; judge what fits your setting, and check the current official text of any standard.

0Full automation

  • Require manufacturers to supply accuracy data by skin tone for any oximeter you buy, and prefer devices tested under FDA's 2025 draft protocol.[3,41]
  • Require an SBOM, a coordinated vulnerability disclosure process and a stated patch timeline in every networked-device contract, mirroring FD&C Act 524B.[17,52,18]
  • Treat any device with USB, serial, Bluetooth or ethernet ports as internet-capable when you assess it; FDA does.[18]
  • Put every endpoint agent and device firmware update into staged rings (test group, one unit, then fleet) with a hold period; refuse vendors that cannot support customer-controlled staging.[6,7]
  • Run IEC 80001-1 risk management before connecting any device to the network, with clinical engineering, IT and the vendor named as owners.[53]
  • Keep a device inventory with model, serial, firmware version, network location and support end date, and reconcile every recall against it within 10 working days.[54,16]

1Assisted operation

  • When an oximetry reading does not fit the clinical picture, draw an arterial blood gas before withholding or delaying oxygen-threshold therapy.[1,2]
  • Verify rate, dose and volume on the pump against the current order before starting any auto-programmed infusion.[9]
  • Segment clinical devices onto their own networks and block outbound internet by default, so a compromised monitor can still monitor locally.[14,15]
  • Set alarm limits per patient population and document which alarm signals matter most on each unit, as NPG.01.05.01 requires.[51,10]

2Manual operation

  • Keep standalone (non-networked) monitors and pumps stocked on each critical unit for use when networked devices or their central stations are down.[16]
  • Pre-stage offline recovery kits (local admin credentials, disk-encryption recovery keys, bootable media) so endpoints can be restored by hand at scale.[6,31]
  • Give home patients on recalled sensors a verified fallback (fingerstick meter, strips) and tell them in writing which readings to trust.[4]
  • Switch to manual infusion programming with independent double-check when the interoperability layer is suspect.[9]

3Analog fallback

  • Keep paper vital-sign and infusion flowsheets on every unit and drill their use; ECRI ranks digital-darkness unpreparedness the second hazard of 2026.[16]
  • Maintain manual measurement skills and equipment (manual BP cuffs, gravity infusion sets with drip-rate charts) for when devices cannot be trusted.[16]
  • Pre-decide which elective procedures cancel when device fleets fail, so the call takes minutes, as it did at Mass General Brigham on 19 July 2024.[31]

Standards and rules (US)

InstrumentWhat it requires
ISO 14971:2019 (FDA recognition 5-125)Manufacturers identify hazards, estimate and control risks, and monitor effectiveness of controls across the device life cycle, including post-production information.[55]
IEC 62304:2006+AMD1:2015Life cycle processes for development and maintenance of medical device software, including software safety classification, change control and problem resolution.[56]
IEC 60601-1-8:2006+AMD1:2012+AMD2:2020Requirements and tests for medical alarm systems: alarm priority categories, alarm signal characteristics and control states such as pausing and silencing.[13]
IEC 80001-1:2021The healthcare delivery organization applies risk management for safety, effectiveness and security before, during and after connecting devices or health software to its IT infrastructure.[53]
FD&C Act section 524B (21 U.S.C. 360n-2)Cyber device sponsors must submit a postmarket vulnerability plan, maintain processes to assure cybersecurity, ship patches on a justified regular cycle and critical fixes out of cycle, and provide an SBOM.[17]
Joint Commission NPG.01.05.01 (2026)Hospitals identify the most important alarm signals, set policies for managing them, and educate staff; replaces NPSG.06.01.01 from January 2026.[51]

Elsewhere: EU and UK

In the EU, the Medical Device Regulation (EU) 2017/745 makes information security part of the essential requirements: Annex I 17.2 requires software to be built under state-of-the-art life cycle and risk management including information security, and 17.4 requires manufacturers to state minimum hardware, network and IT security requirements, including protection against unauthorised access. In Great Britain, amended post-market surveillance rules in force from 16 June 2025 cut the serious-incident reporting deadline from 30 to 15 days and require manufacturers to submit Field Safety Notices to the MHRA before they go to users, which targets the recall-communication failure mode directly.[57,58]

Severity score v0.1 draft

4Likelihood
4Blast radius
5Detectability (5 = hardest)
80of 125

FailSystems judgementJudgement: device faults reported to FDA are routine (Class I recalls on pumps, ventilators and sensors recur yearly), so likelihood is high. Blast radius is high because fleet updates and population-wide sensors (oximetry, CGMs, a dominant lead analyzer) spread one error across many patients. Detectability is scored hardest (5) because the most harmful mode is a plausible wrong value that triggers no alarm and no downtime procedure.

Each factor is scored 1–5 and multiplied, as in a classic FMEA risk priority number. This is our first-draft judgement, not a measurement; see how scoring works and how it will be revised.

What we don't know yet

  • How much patient harm does oximetry bias cause at the outcome level (mortality, ICU admission), beyond delayed treatment eligibility?
  • What share of hospital device fleets run end-of-support software or unmanaged agents, and how does that track with outage and incident exposure?
  • Do staged, customer-controlled update rings actually reduce fleet-failure blast radius in hospitals, and at what patch-delay cost for security?
  • How often do EHR-to-device integrations deliver stale or mismatched commands in routine operation, below the threshold of a recall?
  • Will FDA finalize the 2025 pulse oximeter guidance, and how fast will legacy oximeters in use be replaced?

These gaps drive what the nightly research pass looks for. If you have evidence, send it.

Sources cited on this page

  1. Racial Bias in Pulse Oximetry Measurement. New England Journal of Medicine (Sjoding MW, Dickson RP, Iwashyna TJ, Gay SE, Valley TS), 17 December 2020. Primary Peer-reviewed · link checked 2026-09-26
  2. Racial and Ethnic Discrepancy in Pulse Oximetry and Delayed Identification of Treatment Eligibility Among Patients With COVID-19. JAMA Internal Medicine (Fawzy A, et al.), 1 July 2022. Primary Peer-reviewed · link checked 2026-09-26
  3. Pulse Oximeters for Medical Purposes - Non-Clinical and Clinical Performance Testing, Labeling, and Premarket Submission Recommendations (Draft Guidance). U.S. Food and Drug Administration, 7 January 2025. Primary Guidance · link checked 2026-09-26
  4. Glucose Monitor Sensor Recall: Abbott Diabetes Care Removes Certain FreeStyle Libre 3 and FreeStyle Libre 3 Plus Sensors. U.S. Food and Drug Administration, 5 February 2026. Primary Official report · link checked 2026-09-26
  5. Magellan Diagnostics Pleads Guilty to Criminal FDCA Charges. U.S. Department of Justice (District of Massachusetts), reposted by FDA OCI, 27 June 2024. Primary Official report · link checked 2026-09-26
  6. External Technical Root Cause Analysis - Channel File 291. CrowdStrike, 6 August 2024. Supporting Official report · link checked 2026-09-26
  7. Testimony of Adam Meyers, CrowdStrike, before the House Homeland Security Subcommittee on Cybersecurity and Infrastructure Protection: 'An Outage Strikes'. U.S. House Committee on Homeland Security, 24 September 2024. Primary Testimony / filing · link checked 2026-09-26
  8. Patient Care Technology Disruptions Associated With the CrowdStrike Outage. JAMA Network Open (Tully JL, ... Dameff CJ), 1 July 2025. Primary Peer-reviewed · link checked 2026-09-26
  9. Infusion Pump Software Correction: BD Issues Correction for BD Alaris Systems Manager and Care Coordination Engine Infusion Adapter Software Due to Risk for Outdated Automated Programming Requests to Load. U.S. Food and Drug Administration, 18 February 2025. Primary Official report · link checked 2026-09-26
  10. Sentinel Event Alert Issue 50: Medical device alarm safety in hospitals. The Joint Commission, 8 April 2013. Secondary Official report · link checked 2026-09-26
  11. BD Provides Update on Feb. 4, 2020 Voluntary Recall of the BD Alaris System PC Units and Modules. U.S. Food and Drug Administration (company announcement), 9 March 2020. Primary Official report · link checked 2026-09-26
  12. Ventilator Software Correction: Philips Respironics Issues Mandatory Software Correction and Updates Use Instructions for Trilogy Evo, EV300, EvoO2, and Evo Universal. U.S. Food and Drug Administration, 16 July 2024. Primary Official report · link checked 2026-09-26
  13. IEC 60601-1-8:2006+AMD1:2012+AMD2:2020 CSV Alarm systems in medical electrical equipment and systems. International Electrotechnical Commission, 23 July 2020. Primary Standard · link checked 2026-09-26
  14. Cybersecurity Vulnerabilities with Certain Patient Monitors from Contec and Epsimed: FDA Safety Communication. U.S. Food and Drug Administration, 30 January 2025. Primary Official report · link checked 2026-09-26
  15. ICS Medical Advisory ICSMA-25-030-01: Contec Health CMS8000 Patient Monitor (Update A). Cybersecurity and Infrastructure Security Agency, 30 January 2025. Primary Official report · link checked 2026-09-26
  16. Top 10 Health Technology Hazards for 2026: Executive Brief. ECRI, January 2026. Secondary Official report · link checked 2026-09-26
  17. 21 U.S.C. 360n-2 (FD&C Act section 524B): Ensuring cybersecurity of devices. Office of the Law Revision Counsel, U.S. House of Representatives, 29 December 2022. Primary Regulation · link checked 2026-09-26
  18. Draft Guidance - Select Updates for the Premarket Cybersecurity Guidance: Section 524B of the FD&C Act (webinar slides). U.S. Food and Drug Administration (CDRH), 30 April 2024. Primary Guidance · link checked 2026-09-26
  19. Postmarket Management of Cybersecurity in Medical Devices. U.S. Food and Drug Administration, December 2016. Primary Guidance · link checked 2026-09-26
  20. FDA Activities Related to Recalled Philips Ventilators, BiPAP Machines, and CPAP Machines. U.S. Food and Drug Administration, November 2024. Primary Official report · link checked 2026-09-26
  21. Problems Reported with Recalled Philips Ventilators, BiPAP Machines, and CPAP Machines. U.S. Food and Drug Administration, 31 January 2024. Primary Dataset · link checked 2026-09-26
  22. Medical Device Recalls database. U.S. Food and Drug Administration, November 2002. Primary Dataset · link checked 2026-09-26
  23. Final Report on the Grid Incident in Spain and Portugal on 28 April 2025. ENTSO-E Expert Panel, 20 March 2026. Primary Official report · link checked 2026-09-26
  24. La resaca en los hospitales tras salvar el apagón: 'Más allá de cierto caos, hemos sobrevivido bastante bien'. elDiario.es (Sofía Pérez Mendoza), 29 April 2025. Secondary Journalism · link checked 2026-09-26
  25. When the lights went out: impacts of the April 2025 Iberian blackout on the Portuguese National Health Service sovereignty. Frontiers in Public Health, 2025. Primary Peer-reviewed · link checked 2026-09-26
  26. Blackout in Spain: Urgent Analysis of Impact on Emergency Medical Services. Prehospital and Disaster Medicine, December 2025. Primary Peer-reviewed · link checked 2026-09-26
  27. Excess mortality attributable to the 2025 Iberian Peninsula blackout. Nature Communications, July 2026. Primary Peer-reviewed · link checked 2026-09-26
  28. Do the CONTEC CMS8000 Patient Monitors Contain a Chinese Backdoor? The Reality is More Complicated…. Claroty Team82, 2 February 2025. Supporting Vendor research · link checked 2026-09-27
  29. Contec Patient Vital Signs Monitor: Chinese Backdoor or Bad Design?. Cylera (Chad Waters, Apostolos Bakoyiannis), 4 February 2025. Supporting Vendor research · link checked 2026-09-27
  30. Microsoft global outage forces hospitals to cancel appointments. STAT (Palmer K, Trang B, Ross C), 19 July 2024. Secondary Journalism · link checked 2026-09-26
  31. Helping our customers through the CrowdStrike outage. Microsoft (David Weston), 20 July 2024. Supporting Official report · link checked 2026-09-26
  32. Widespread IT Outage Due to CrowdStrike Update. CISA, 19 July 2024. Primary Guidance · link checked 2026-09-26
  33. A look at how Mass General Brigham recovered from the CrowdStrike outage. Healthcare Brew (Cassie McGrath), 11 September 2024. Secondary Journalism · link checked 2026-09-27
  34. The February 2021 Cold Weather Outages in Texas and the South Central United States — FERC, NERC and Regional Entity Joint Staff Report (presentation of findings). FERC / NERC, November 2021. Primary Official report · link checked 2026-09-26
  35. Austin hospitals lose water pressure and heat amid winter storm. The Texas Tribune, 17 February 2021. Secondary Journalism · link checked 2026-09-26
  36. February 2021 Winter Storm-Related Deaths – Texas. Texas Department of State Health Services, 31 December 2021. Primary Official report · link checked 2026-09-26
  37. The February 2021 Cold Weather Outages in Texas and the South Central United States — Tracking of Responses to Recommendations. FERC (with NERC and Regional Entity staff), December 2022. Primary Official report · link checked 2026-09-26
  38. Boil-Water Advisory in Effect, Low Water Pressure Impacts Austin Hospitals. Circle of Blue, 18 February 2021. Secondary Journalism · link checked 2026-09-26
  39. Texas' power outages, water shortages put bigger strain on hospitals. ABC News, 18 February 2021. Secondary Journalism · link checked 2026-09-26
  40. Pulse Oximeters (FDA actions on accuracy and skin pigmentation). U.S. Food and Drug Administration, 6 January 2025. Primary Guidance · link checked 2026-09-26
  41. Investigation: WannaCry cyber attack and the NHS. National Audit Office (UK), 27 October 2017. Primary Official report · link checked 2026-09-26
  42. Lessons learned review of the WannaCry Ransomware Cyber Attack. Department of Health and Social Care / NHS England (William Smart, CIO for Health and Social Care), 1 February 2018. Primary Official report · link checked 2026-09-26
  43. A retrospective impact analysis of the WannaCry cyberattack on the NHS. npj Digital Medicine, 2 October 2019. Primary Peer-reviewed · link checked 2026-09-26
  44. What caused generators to fail at NYC hospitals?. CBS News / Associated Press, 2 November 2012. Secondary Journalism · link checked 2026-09-26
  45. Evacuation of a neonatal intensive care unit in a disaster: lessons from Hurricane Sandy. Pediatrics (American Academy of Pediatrics), 2014. Primary Peer-reviewed · link checked 2026-09-26
  46. Hospital Emergency Preparedness and Response During Superstorm Sandy (OEI-06-13-00260). US HHS Office of Inspector General, 16 September 2014. Primary Official report · link checked 2026-09-26
  47. MGH death spurs review of patient monitors. The Boston Globe (Liz Kowalczyk), 21 February 2010. Secondary Journalism · link checked 2026-09-27
  48. Patient alarms often unheard, unheeded. The Boston Globe (Liz Kowalczyk), 13 February 2011. Secondary Journalism · link checked 2026-09-27
  49. About Manufacturer and User Facility Device Experience (MAUDE) Database. U.S. Food and Drug Administration, 8 December 2025. Primary Dataset · link checked 2026-09-26
  50. National Performance Goals Effective January 2026 for the Hospital Program. The Joint Commission, 1 January 2026. Secondary Standard · link checked 2026-09-26
  51. Cybersecurity in Medical Devices: Quality Management System Considerations and Content of Premarket Submissions. U.S. Food and Drug Administration (CDRH/CBER), February 2026. Primary Guidance · link checked 2026-09-26
  52. IEC 80001-1:2021 Safety, effectiveness and security in the implementation and use of connected medical devices or connected health software - Part 1: Application of risk management. International Electrotechnical Commission, 21 September 2021. Primary Standard · link checked 2026-09-26
  53. Recalls, Corrections and Removals (Devices). U.S. Food and Drug Administration, 2020. Primary Regulation · link checked 2026-09-26
  54. Recognized Consensus Standard 5-125: ISO 14971:2019 Medical devices - Application of risk management to medical devices. U.S. Food and Drug Administration (Recognized Consensus Standards database), 23 December 2019. Primary Standard · link checked 2026-09-26
  55. IEC 62304:2006+AMD1:2015 CSV Medical device software - Software life cycle processes. International Electrotechnical Commission, 26 June 2015. Primary Standard · link checked 2026-09-26
  56. Regulation (EU) 2017/745 on medical devices (MDR), Annex I sections 17.2 and 17.4. Official Journal of the European Union / EUR-Lex, 5 April 2017. Primary Regulation · link checked 2026-09-26
  57. First major overhaul of medical device regulation comes into force across Great Britain. Medicines and Healthcare products Regulatory Agency (GOV.UK), 16 June 2025. Primary Regulation · link checked 2026-09-26

Cite this pageFailSystems. “Devices & electronics.” https://failsystems.health201.com/layers/devices/ (reviewed 2026-09-26). Health 201 / AstroNexus LLC. CC BY 4.0.

Information only, not advice. FailSystems is an aggregation and synthesis of published sources. It is not consulting, engineering, legal, regulatory or medical advice, and using it creates no professional relationship. Health systems are complex and no approach fits every organisation: anything you adopt is your own decision, at your own risk, and should be checked against the current official sources and by qualified people who know your setting. Full disclaimer.

Dealing with an incident right now? This site is a reference, not an incident-response service. Activate your organisation's emergency operations plan and incident command, and: