United States · 2026 – 2028

The World Is Coming
to the U.S.
Is Your Organization
Ready?

The FIFA World Cup has come and gone — and it confirmed what we expected: threat actors plan around major global events. The Super Bowl and the Olympic Games are still ahead, both landing in California. Nation-state groups and ransomware organizations don't sit out these moments — they prepare for them months in advance. The events are in California. The threat exposure is nationwide.

A joint initiative by Tec-Refresh + Semperis
FIFA World Cup
✓ Completed
FIFA World Cup
16 U.S./CA/MX cities · Concluded July 2026
Super Bowl SoFi Stadium
🏈 Super Bowl LXI
SoFi Stadium
Inglewood, CA · February 2027
LA Olympics 2028
🏅 Olympic Games
LA 2028
Los Angeles · 2028
Active Threat IntelligenceNation-state actors including Volt Typhoon have already established persistence inside U.S. critical infrastructure. With the World Cup behind us, Super Bowl LXI is the next milestone on the runway.
0+
Cyber incidents during the 2024 Paris Olympics
9/10
Cyberattacks target Active Directory
0
Major global events still ahead — Super Bowl LXI and the LA28 Olympics
50 States
The threat exposure is nationwide — not limited to host cities
The World Cup Confirmed It. Two Events Remain.

Major Global Events Are Proven Targets for Coordinated Cyberattacks

The FIFA World Cup ran June 11 through July 19, 2026, across 16 host cities in the U.S., Mexico, and Canada — and the threat landscape played out largely as predicted. Security researchers tracked over a million leaked credentials tied to the tournament, ransomware activity against hospitality providers, and DDoS attacks that knocked regional ticketing portals offline. Threat actors had infrastructure staged and waiting for months before kickoff, including large volumes of fraudulent domains impersonating FIFA-branded ticketing, merchandise, and job sites.

The takeaway for organizations gearing up for Super Bowl LXI and the LA28 Olympics: this is not a hypothetical risk. It is a documented pattern, and it repeats with every major global event, at greater scale each time.

For SLED organizations and critical infrastructure operators, the stakes are especially high. A successful cyberattack — particularly one targeting identity systems — doesn't just disrupt IT. It disrupts public services, emergency operations, and community trust in real time, in front of a global audience.

It's also important to understand that host-city exposure doesn't stay in the host city. The infrastructure supporting these events — power, telecommunications, financial networks, supply chains, emergency services — is deeply interconnected across state lines. U.S. organizations well outside California should expect to see the same probing activity in the run-up to the next two events.

Preparedness isn't optional. And the window to act is now.

Olympics stadium
🏅 2024 Paris Olympics
140+
Cybersecurity incidents during the games — transport, utilities, and public agencies all targeted
FIFA World Cup
⚽ FIFA World Cup 2026 · Confirmed
1M+ Credentials
Leaked credentials, ticketing-portal DDoS attacks, and ransomware against hospitality vendors during the June–July 2026 tournament
SoFi Stadium
🏈 What's Next · Super Bowl LXI + LA28
2 To Go
Both remaining events land in California — and history says preparation needs to start well before kickoff
The Threat Doesn't Stop at the State Line

California hosts the events.
The entire nation shares the exposure.

The infrastructure supporting these events — power grids, telecommunications, financial networks, emergency services, supply chains — doesn't stop at California's border. Neither do the threat actors targeting them. During the 2026 FIFA World Cup, threat activity extended well beyond the host cities themselves, echoing what nation-state groups did during the 2024 Paris Olympics. Groups like Volt Typhoon have already established persistence inside U.S. critical infrastructure in preparation for exactly these moments. When the world is watching, threat actors are too — and they're not just watching California.

50
states share the elevated threat exposure
The Assessment Offer

Know Where You Stand.
Get a Roadmap to Get There.

The Preparedness & Identity Resilience Assessment is a structured evaluation of your organization's readiness for identity-based attacks and operational disruption. Delivered by Tec-Refresh, with Semperis supporting the identity infrastructure components.

DELIVERABLE 01
Executive Risk Report
Written for C-suite and board-level audiences. Clear findings, business impact framing, and actionable priorities — no technical jargon required. Ready to present the day you receive it.
DELIVERABLE 02
NIST CSF 2.0 Alignment Heatmap
A visual gap analysis across all five CSF 2.0 functions — Identify, Protect, Detect, Respond, Recover — showing your current state versus target state at a glance.
DELIVERABLE 03
Prioritized Remediation Roadmap
A sequenced 90-day, 6-month, and 12-month action plan organized by risk severity and feasibility. Know exactly what to fix, in what order, and why.

Remediation takes time. The right time to start is now.

→ Request Your Assessment

Assessment spots are limited. Tec-Refresh is working with organizations across the U.S. through Q3 and Q4 2026. Request yours while capacity is available.

How It Works

Simple. Structured. Actionable.

1
Schedule
Request your assessment and connect with a Tec-Refresh advisor to confirm scope and logistics. Most assessments begin within two to three weeks of scheduling.
2
Assessment
Our team evaluates your identity infrastructure, operational resilience posture, NIST CSF 2.0 alignment, and threat exposure. Conducted remotely, with on-site options for larger organizations.
3
Deliverables
Within two to three weeks you receive your Executive Risk Report, NIST CSF 2.0 Alignment Heatmap, and Prioritized Remediation Roadmap — ready to present to leadership.
Built Around the Framework That Matters

NIST CSF 2.0 — The Federal Standard for Cyber Readiness

Every assessment maps directly to all five NIST CSF 2.0 functions. You'll know exactly where you stand — and what to do next.

Identify
Asset visibility, identity inventory, and risk awareness across your environment
Protect
AD hardening, MFA enforcement, and privileged access controls
Detect
Identity threat detection and anomaly monitoring — powered by Semperis ITDR
Respond
Incident playbooks, coordination plans, and tabletop exercise readiness
Recover
AD forest recovery, BCP maturity, and RTO vs. actual recovery capability
Two Organizations. One Mission.

About the Partners

Tec-Refresh and Semperis bring complementary expertise to every engagement — from assessment through remediation and ongoing resilience.

Tec-Refresh
Tec-Refresh
A managed security services provider based in Newport Beach, CA, serving public sector and critical infrastructure organizations nationwide. Deep expertise in cybersecurity, business continuity, and operational resilience across SLED and critical infrastructure environments.
Campaign Lead
Semperis
Semperis
The industry leader in identity threat detection and Active Directory resilience. Semperis protects some of the world's most critical organizations from identity-based attacks and enables rapid recovery from Active Directory compromise.
Identity + AD Resilience
Tec-Refresh + Semperis
Together, we provide a comprehensive approach to cyber preparedness — from assessment through remediation and ongoing resilience. When the world is watching, your organization will be ready.
The Campaign. The Timeline. The Opportunity.

Three Phases. One Goal.

✓ Foundational Work Complete
Phase 1 — Awareness
2025 – 2026
Awareness campaigns, webinars, and readiness assessments. Organizations that assessed early have the runway to remediate before the world arrives again.
● Active Now
Phase 2 — Engagement
2026 – 2027
Regional field events and executive briefings across the U.S. Deepen resilience, validate assessments, and close remaining gaps ahead of Super Bowl LXI.
Phase 3 — Peak Readiness
2027 – 2028
Final preparation as the LA28 Olympics arrive. Organizations that started in Phase 1 will be confident. Those that waited will be reacting.
Super Bowl LXI is the next milestone. Closing identity security gaps — hardening Active Directory, implementing incident response playbooks, addressing NIST CSF 2.0 gaps — takes months, not weeks. Organizations that act now will be genuinely ready. Those that wait may not.
Industry Resources

Built for Your Sector

Every industry faces a different compliance landscape and threat profile. We built dedicated resources for the organizations most exposed ahead of the U.S. global event window.

Resources & Insights

From the World Stage Series

Thought leadership and webinars from Tec-Refresh and Semperis — updated as new content is published.

Blogs
July 2026 · Wrap-Up
Lessons From the World Cup: What a Global Mega-Event Teaches Every Organization About Vendor Risk

A look back at how the tournament's sprawling vendor ecosystem and months-of-advance phishing infrastructure mirror the exposure every organization carries daily — and what that means heading into Super Bowl LXI.

Read the blog →
April 2026
Why California’s Biggest Moment Could Be Its Biggest Cyber Risk

The Super Bowl, FIFA World Cup, and Olympic Games are coming to California — and so are the threat actors who plan around them.

Read the blog →
May 2026 · SLED
Identity Is the New Perimeter — What SLED Leaders Need to Know

A joint piece from Tec-Refresh and Semperis on why Active Directory is the primary target for attacks against SLED organizations — and what to do about it.

Read the blog →
May 2026 · SLED
SLED Cybersecurity 101: CMMC, CISA Directives, and What Agencies Actually Need

A practical breakdown of the compliance mandates shaping public-sector cybersecurity — what CMMC 2.0 and CISA KEV directives mean for state agencies, school districts, and municipalities.

Read the blog →
Webinar
Now Live — Watch On-Demand
Identity Under Siege — Are You Ready for 2028?
Hosted by Miguel Martinez, CTO at Tec-Refresh, with Greg Mundy, Senior Solutions Architect at Semperis.
Tuesday, June 9, 2026  ·  On-demand after broadcast
Watch Now →
Energy Deep-Dive
Miguel Martinez + vertical SME · Proposed Aug 5, 2026
Coming Soon
Finance Deep-Dive
Miguel Martinez + vertical SME · Proposed Sep 9, 2026
Coming Soon
Get Started

Request Your Preparedness Assessment

Fill out the form below and a Tec-Refresh advisor will be in touch within one business day to discuss your organization's needs and confirm next steps. You'll also get access to our on-demand webinar, Identity Under Siege — Are You Ready for 2028?, now available to watch.

Your information will only be used to follow up on your assessment request. Tec-Refresh does not sell or share contact information.