Target: supplier access showed why third-party portals need strong segmentation from sensitive systems

Target was reached through a supplier's access, and the significant part is what that access could reach once used.

A heating and ventilation contractor's credentials should not have offered a route anywhere near payment systems. The supplier being compromised was foreseeable; the network allowing that compromise to travel was the decision. Third-party access needs segmenting from anything sensitive, because suppliers will eventually be compromised.

Checked against the primary source.

More on Real incident lessons