Target: supplier access showed why third-party portals need strong segmentation from sensitive systems
Target was reached through a supplier's access, and the significant part is what that access could reach once used.
A heating and ventilation contractor's credentials should not have offered a route anywhere near payment systems. The supplier being compromised was foreseeable; the network allowing that compromise to travel was the decision. Third-party access needs segmenting from anything sensitive, because suppliers will eventually be compromised.
Checked against the primary source.
More on Real incident lessons
- Equifax: knowing about a vulnerability is not knowing it is patchedThe list said five
- Colonial Pipeline: business shutdown can follow IT compromiseNothing touched the pipe
- Help-desk identity processes are attack surfaces when social engineering can trigger password resets or MFA transferThree answers, and it moves
- British Library: recovery can outlast initial disruptionThe outage was the short part
- Hawaii false missile alert: test and live alert paths need separation because confirmation prompts cannot correct a convinced operatorA hand apart
- CrowdStrike 2024: trusted security software can be concentration riskOne roller, every machine
