Discussion about this post

User's avatar
Mike Schlottman's avatar

Credit to Chris for running CISA's own postmortem instead of burying it. Nine ignored automated alerts and a reporting channel nobody could find are the same findings I have watched auditors write up in ISO 27001 and SOC 2 engagements for years, just with higher stakes here. The real tell is the 48 hour key rotation. If your incident response plan assumes revocation is instant, you have never actually tested it.

No posts

Ready for more?