CipherWatch All articles
Cyber Threat Intelligence

The Familiar Playbook: Recurring Security Failures That Put Your Data at Risk — and the Warning Signs to Watch For

CipherWatch
The Familiar Playbook: Recurring Security Failures That Put Your Data at Risk — and the Warning Signs to Watch For

If you read enough breach disclosure notices — and working in digital security means reading a great many of them — a disquieting pattern emerges. The specific companies change. The affected data types shift. The dollar figures grow. But the underlying failures repeat themselves with a regularity that suggests the industry has not learned what it should have learned.

The 2013 Target breach was traced in part to credentials stolen from an HVAC vendor. The 2017 Equifax breach exploited a vulnerability in a web application framework that had been publicly disclosed and patchable for months before attackers used it. The 2020 SolarWinds incident demonstrated that a trusted software update mechanism could become a delivery vehicle for malicious code. The 2021 Colonial Pipeline ransomware attack was enabled, at least in part, by a legacy VPN account that lacked multi-factor authentication.

These are not obscure edge cases. They are canonical examples, taught in security courses, cited in congressional testimony, and referenced in federal guidance documents. Yet their core failure modes — unpatched systems, poor vendor oversight, inadequate access controls, legacy credential management — appear in new breach disclosures with stubborn consistency.

Understanding why these failures persist, and knowing how to identify them from the outside, is increasingly relevant not just to security professionals but to any American consumer who entrusts personal and financial data to businesses, service providers, and digital platforms.

Failure Mode One: The Unpatched System

Software vulnerabilities are discovered and disclosed every day. Vendors release patches. Security teams are expected to apply them. In practice, patch management is one of the most operationally difficult disciplines in enterprise security, and it is one of the most commonly cited factors in post-breach analyses.

The challenge is scale. A mid-sized enterprise may operate thousands of software components across its infrastructure. Applying patches requires testing for compatibility, scheduling maintenance windows, and managing the risk of operational disruption. In environments where uptime is paramount — hospitals, utilities, financial institutions — the calculus of when to patch becomes genuinely complicated.

But the Equifax case illustrates the consequence of getting that calculus wrong. The Apache Struts vulnerability exploited in that breach had been publicly known for 78 days before attackers used it to exfiltrate the personal records of approximately 147 million Americans. The patch was available. It was not applied.

What to look for: Companies that communicate transparently about their patch management practices, that publish security advisories when vulnerabilities affect their products, and that have documented vulnerability disclosure programs are demonstrating a baseline of operational maturity. Companies that cannot or will not answer basic questions about their patching cadence when asked directly are a cause for concern.

Failure Mode Two: The Overprivileged Account

The principle of least privilege — the security doctrine that users, systems, and applications should have access only to the resources they need to perform their specific functions — is foundational to sound access control design. It is also frequently honored in the breach rather than in the observance.

Organizations accumulate excessive permissions over time through a combination of operational convenience, poor onboarding and offboarding processes, and inadequate access reviews. When an attacker compromises a single account, the damage they can inflict is directly proportional to the privileges that account carries. A stolen credential belonging to an account with administrative access to multiple systems is exponentially more dangerous than one belonging to a user with narrowly scoped permissions.

The 2021 Colonial Pipeline incident highlighted a specific variant of this problem: legacy accounts — credentials that were no longer actively managed but remained valid — provided the initial foothold. The account in question had not been in active use for some time, lacked multi-factor authentication, and apparently fell outside the organization's active credential-management processes.

What to look for: Ask prospective service providers whether they conduct periodic access reviews and whether they enforce multi-factor authentication for privileged accounts. Companies that publish SOC 2 Type II audit reports — a voluntary but meaningful certification — have at minimum subjected their access control practices to independent scrutiny.

Failure Mode Three: The Neglected Vendor

Modern organizations do not operate as closed systems. They depend on vendors, contractors, managed service providers, and software suppliers whose security posture directly affects their own. The Target breach — in which attackers entered Target's network through credentials belonging to a refrigeration and HVAC contractor — remains the definitive illustration of how third-party relationships become first-order security risks.

Vendor risk management, sometimes called third-party risk management, is a discipline that attempts to assess and govern the security practices of an organization's external partners. Done well, it involves contractual security requirements, periodic assessments, and ongoing monitoring. Done poorly — or not at all — it creates a perimeter that is only as strong as its weakest contractor.

Small and mid-sized businesses are particularly vulnerable here because they frequently lack the resources to conduct meaningful vendor assessments and may not recognize the risk until after an incident.

What to look for: Before sharing sensitive data with a service provider, ask whether they conduct security assessments of their own vendors and subprocessors. Review their privacy policy for language about data sharing with third parties. Companies that list their subprocessors publicly — as required for GDPR compliance in Europe, a standard some US companies voluntarily adopt — are demonstrating a level of supply-chain transparency worth noting.

Failure Mode Four: The Under-Resourced Security Function

Many of the organizations that suffer significant breaches were, in retrospect, operating with security teams that were understaffed, under-funded, or structurally marginalized within the organization. Security leadership that lacks board-level access, security budgets that are treated as cost centers rather than risk-management investments, and alert-fatigue environments where genuine threats are lost in the noise of false positives are all contributing factors in breach post-mortems.

This failure mode is the hardest for an outside observer to assess directly, but its symptoms are sometimes visible.

What to look for: Check whether the company has a published security contact or a formal vulnerability disclosure policy — the presence of these suggests that someone within the organization is responsible for and empowered to address security concerns. Review the company's breach history on public databases such as the Identity Theft Resource Center's breach database or the HHS breach portal for healthcare entities. A pattern of repeated breaches, or a single breach followed by minimal disclosed remediation, is a meaningful signal.

A Practical Evaluation Framework

For consumers evaluating whether to trust a company with personal data, the following questions provide a structured starting point.

No framework eliminates risk entirely. But the organizations most likely to appear in next year's breach headlines are the ones that have not addressed the failures documented in this year's. Recognizing those patterns — and making informed decisions about which companies to trust with your data — is one of the most consequential privacy decisions a consumer can make.

All Articles

Related Articles

Always Listening: The Hidden Data Life of Your Smart Speaker

Always Listening: The Hidden Data Life of Your Smart Speaker

Seeing Is No Longer Believing: A Practical Guide to Detecting AI-Generated Video and Audio

Seeing Is No Longer Believing: A Practical Guide to Detecting AI-Generated Video and Audio

Locked Doors, Open Networks: A Room-by-Room Security Audit of Your Smart Home

Locked Doors, Open Networks: A Room-by-Room Security Audit of Your Smart Home