{"id":267,"date":"2026-04-22T06:00:00","date_gmt":"2026-04-22T05:00:00","guid":{"rendered":"https:\/\/www.auravere.com\/insights\/?p=267"},"modified":"2026-04-24T11:09:05","modified_gmt":"2026-04-24T10:09:05","slug":"the-boundary-was-never-where-you-thought-it-was","status":"publish","type":"post","link":"https:\/\/www.auravere.com\/insights\/the-boundary-was-never-where-you-thought-it-was\/","title":{"rendered":"The Boundary Was Never Where You Thought It Was"},"content":{"rendered":"\n<p class=\"wp-block-paragraph\">Everyone was watching Rockstar Games this week.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Just not for the right reason.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The gaming world has been waiting for Grand Theft Auto 6 for years. The headline everyone hoped for from Rockstar was a confirmed release date, a new trailer, a launch. Instead the headline was a breach. ShinyHunters accessed Rockstar&#8217;s Snowflake servers through a compromised monitoring service called Anodot. A third party tool. Something sitting quietly in the background doing its job, with access to systems that mattered, and nobody was watching it the way they were watching everything else.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">This is the story of enterprise security in 2026. Not the headline breach. The quiet door that was left open because nobody thought to check it.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>The boundary illusion<\/strong><\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Organisations spend considerable effort defining and defending what they think of as their perimeter. Firewalls, endpoint protection, access controls, network segmentation. All of it pointed at a boundary that their users, their data, and their attackers have long since stopped respecting.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Your users have never seen the boundary. Data goes into SaaS applications, collaboration tools, cloud storage, personal devices, supplier portals, and monitoring platforms without a second thought. Every one of those destinations is a third party relationship. Every one of those relationships is an extension of your attack surface. Most organisations do not have a complete picture of what those connections look like or what access those third parties actually have.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">This is not a new problem. It is a problem that keeps producing the same incidents because the same assumptions keep being made.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>The pattern that nobody is learning from<\/strong><\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Cast your mind back to M&amp;S last year. Third party vector. Cast your mind back further to MOVEit. Supply chain. SolarWinds before that. Supply chain again. Log4Shell, embedded in hundreds of products that organisations did not know they were running.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Every time one of these incidents happens the conversation follows the same pattern. Initial shock. Attribution. Patching. Lessons learned documents that sit in SharePoint. And then the next one arrives and everyone is surprised again.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">This week it was not just Rockstar. Multiple organisations were hit through a Salesforce compromise. Cisco disclosed critical flaws in its identity services platform, a 9.9 CVSS score, arbitrary code execution, impersonation of any user within the service. Apache ActiveMQ had a vulnerability that had been hiding in plain sight for thirteen years, now under active exploitation.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Different products. Different vendors. Different attack vectors. Same underlying problem. We trusted something we did not fully understand and had no complete visibility of.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>I said this in 2018<\/strong><\/p>\n\n\n\n<p class=\"wp-block-paragraph\">When GDPR came into force, one of the things it made explicit was that data controllers are responsible for what their processors do with shared data. Not just contractually responsible. Actually responsible. If your supplier mishandles personal data you shared with them, that is your problem under the regulation.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Most organisations treated that as a compliance checkbox. They updated their data processing agreements and moved on. They did not fundamentally change how they mapped and monitored their third party relationships, because doing that properly is hard and expensive and does not have an obvious deadline attached to it.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The security argument for doing it properly has been there all along. The regulatory argument has been there since 2018. And here we are in 2026 watching the same incidents unfold because the lesson is still not being learned.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Policy is not a control you can measure<\/strong><\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The default response to third party risk in most organisations is a supplier questionnaire and an acceptable use policy. Both have their place. Neither tells you what is actually happening.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">You cannot audit a third party relationship you do not know exists. You cannot revoke access from a monitoring tool if you do not know what access it has. You cannot respond to a breach via a supplier&#8217;s compromised credentials if you do not know that supplier has credentials to your environment in the first place.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Policy describes what should happen. Visibility tells you what is actually happening. In the gap between those two things is where every supply chain incident lives.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>The question organisations are not asking<\/strong><\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The question most organisations ask after a supply chain breach is how do we stop this happening again. The question they should be asking is how many of these doors are currently open, that we do not know about.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Because the Anodot compromise that hit Rockstar was not a sophisticated attack. It was a monitoring tool with access it needed to do its job, credentials that got stolen, and an organisation that did not have enough visibility of its third party connections to catch it before it became a headline.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Every organisation reading about Rockstar this week has an Anodot. Probably several. A monitoring tool, a backup service, a supplier integration, a legacy API connection to a platform nobody remembers approving. All of them sitting quietly in the background. All of them with access to something that matters.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The boundary was never where you thought it was. The question is whether you actually know where it is?<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Everyone was watching Rockstar Games this week. Just not for the right reason. The gaming world has been waiting for Grand Theft Auto 6 for years. The headline everyone hoped for from Rockstar was a confirmed release date, a new trailer, a launch. Instead the headline was a breach. ShinyHunters accessed Rockstar&#8217;s Snowflake servers through&#8230;<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"advanced_seo_description":"Rockstar, M&S, MOVEit, SolarWinds. The supply chain breach pattern keeps repeating. Do you know where your third party doors actually are?","jetpack_seo_html_title":"The Boundary Was Never Where You Thought It Was","jetpack_seo_noindex":false,"jetpack_seo_schema_type":"","_kad_post_transparent":"","_kad_post_title":"","_kad_post_layout":"","_kad_post_sidebar_id":"","_kad_post_content_style":"","_kad_post_vertical_padding":"","_kad_post_feature":"","_kad_post_feature_position":"","_kad_post_header":false,"_kad_post_footer":false,"_kad_post_classname":"","_jetpack_newsletter_access":"","_jetpack_dont_email_post_to_subs":false,"_jetpack_newsletter_tier_id":0,"_jetpack_memberships_contains_paywalled_content":false,"_jetpack_feature_clip_id":0,"_jetpack_memberships_contains_paid_content":false,"footnotes":"","jetpack_post_was_ever_published":false},"categories":[22,29,3,24,23],"tags":[14,10,9,15,30],"class_list":["post-267","post","type-post","status-publish","format-standard","hentry","category-cyber-awareness","category-cyber-risk","category-gdpr","category-information-security","category-security-leadership","tag-cissp","tag-cyber-security","tag-information-security","tag-security-leadership","tag-third-party-risk"],"jetpack_featured_media_url":"","jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/www.auravere.com\/insights\/wp-json\/wp\/v2\/posts\/267","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.auravere.com\/insights\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.auravere.com\/insights\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.auravere.com\/insights\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.auravere.com\/insights\/wp-json\/wp\/v2\/comments?post=267"}],"version-history":[{"count":1,"href":"https:\/\/www.auravere.com\/insights\/wp-json\/wp\/v2\/posts\/267\/revisions"}],"predecessor-version":[{"id":268,"href":"https:\/\/www.auravere.com\/insights\/wp-json\/wp\/v2\/posts\/267\/revisions\/268"}],"wp:attachment":[{"href":"https:\/\/www.auravere.com\/insights\/wp-json\/wp\/v2\/media?parent=267"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.auravere.com\/insights\/wp-json\/wp\/v2\/categories?post=267"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.auravere.com\/insights\/wp-json\/wp\/v2\/tags?post=267"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}