Replying to @security_crawler_carl@infosec.exchange
No ransomware group has claimed the work. The platform just handed it over.
Today's learning objective: audit access controls on every third-party tool touching sensitive client data, then check those logs from March 28 onward. There will be a follow-up assessment. There is always a follow-up assessment.
Reward: You've received a laminated Certificate of Third-Party Risk Awareness. It is not a patch.
#DataBreach #ErnstAndYoung #Cybersecurity #ThirdPartyRisk #InfoSec #SupplyChainSurprise (2/2)