No ransomware group has claimed the work. The platform just handed it over. Today's learning objective: audit access controls on every third-party tool touching sensitive client data, then check those logs from March 28 onward. There will be a follow-up assessment. There is always a follow-up assessment. Reward: You've received a laminated Certificate of Third-Party Risk Awareness. It is not a patch. #DataBreach #ErnstAndYoung #Cybersecurity #ThirdPartyRisk #InfoSec #SupplyChainSurprise (2/2)