This week the FBI explained how attackers got into one of its systems. Brett Leatherman, the bureau's cyber chief, said the incident "occurred as the result of a security failure" of "a platform managed by a third-party organization," "after a contractor failed to implement a security patch explicitly issued to secure the platform." The contractor has been removed. According to SecurityWeek and other reports, the platform held HR records, the ShinyHunters group claimed the breach, and the fix had been issued months before it.
I'm not going to pile on the contractor. The investigation is the FBI's to finish, and much of what is public comes from reporting and unnamed sources. The more useful question is this: if it happened to an agency with the FBI's resources, what would stop it happening to you?
You can outsource the work, not the risk
Most organisations now run critical data on platforms someone else operates: HR and payroll systems, finance applications, file transfer services, line-of-business apps hosted and patched by an integrator. The contract says the supplier patches. The risk register says "managed by supplier". And the part of the organisation that would notice a missing patch on its own servers has no view of this one at all.
That's where the gap opens. The software vendor does its job and ships a fix. The supplier is meant to apply it. Nobody on your side checks it went on, or watches the platform for signs that someone got in first. When it goes wrong, the data, the regulator and the headline are yours, whatever the contract says.
Three questions worth asking this month
1. Do you know which platforms hold your sensitive data and are patched by someone else?
Not the supplier list, the platform list. For each system holding personal, financial or sensitive operational data, write down who applies security updates, who decides when, and who would know if they didn't. If the honest answer to the last one is "the supplier", you have a single point of failure you've chosen not to look at.
2. Does the contract say how fast, or only that they will?
"The supplier will apply security patches" is not a commitment. A useful clause separates routine updates from fixes for vulnerabilities being exploited in the wild, such as anything on CISA's Known Exploited Vulnerabilities catalogue. It sets a timescale for each. It requires the supplier to tell you when they can't meet that timescale, and why. And it gives you the right to see evidence. A quarterly attestation that "systems are patched" tells you what someone believed on the day they signed it.
3. Can you see the platform at all?
This is the one most organisations miss. Even if you can't patch a supplier-run platform, you can usually get its authentication and audit logs, scan its internet-facing surface, and know its version numbers. That's enough to spot a missing fix and to see an attacker using it. Without that visibility, the first sign of a breach is a post on a leak site.
What good looks like
- An owner on your side for every supplier-run platform. Someone who reads the vendor's security advisories and asks the supplier the same day whether they apply.
- Exploited-vulnerability patching measured in days, not maintenance windows, written into the contract and reported against.
- Evidence, not attestation. Version numbers, scan results or change records that show the fix is in place.
- Logs flowing to your security operations, so suspicious sign-ins and bulk data access on the platform are seen by people watching for them.
- A rehearsed answer to "what if they didn't patch?" Who isolates the platform, who talks to the supplier, and who decides whether data has left.
None of this is exotic. It's ordinary third-party risk management and vulnerability management, applied to the systems that tend to fall between them.
The uncomfortable bit
When something like this happens, removing the contractor is the visible response, and sometimes the right one. But the patch only went unapplied for so long because nobody else in the chain was checking. Leaders who sign off outsourcing decisions own that oversight. The work can be delegated, but the accountability stays with you, and so does the duty to check the work was done.
If we were having this conversation with your board, the test I'd suggest is simple. Pick your three most sensitive supplier-run platforms and ask when each last received a security fix, and how you know. If nobody can answer in a day, that's the work to start on.
How we help
We help organisations build third-party risk management that asks suppliers the right questions, run vulnerability and patch management that covers the estate they don't operate as well as the estate they do, and bring supplier platform logs into 24/7 monitoring so someone is watching when a fix is late. Our vCISO service gives leadership teams senior help to set that oversight up and keep it honest.
If you'd like a second opinion on how your supplier-run platforms are patched and watched, talk to our team.