A supplier tells you they were breached
Somebody else had the incident and you have the exposure. The work is establishing what they held, what they could reach, and whether their access into your estate is still open, usually with far less information than you want.
060 min120
- 01
Write down what they hold and what they can reach
by 30 minTwo different questions. Data they were given, and access they were granted: service accounts, API keys, VPN or remote access, OAuth grants, and any federation. The second is usually undocumented and is the one that matters.
- 02
Hunt their access in your own logs
by 60 minexpiresSign-ins and API calls attributable to the supplier across the stated incident window, and a reasonable margin either side. Your logs are evidence about their incident and may be better than theirs.