A supplier tells you they were breached

Somebody else had the incident and you have the exposure. The work is establishing what they held, what they could reach, and whether their access into your estate is still open, usually with far less information than you want.

Trigger. A notification from a vendor, or their name in the news before their email arrives.

The first 120 minutes1 of 5 expire
060 min120
  1. 01

    Write down what they hold and what they can reach

    by 30 min

    Two different questions. Data they were given, and access they were granted: service accounts, API keys, VPN or remote access, OAuth grants, and any federation. The second is usually undocumented and is the one that matters.

  2. 02

    Hunt their access in your own logs

    by 60 minexpires

    Sign-ins and API calls attributable to the supplier across the stated incident window, and a reasonable margin either side. Your logs are evidence about their incident and may be better than theirs.