For most of the interval the company was the victim of an incident that had already happened and had not yet surfaced.
Automation, mining, peripherals, a newspaper. The vulnerability selected the victims, and the attacker learned afterwards who they were.
A subsidiary carries the parent’s brand and data relationships, frequently with a fraction of its security capability.
Nobody targeted a newsroom. A media organisation cannot scope its security to the systems that obviously hold journalism.
A university ERP holds staff, students, alumni donors and grant administration. One flaw reached all of it.
The window between disclosure and exploitation is shortest exactly where the ability to respond is slowest.
One ERP zero-day, 29 named victims across unrelated sectors, nothing encrypted. Theft-and-publication at industrial scale.
A product that is exposed, trusted and full is not an unfortunate combination. It is the specification.
A privately held operator using the same product would have had the same exposure and, quite possibly, produced no public record at all.
An organisation appears on the list because it did not pay, or paid late. An organisation absent from the list may have paid.
An initial figure measures how far a review had got, not how large an incident was.
The campaign is unmeasurable. Its individual victims are not.
An organisation dealing with an incident should not assume it is dealing with an incident.
A product bought to move sensitive files safely became the reason thousands of organisations lost them at once.
Every other consumer file here involves someone who chose a company. Here the population is everyone who needed to drive.
High privilege, low attention, reachable. The vulnerable thing is rarely the one anyone would name.
The same operators, the same product category, four months before MOVEit. The rehearsal nobody treated as one.