CIO Brief: When Your Security Vendor Loses Its Cloud Keys
Retrospective: this article looks back at events from August 2019, written in 2026 with the benefit of hindsight.
The short version: In 2019, Imperva — a company that sells security protection — disclosed that customer data was exposed after an attacker stole a cloud access key from one of its systems. Security vendors hold sensitive data about you, and they can be breached like anyone else.
Why vendor key hygiene matters to you
Your security vendors often hold some of your most sensitive information: API keys, certificates, configuration details, user accounts. When they are breached, you must act quickly to rotate what they held.
The business impact
- Exposure of credentials that could be used against your systems.
- Urgent rotation work across teams.
- Loss of trust in a provider you rely on for protection.
Questions to ask your team
- What secrets and credentials do our security vendors hold for us?
- How quickly could we rotate them if a vendor were breached?
- Do our own systems still use long-lived cloud access keys like the one stolen here?
- Do we ask vendors how they protect our data and keys?
What good looks like
An inventory of credentials shared with vendors, a rotation runbook, a preference for vendors that integrate with short-lived credentials, and your own environment free of long-lived keys.
The decision
Ask your team to count the long-lived cloud access keys in your own environment. If the number isn't small and shrinking, make replacing them a priority — it is the same weakness that exposed Imperva's customers.
- Imperva's Cloud WAF Breach (Aug 2019): A Stolen AWS API Key From an Internal Instance Incident Teardowns
- How to Replace Long-Lived AWS Access Keys With IAM Roles and Identity Center How-To & Hardening
- Detecting Stolen AWS API Keys: CloudTrail, GuardDuty and Athena Queries Detection & Response