Microsoft 365CIO BriefingsRetrospectives

CIO Brief: Your Security Vendor Can Be Breached — Plan for It

By OnCloudSec Research Team · Published Oct 6, 2026 · 1 min read

Retrospective: this article looks back at events from March 2019, written in 2026 with the benefit of hindsight.

The short version: In 2019, Citrix — a company that sells remote access technology to enterprises — was breached, likely through attackers trying common passwords. Your vendors can be breached, and their breaches can become yours.

Why vendor breaches belong in your risk plan

You trust vendors with data, network access and software that runs inside your environment. When a vendor is breached, you need to know quickly whether you are affected and what to do. Most organizations only start asking those questions after the news breaks.

The business impact

  • Exposure of your data held by the vendor.
  • Compromised software or updates delivered into your environment.
  • Disruption if a critical vendor's services go down during their response.

Questions to ask your team

  • Which vendors have access to our systems or hold our sensitive data?
  • What do our contracts say about breach notification?
  • If a key vendor announced a breach tomorrow, who would assess our exposure, and how?
  • Could we cut off a vendor's access quickly if needed?

What good looks like

A ranked vendor list, contract terms requiring prompt notification, a short vendor-breach playbook, and technical ability to revoke vendor access fast.

The decision

Create a one-page vendor-breach playbook and test it with a recent real-world example. It will expose gaps in your vendor inventory and access controls.

citrix breach 2019 impactCitrix password spraying2019

More on this story