CIO Brief: Your Security Vendor Can Be Breached — Plan for It
Retrospective: this article looks back at events from March 2019, written in 2026 with the benefit of hindsight.
The short version: In 2019, Citrix — a company that sells remote access technology to enterprises — was breached, likely through attackers trying common passwords. Your vendors can be breached, and their breaches can become yours.
Why vendor breaches belong in your risk plan
You trust vendors with data, network access and software that runs inside your environment. When a vendor is breached, you need to know quickly whether you are affected and what to do. Most organizations only start asking those questions after the news breaks.
The business impact
- Exposure of your data held by the vendor.
- Compromised software or updates delivered into your environment.
- Disruption if a critical vendor's services go down during their response.
Questions to ask your team
- Which vendors have access to our systems or hold our sensitive data?
- What do our contracts say about breach notification?
- If a key vendor announced a breach tomorrow, who would assess our exposure, and how?
- Could we cut off a vendor's access quickly if needed?
What good looks like
A ranked vendor list, contract terms requiring prompt notification, a short vendor-breach playbook, and technical ability to revoke vendor access fast.
The decision
Create a one-page vendor-breach playbook and test it with a recent real-world example. It will expose gaps in your vendor inventory and access controls.
- Citrix Breached via Password Spraying (Mar 2019): Weak Passwords at Enterprise Scale Incident Teardowns
- How to Use Entra ID Smart Lockout and Identity Protection Against Spraying How-To & Hardening
- Detecting Password Spray Attacks: Defender XDR and Sentinel Hunting Queries Detection & Response