How a Two-Week Security Exception Quietly Survived for Three Years
A software team approved a temporary security exception — including shared credentials and relaxed firewall rules — to meet a supplier integration deadline, with a documented two-week expiry. Three years later, the exception was discovered still active, with no one able to explain its origin, as the staff who requested and approved it had since moved on or left. The incident revealed a systemic flaw: the organisation had a formal process for granting security exceptions but no mechanism to enforce their removal. An audit found that years of deadline-driven workarounds had created an unknown number of similar deviations, making the real security posture significantly weaker than policy suggested. The team responded by building expiry enforcement directly into technical systems and instituting a mandatory quarterly review where every open exception must be verbally justified by name.
This is an AI-generated summary. ShortSingh links to the original source for the complete article.


Discussion (0)
Log in to join the discussion and vote.
Log in