Blog

Data breaches: even an excellent IT team needs a second line of vigilance

Data breaches have become so frequent that they almost risk losing their ability to surprise us. A company announces that personal information has been compromised, a few hundred thousand or several million people are notified, credit monitoring services are offered, and a few days later another organization discloses an incident of its own.

That normalization is itself a risk. A breach does not become less serious because it is frequent. Every incident can expose personal information, financial data, identities, commercial information, trade secrets, or organizational knowledge that can never truly be recovered. Once copied, information can circulate for years and be combined with other data to facilitate fraud, identity theft, social engineering, or future cyberattacks.

Recent events also show that breaches no longer stem from a single type of weakness. They can result from a compromised account, an unknown vulnerability, third-party software, a logistics provider, poor data governance, a misconfigured infrastructure, or a dependency that no one had until then considered particularly critical.

The challenge therefore goes well beyond protecting a network. An organization must understand and monitor a digital ecosystem made up of its infrastructures, its identities, its data, its suppliers, its cloud applications, its software, its partners, and now its artificial intelligence systems. This complexity should lead executives, IT teams, cybersecurity leaders, and their technology partners to consider the value of a second line of vigilance capable of observing risks in a cross-cutting, independent, and continuous way.

The purpose of this upper layer is not to replace those who already know and operate the environment. It aims to give them an additional capability to understand the relationships between the various components, identify blind spots, and examine the risks that appear precisely between several areas of responsibility. It is in this space that Quantum Beyond seeks to work alongside internal teams.

Recent news unfortunately illustrates the diversity of paths that can lead to a data breach. In Quebec, the Commission de la construction du Québec detected a cyberattack on August 24 and temporarily suspended several services in order to protect its systems and carry out the necessary checks. A few days later, the organization confirmed that some personal information belonging to clients and employees had been stolen and announced various support measures for the people concerned.

Other incidents reveal very different scenarios. Trezor, a manufacturer of hardware wallets for cryptocurrencies, announced that an incident at its logistics provider ShipMonk had exposed the contact details of thousands of customers. The case is particularly instructive because Trezor states that it repeatedly requested the deletion of old data and received written confirmations indicating that this had been done. Yet some of that information still existed in the provider’s systems when it was compromised.

This situation highlights an essential distinction between policy, compliance, and operational reality. An organization can have a data retention policy, set out contractual obligations, request deletion, and obtain written confirmation from its supplier. The risk may nevertheless persist if the data still exists somewhere in the technology chain. Modern cybersecurity must therefore go beyond asking whether a rule exists and also seek to determine whether the organization has sufficient means to verify that reality matches what it believes to be true.

This verification requirement becomes fundamental as organizations outsource a growing share of their technological capabilities. Cloud, SaaS software, CRM, ERP, payroll, human resources, communications, backups, analytics, marketing, artificial intelligence, hosting, logistics, and development can all depend on different suppliers. This outsourcing delivers considerable value by providing access to technologies and skills that would be difficult or pointless to develop entirely in-house. At the same time, it increases the number of digital relationships on which the company’s operations depend.

The Framework case provides another illustration. The computer manufacturer had to inform some customers that a breach had exposed various personal contact details following an upstream attack against Metabase, a provider of business intelligence tools. The attackers are reported to have exploited an unknown vulnerability allowing access to databases hosted in the provider’s cloud environment.

The client company’s IT team therefore does not need to make a mistake itself for its data to be compromised. A supplier can be attacked, as can that supplier’s supplier. A software library may contain a vulnerability, an access key may be exposed, an old database may have been kept, or a connector installed several years earlier may hold permissions that have become excessive.

An organization’s real cybersecurity surface increasingly corresponds to the whole set of digital relationships that allow it to operate. This reality explains the growing importance of attacks targeting the technology supply chain. A weakness present at a single supplier can simultaneously become a risk for dozens, hundreds, or thousands of customers.

This complexity in no way means that IT teams are not doing their job properly. In many organizations, they are doing exactly the opposite. They maintain infrastructures, administer users, respond to requests, deploy updates, manage the cloud, monitor backups, support employees, coordinate suppliers, respond to incidents, and at the same time try to keep up with the constant evolution of technologies and threats.

The problem gradually becomes one of attention capacity. A team can be extremely competent while remaining absorbed by its operational responsibilities. Its deep knowledge of the environment is an essential strength, but that closeness can also make certain dependencies less visible because they have long been part of the organization’s normal functioning.

Technology suppliers face a comparable situation. Each has its own expertise and its own scope. The network provider watches the network, the cloud provider masters its environment, the ERP vendor protects its platform, and the internal team knows its operations. Yet a cyberattack does not respect the boundaries between mandates. It looks for the available path, and the decisive weakness can lie precisely between two areas of responsibility.

A second line of vigilance then takes on its full meaning. It is not meant to administer workstations in place of IT, manage the network in place of the supplier, replace the cloud specialist, or take over the responsibilities of the experts already in place. Its role consists in examining how these components interact and looking for the areas where their boundaries can create blind spots.

This perspective leads naturally from cybersecurity toward a broader architectural view. When an organization suffers a breach, identifying the point of entry remains essential. You have to understand how the attacker got in, which vulnerability was exploited, or which identity was compromised. The analysis must then go further and seek to determine why the attacker was able to move so deeply through the environment.

Why could that identity access that data? Why did that application hold so many permissions? Why was some information still being retained? Why could a supplier reach that resource? Why was the data not better segmented? Why did that activity not trigger an alert? How could an initially limited compromise become an incident affecting a far larger part of the organization?

These questions gradually shift the analysis from vulnerability to architecture. An attack may begin with a single weakness, while its scale often depends on everything that becomes accessible after that first compromise. Zero Trust, the principle of least privilege, IAM, segmentation, data classification, and behavioral monitoring then make it possible to reduce the blast radius when a control eventually fails.

No serious expert can promise the complete elimination of risk. An unknown vulnerability may be discovered tomorrow, an employee may be deceived, a supplier may be compromised, a configuration may contain an error, and an artificial intelligence may eventually identify a weakness no one had yet noticed. A responsible approach therefore seeks to reduce the likelihood of an incident, increase the chances of detecting it quickly, limit its spread, and allow the organization to recover effectively when something happens.

It is precisely at this level that the notion of Hypersecurity becomes relevant. It does not replace cybersecurity and its fundamental disciplines. It provides an architectural, operational, and governance framework that connects technical protections to the full set of dependencies that today determine the organization’s actual security. Identities, data, knowledge, infrastructures, suppliers, artificial intelligence, cryptography, resilience, and sovereignty must be observable as different dimensions of one and the same system.

Hypersecurity thus seeks to maintain a global and continuous view of the environment. It recognizes that the trust granted to an identity, an application, a supplier, or a system should never become permanent simply because a validation was performed in the past. Conditions change, permissions evolve, suppliers modify their infrastructures, new vulnerabilities appear, and technological capabilities advance. Trust must therefore be verifiable and reassessed continuously.

This approach also makes it easier to understand why data governance is becoming an essential component of security. The Trezor case is a reminder that the easiest data to protect is sometimes the data the organization no longer needs to keep. Companies accumulate historical databases, backups, copies intended for analysis, test environments, and information retained by various suppliers. Each additional copy potentially creates a new surface to protect.

An organization should therefore know what data it holds, where it is located, why it is being kept, who can access it, what copies exist, and how long it remains necessary. This discipline becomes even more important with artificial intelligence, since companies want to connect a growing share of their knowledge to models and agents capable of establishing relationships between information that was previously scattered.

AI’s ability to interpret and correlate data simultaneously increases its value and the potential consequences of its exposure. A set of documents that seem relatively insensitive when examined individually can make it possible to reconstruct a considerable amount of organizational knowledge when an intelligent system can analyze them together. Data protection must therefore gradually take into account the potential for combination and inference.

For this reason, vigilance must run across the entire organization. Executives choose certain directions and certain suppliers, finance authorizes investments, human resources holds extremely sensitive information, marketing collects customer data, sales use multiple applications, operations connect equipment, employees adopt new artificial intelligence tools, procurement negotiates contracts, and legal teams define various obligations. IT must then integrate and secure a large part of that environment.

Cybersecurity thus becomes a shared organizational responsibility. That does not mean every employee or every manager has to become a security expert. Rather, the organization must have enough expertise to connect decisions to one another and understand their cumulative consequences. A new application should not be assessed solely on its price and its features, but also on the data it will receive, its subcontractors, its identity mechanisms, its permissions, its interfaces, its retention practices, its contractual obligations, and the possible consequences of a compromise.

Digital due diligence therefore begins well before a technology is installed. It must also continue throughout its lifetime, because a decision that was perfectly reasonable at the time of acquisition may present a very different risk profile a few years later.

It is precisely in this space that Quantum Beyond can work alongside organizations. Many already have excellent IT teams, some also have cybersecurity specialists, and others work with IT suppliers, network experts, cloud integrators, or specialized consultants. These resources are essential and hold a knowledge of the environment that external expertise should never seek to replace.

Quantum Beyond adds an upper layer of expertise in architecture, Hypersecurity, governance, and resilience that works with these teams. That layer examines infrastructures, identities, data, suppliers, cloud, artificial intelligence, dependencies, cryptography, processes, and governance mechanisms across the board. It looks in particular for the questions that fall between several mandates and the assumptions on which certain controls rest.

This intellectual independence can bring considerable value. Outside expertise can challenge an architecture without having to defend the historical decisions that led to its construction. It can examine a dependency that has become so normal that it is no longer spontaneously regarded as a risk, help teams prioritize the vulnerabilities that genuinely matter, and provide specialized skills that would be difficult or costly to maintain full time in every organization.

In several critical fields, a second opinion is already considered a normal practice of due diligence. Financial statements are audited, buildings are inspected, quality systems are assessed, and certain important decisions are reviewed by several specialists. As digital systems become essential to operations and the consequences of a compromise increase, cybersecurity too deserves this capacity for re-examination.

Quantum Beyond’s contribution can thus be understood as a second line of technological vigilance set within a Hypersecurity approach. It does not promise that a cyberattack will never happen. It seeks to increase the chances that a weakness will be identified before it is exploited, that a dependency will be understood before it becomes critical, that an excessive permission will be corrected before it is used, and that an incident will be detected and contained before producing disproportionate consequences.

This layer can draw on several complementary areas of expertise: enterprise security architecture, security audit and assessment, IAM, Zero Trust and Continuous Trust, data and knowledge governance, cyber resilience, sovereign digital defense, post-quantum readiness, AI governance, and technology dependency analysis. Their value lies as much in each of these disciplines as in their ability to work together.

The objective is therefore not to keep adding more and more technologies in order to create the impression of being better protected. It is to increase the organization’s capacity for understanding. In an environment that has become extremely complex, a significant share of the risk lies precisely in the dependencies, interactions, and assumptions that no one is yet observing as a whole.

This capacity for understanding also has an important dimension of accountability and due diligence. No executive can reasonably claim to have eliminated all IT risk. An organization can, however, demonstrate that it has taken serious measures to know its risks, reduce them, monitor them, and prepare its teams to respond.

Due diligence does not consist in guaranteeing that no incident will occur. It consists in being able to demonstrate that risks have been considered, that the necessary expertise has been mobilized, that important recommendations have been assessed, that responsibilities have been defined, and that the organization is continuously seeking to improve its posture. Vigilance then becomes a lasting organizational capability rather than a one-off reaction to each new threat.

Recent data breaches do not all tell the same story. Some begin directly within the organization, others at a supplier. Some exploit a technical vulnerability, others compromised credentials. Some expose recently collected data, while others reveal that information believed to have been deleted still existed several years later.

What they have in common is the growing complexity of our digital environments. We have built organizations in which data passes through dozens of systems, suppliers, identities, applications, networks, and now artificial intelligence systems. Each of these relationships creates value, and each also introduces a dependency that must be understood and governed.

In this context, asking IT teams alone to see everything, know everything, and anticipate everything becomes unrealistic. The same is true of technology partners, each of whom necessarily has their own scope of responsibility. An organization can be very well supported, have excellent specialists, and still benefit from a second line of vigilance capable of examining the relationships between these various areas of expertise across the board.

It is in this evolution that Hypersecurity takes on its full meaning. It extends the fundamental disciplines of cybersecurity with a global view connecting architecture, identities, data, knowledge, suppliers, artificial intelligence, cryptography, resilience, sovereignty, and governance. It seeks to strengthen the organization’s ability to anticipate, withstand, detect, contain, recover, and learn in a digital environment that is continuously evolving.

Quantum Beyond wants to bring this upper layer alongside internal teams and their partners. Examining the environment from a cross-cutting perspective, challenging assumptions, identifying dependencies, looking for blind spots, bringing in specialized expertise when the need exceeds available capacity, and helping executives understand the risks they accept all strengthen the protections already built without taking control of the environment away from the teams.

This approach will never make it possible to guarantee that no data will be stolen or that no vulnerability will be exploited. It can, however, make the organization more vigilant in what it observes, more diligent in the decisions it makes, more resilient when a control fails, and more accountable in how it protects the information entrusted to it. In an environment where attackers are continuously looking for the available path and the link no one is watching, adding a second line of vigilance does not mean the previous ones have failed. It means that the defense, too, must learn to observe the organization in all its depth.