NZ Herald
  • Home
  • Latest news
  • Herald NOW
  • Video
  • New Zealand
  • Sport
  • World
  • Business
  • Entertainment
  • Podcasts
  • Quizzes
  • Opinion
  • Lifestyle
  • Travel
  • Viva
  • Weather

Subscriptions

  • Herald Premium
  • Viva Premium
  • The Listener
  • BusinessDesk

Sections

  • Latest news
  • New Zealand
    • All New Zealand
    • Crime
    • Politics
    • Education
    • Open Justice
    • Scam Update
  • Herald NOW
  • On The Up
  • World
    • All World
    • Australia
    • Asia
    • UK
    • United States
    • Middle East
    • Europe
    • Pacific
  • Business
    • All Business
    • MarketsSharesCurrencyCommoditiesStock TakesCrypto
    • Markets with Madison
    • Media Insider
    • Business analysis
    • Personal financeKiwiSaverInterest ratesTaxInvestment
    • EconomyInflationGDPOfficial cash rateEmployment
    • Small business
    • Business reportsMood of the BoardroomProject AucklandSustainable business and financeCapital markets reportAgribusiness reportInfrastructure reportDynamic business
    • Deloitte Top 200 Awards
    • CompaniesAged CareAgribusinessAirlinesBanking and financeConstructionEnergyFreight and logisticsHealthcareManufacturingMedia and MarketingRetailTelecommunicationsTourism
  • Opinion
    • All Opinion
    • Analysis
    • Editorials
    • Business analysis
    • Premium opinion
    • Letters to the editor
  • Politics
  • Sport
    • All Sport
    • OlympicsParalympics
    • RugbySuper RugbyNPCAll BlacksBlack FernsRugby sevensSchool rugby
    • CricketBlack CapsWhite Ferns
    • Racing
    • NetballSilver Ferns
    • LeagueWarriorsNRL
    • FootballWellington PhoenixAuckland FCAll WhitesFootball FernsEnglish Premier League
    • GolfNZ Open
    • MotorsportFormula 1
    • Boxing
    • UFC
    • BasketballNBABreakersTall BlacksTall Ferns
    • Tennis
    • Cycling
    • Athletics
    • SailingAmerica's CupSailGP
    • Rowing
  • Lifestyle
    • All Lifestyle
    • Viva - Food, fashion & beauty
    • Society Insider
    • Royals
    • Sex & relationships
    • Food & drinkRecipesRecipe collectionsRestaurant reviewsRestaurant bookings
    • Health & wellbeing
    • Fashion & beauty
    • Pets & animals
    • The Selection - Shop the trendsShop fashionShop beautyShop entertainmentShop giftsShop home & living
    • Milford's Investing Place
  • Entertainment
    • All Entertainment
    • TV
    • MoviesMovie reviews
    • MusicMusic reviews
    • BooksBook reviews
    • Culture
    • ReviewsBook reviewsMovie reviewsMusic reviewsRestaurant reviews
  • Travel
    • All Travel
    • News
    • New ZealandNorthlandAucklandWellingtonCanterburyOtago / QueenstownNelson-TasmanBest NZ beaches
    • International travelAustraliaPacific IslandsEuropeUKUSAAfricaAsia
    • Rail holidays
    • Cruise holidays
    • Ski holidays
    • Luxury travel
    • Adventure travel
  • Kāhu Māori news
  • Environment
    • All Environment
    • Our Green Future
  • Talanoa Pacific news
  • Property
    • All Property
    • Property Insider
    • Interest rates tracker
    • Residential property listings
    • Commercial property listings
  • Health
  • Technology
    • All Technology
    • AI
    • Social media
  • Rural
    • All Rural
    • Dairy farming
    • Sheep & beef farming
    • Horticulture
    • Animal health
    • Rural business
    • Rural life
    • Rural technology
    • Opinion
    • Audio & podcasts
  • Weather forecasts
    • All Weather forecasts
    • Kaitaia
    • Whangārei
    • Dargaville
    • Auckland
    • Thames
    • Tauranga
    • Hamilton
    • Whakatāne
    • Rotorua
    • Tokoroa
    • Te Kuiti
    • Taumaranui
    • Taupō
    • Gisborne
    • New Plymouth
    • Napier
    • Hastings
    • Dannevirke
    • Whanganui
    • Palmerston North
    • Levin
    • Paraparaumu
    • Masterton
    • Wellington
    • Motueka
    • Nelson
    • Blenheim
    • Westport
    • Reefton
    • Kaikōura
    • Greymouth
    • Hokitika
    • Christchurch
    • Ashburton
    • Timaru
    • Wānaka
    • Oamaru
    • Queenstown
    • Dunedin
    • Gore
    • Invercargill
  • Meet the journalists
  • Promotions & competitions
  • OneRoof property listings
  • Driven car news

Puzzles & Quizzes

  • Puzzles
    • All Puzzles
    • Sudoku
    • Code Cracker
    • Crosswords
    • Cryptic crossword
    • Wordsearch
  • Quizzes
    • All Quizzes
    • Morning quiz
    • Afternoon quiz
    • Sports quiz

Regions

  • Northland
    • All Northland
    • Far North
    • Kaitaia
    • Kerikeri
    • Kaikohe
    • Bay of Islands
    • Whangarei
    • Dargaville
    • Kaipara
    • Mangawhai
  • Auckland
  • Waikato
    • All Waikato
    • Hamilton
    • Coromandel & Hauraki
    • Matamata & Piako
    • Cambridge
    • Te Awamutu
    • Tokoroa & South Waikato
    • Taupō & Tūrangi
  • Bay of Plenty
    • All Bay of Plenty
    • Katikati
    • Tauranga
    • Mount Maunganui
    • Pāpāmoa
    • Te Puke
    • Whakatāne
  • Rotorua
  • Hawke's Bay
    • All Hawke's Bay
    • Napier
    • Hastings
    • Havelock North
    • Central Hawke's Bay
    • Wairoa
  • Taranaki
    • All Taranaki
    • Stratford
    • New Plymouth
    • Hāwera
  • Manawatū - Whanganui
    • All Manawatū - Whanganui
    • Whanganui
    • Palmerston North
    • Manawatū
    • Tararua
    • Horowhenua
  • Wellington
    • All Wellington
    • Kapiti
    • Wairarapa
    • Upper Hutt
    • Lower Hutt
  • Nelson & Tasman
    • All Nelson & Tasman
    • Motueka
    • Nelson
    • Tasman
  • Marlborough
  • West Coast
  • Canterbury
    • All Canterbury
    • Kaikōura
    • Christchurch
    • Ashburton
    • Timaru
  • Otago
    • All Otago
    • Oamaru
    • Dunedin
    • Balclutha
    • Alexandra
    • Queenstown
    • Wanaka
  • Southland
    • All Southland
    • Invercargill
    • Gore
    • Stewart Island
  • Gisborne

Media

  • Video
    • All Video
    • NZ news video
    • Herald NOW
    • Business news video
    • Politics news video
    • Sport video
    • World news video
    • Lifestyle video
    • Entertainment video
    • Travel video
    • Markets with Madison
    • Kea Kids news
  • Podcasts
    • All Podcasts
    • The Front Page
    • On the Tiles
    • Ask me Anything
    • The Little Things
  • Cartoons
  • Photo galleries
  • Today's Paper - E-editions
  • Photo sales
  • Classifieds

NZME Network

  • Advertise with NZME
  • OneRoof
  • Driven Car Guide
  • BusinessDesk
  • Newstalk ZB
  • Sunlive
  • ZM
  • The Hits
  • Coast
  • Radio Hauraki
  • The Alternative Commentary Collective
  • Gold
  • Flava
  • iHeart Radio
  • Hokonui
  • Radio Wanaka
  • iHeartCountry New Zealand
  • Restaurant Hub
  • NZME Events

SubscribeSign In
Advertisement
Advertise with NZME.
Home / Business

Juha Saarinen: When you can’t trust your cyber security vendors

Juha Saarinen
By Juha Saarinen
Tech blogger for nzherald.co.nz.·NZ Herald·
24 Oct, 2023 04:00 PM4 mins to read

Subscribe to listen

Access to Herald Premium articles require a Premium subscription. Subscribe now to listen.
Already a subscriber?  Sign in here

Listening to articles is free for open-access content—explore other articles or learn more about text-to-speech.
‌
Save

    Share this article

    Reminder, this is a Premium article and requires a subscription to read.

Customers have had to take it on trust that cyber security vendors know what they’re doing and are able to keep themselves safe. Photo / 123RF

Customers have had to take it on trust that cyber security vendors know what they’re doing and are able to keep themselves safe. Photo / 123RF

Juha Saarinen
Opinion by Juha Saarinen
Tech writer for NZ Herald.
Learn more

OPINION

The big problem with cyber security is that customers have to trust the providers of it.

To be effective, cyber security providers need access to all nooks and crannies of information processing systems, so that they can check if anything untoward is happening there.

That’s a very privileged position, and it’s a very risky one. Ever since the day of anti-viruses, security vendors placing themselves in that position have had bull’s eyes painted on their backs.

Breach a security vendor’s software, hardware or systems and it’s open sesame time for hackers.

Advertisement
Advertise with NZME.

Customers meanwhile have had to take it on trust that cyber security vendors know what they’re doing and are able to keep themselves safe.

That trust can be dangerous, as the recent breach of Okta, a large American identity and access management company that many enterprises use has shown.

Okta’s business is to authenticate users and provide them with secure access to corporate systems. That’s about as privileged a position as it gets in any organisation.

Advertisement
Advertise with NZME.

For the second time, Okta’s support system was breached by unknown hackers who were able to get their hands on system access tokens which were embedded in files customers sent in for troubleshooting.

Okta however did not detect it had been compromised. Instead, two of its customers spotted the hack after they were attacked.

Unfortunately for Okta, one customer was security vendor BeyondTrust which was founded by Marc Maiffret.

Maiffret is something of an infosec legend having discovered the infamous Code Red Windows worm malware with Ryan Permeh in 2001. What he says carries weight.

BeyondTrust reported the compromise to Okta which didn’t acknowledge the breach for over two weeks. The long and inexcusable delay was made public by BeyondTrust, and ended up in the news.

Reverse proxy and internet security company Cloudflare is also an Okta customer. It too spotted the compromise after foiling an Okta-connected hack attempt.

This is the second time Cloudflare’s been attacked via Okta. The first time was in March last year when a hacker got access to an Okta support staffer’s account and used it to attack Cloudflare and other internet companies.

Cloudflare was clearly annoyed at the second hack attack and gave Okta a sick burn in a blog post that provided recommendations for the identity and access management vendor on how it could secure itself.

Advertisement
Advertise with NZME.

How Okta will recover from the above embarrassing fiasco remains to be seen, but it’s not unique for companies in trusted positions to screw up magnificently.

Barracuda Networks’ Email Security Gateway device is a recent standout example of that. The devices, popular with many corporates, were compromised in large numbers and so thoroughly that Barracuda told customers to junk their existing gear and replace them with new ones.

Networking giant, Cisco had to scramble to release patches for the operating system that runs many of its routers and switches after hackers discovered a way to add administrative accounts remotely to them, which gave them full control of the devices. Some 42,000 devices were estimated to have been hacked.

The epic SolarWinds “Sunburst” hacks, allegedly perpetrated by Russia in 2019 also warrant a mention. SolarWinds software is used to manage and control systems and networks, so when hackers were able to plant backdoor access malware into the code, it became one of the most successful attacks ever.

American government departments were hit along with well-known security vendor FireEye, and the compromises took a long time to get detected and fixed. This month, SolarWinds had to release patches for three critical remote code execution bugs in its Access Manager software.

“Hackcidents” can and will happen and that should be everyone’s default assumption.

Vendors that are in a privileged position in information systems and networks have been high value hacker targets for a long time now. There are no guarantees that their software and hardware is bug-proof, or that all their processes are robust and without gaps that can be exploited.

Furthermore, as recent and past experience has shown, vendor responsiveness when things go wrong can be found wanting.

Having the ability to detect anomalies is a must for any organisation running IT systems and networks, along with plans for what to do when they’re. For customers, and not just of security vendors, the lesson here is not to outsource trust. Do that, and you’ll live to regret it sooner rather than later.

Save

    Share this article

    Reminder, this is a Premium article and requires a subscription to read.

Latest from Business

Media Insider

TVNZ boss on the future of the 6pm news, Shortland Street - and a move into pay TV

19 Jun 09:37 AM
Premium
Shares

Market close: GDP beats forecasts but NZ sharemarket dips

19 Jun 06:24 AM
Premium
Business

Innovation milestone: NZ approves lab-grown quail for consumption

19 Jun 04:34 AM

Audi offers a sporty spin on city driving with the A3 Sportback and S3 Sportback

sponsored
Advertisement
Advertise with NZME.

Latest from Business

TVNZ boss on the future of the 6pm news, Shortland Street - and a move into pay TV

TVNZ boss on the future of the 6pm news, Shortland Street - and a move into pay TV

19 Jun 09:37 AM

Will this be Simon Dallow's swansong year as the 6pm newsreader?

Premium
Market close: GDP beats forecasts but NZ sharemarket dips

Market close: GDP beats forecasts but NZ sharemarket dips

19 Jun 06:24 AM
Premium
Innovation milestone: NZ approves lab-grown quail for consumption

Innovation milestone: NZ approves lab-grown quail for consumption

19 Jun 04:34 AM
$162k in cash, almost $400k in equipment seized in scam crackdown last year

$162k in cash, almost $400k in equipment seized in scam crackdown last year

19 Jun 04:29 AM
Gold demand soars amid global turmoil
sponsored

Gold demand soars amid global turmoil

NZ Herald
  • About NZ Herald
  • Meet the journalists
  • Newsletters
  • Classifieds
  • Help & support
  • Contact us
  • House rules
  • Privacy Policy
  • Terms of use
  • Competition terms & conditions
  • Our use of AI
Subscriber Services
  • NZ Herald e-editions
  • Daily puzzles & quizzes
  • Manage your digital subscription
  • Manage your print subscription
  • Subscribe to the NZ Herald newspaper
  • Subscribe to Herald Premium
  • Gift a subscription
  • Subscriber FAQs
  • Subscription terms & conditions
  • Promotions and subscriber benefits
NZME Network
  • The New Zealand Herald
  • The Northland Age
  • The Northern Advocate
  • Waikato Herald
  • Bay of Plenty Times
  • Rotorua Daily Post
  • Hawke's Bay Today
  • Whanganui Chronicle
  • Viva
  • NZ Listener
  • Newstalk ZB
  • BusinessDesk
  • OneRoof
  • Driven Car Guide
  • iHeart Radio
  • Restaurant Hub
NZME
  • About NZME
  • NZME careers
  • Advertise with NZME
  • Digital self-service advertising
  • Book your classified ad
  • Photo sales
  • NZME Events
  • © Copyright 2025 NZME Publishing Limited
TOP