ao link
Menu
Teiss - Cracking Cyber Security
Teiss - Cracking Cyber Security

teissTalk: Live at teissLondon2025: From gatekeeping to guardrails - proactive supply chain security at scale

On 18 September 2025, teissTalk host Thom Langford was joined by Paul Holland, Cyber Capability Manager, Royal Mail; Tiago Rosado, Chief Information Security Officer, Asite; Jean Carlos, Information Security Lead, Trade Republic; and John Smith, CTO of EMEA, Veracode.

 

Views on news

 

Cybersecurity providers Tenable and Qualys are the latest in a growing list of companies affected by a significant supply chain attack targeting Salesforce customer data. The campaign involved the theft of OAuth authentication tokens connected to Salesloft Drift, a third-party application integrated with Salesforce used to automate workflows and manage leads and contact information. Supply chains are now so interconnected that if there is a breach, it ripples across these extensive networks. One of the most typical vulnerabilities are exposed APIs without mutual authentication. Uniquely, in the case of the Salesdrift hack, the main concern wasn’t business interruption but data loss.

 

Also, the hackers weren’t after the gold nuggets of data in the Salesforce system but credentials. There is also the risk of those procurement leaders whose credentials were stolen getting phished in the future. With more cybersecurity fundamentals in place, Salesloft could probably have prevented the large-scale data breach and would’ve warned clients to rotate their keys – frameworks like NIST recommend an annual rotation for data encryption keys, which is a minimum requirement and ideally, it’s done more often than that. 

 

How AI affects API security

 

70 per cent of critical security debt stems from third party code. Therefore, it’s key to know what code (SBOM) and dependencies you have in-house, including open source. If a company has a high level of transparency, finding out whether it’s exposed to a new attack will only take minutes. Prioritising vulnerabilities, however, can be overwhelming for large companies with huge amount of data and tens of thousands of vulnerabilities, which can only be managed with the help of EPSS (exploit prediction scoring system) and some other tools. Once you are aware of your exposure, decision-makers in the business must own the risk. (In an emerging trend, cyber risk is the responsibility of the CFO.) A lot of the vulnerabilities can be traced back to software licences or, rather, the lack of them – a problem that must be addressed by replacing them with a suitable library.  


Threat intelligence about a third party must always be validated to ensure that there are no false positives. With DORA, businesses have only 12 hours to report an incident and 12 more to provide evidence about its occurrence. Remember, regulators are more interested in the impacts a breach has on the economy and the society than the minutiae of the hack and what they want to get from the victim is a remediation path to ensure  that the same won’t happen again. 

 

The panel’s advice

  • If you’re attacked, you must be able to explain to regulators why you took certain measures and support that with documents. So always have a convincing audit trail.
  • Business must sooner or later realise that they can leverage security and data privacy for their sales pitch and see their implementation as drivers of their competitive advantage.
  • Shifting left or integrating security into software development is a great concept but can’ be applied to legacy code.
  • The OWASP Top 10 will give software developers a good idea of what vulnerabilities must be addressed when writing the code. 

Please take 30 seconds to register

Register Now

 

Already have an account? Sign in

Remember Login
Teiss - Cracking Cyber Security

Subscribe to our Weekly Newsletter

Receive the latest insights direct to your inbox, and gain access to our exclusive events.
Teiss - Cracking Cyber Security

Winstone House, 3rd Floor,
Units 306-309, 2-4 Dollis park,
London, N3 1HF

 

020 8349 4363

info@teiss.co.uk

 © 2026, Lyonsdown Limited. teiss® is a registered trademark of Lyonsdown Ltd. VAT registration number: 830519543