On 18 September 2025, teissTalk host Thom Langford was joined by Paul Holland, Cyber Capability Manager, Royal Mail; Tiago Rosado, Chief Information Security Officer, Asite; Jean Carlos, Information Security Lead, Trade Republic; and John Smith, CTO of EMEA, Veracode.
Cybersecurity providers Tenable and Qualys are the latest in a growing list of companies affected by a significant supply chain attack targeting Salesforce customer data. The campaign involved the theft of OAuth authentication tokens connected to Salesloft Drift, a third-party application integrated with Salesforce used to automate workflows and manage leads and contact information. Supply chains are now so interconnected that if there is a breach, it ripples across these extensive networks. One of the most typical vulnerabilities are exposed APIs without mutual authentication. Uniquely, in the case of the Salesdrift hack, the main concern wasn’t business interruption but data loss.
Also, the hackers weren’t after the gold nuggets of data in the Salesforce system but credentials. There is also the risk of those procurement leaders whose credentials were stolen getting phished in the future. With more cybersecurity fundamentals in place, Salesloft could probably have prevented the large-scale data breach and would’ve warned clients to rotate their keys – frameworks like NIST recommend an annual rotation for data encryption keys, which is a minimum requirement and ideally, it’s done more often than that.
70 per cent of critical security debt stems from third party code. Therefore, it’s key to know what code (SBOM) and dependencies you have in-house, including open source. If a company has a high level of transparency, finding out whether it’s exposed to a new attack will only take minutes. Prioritising vulnerabilities, however, can be overwhelming for large companies with huge amount of data and tens of thousands of vulnerabilities, which can only be managed with the help of EPSS (exploit prediction scoring system) and some other tools. Once you are aware of your exposure, decision-makers in the business must own the risk. (In an emerging trend, cyber risk is the responsibility of the CFO.) A lot of the vulnerabilities can be traced back to software licences or, rather, the lack of them – a problem that must be addressed by replacing them with a suitable library.
Threat intelligence about a third party must always be validated to ensure that there are no false positives. With DORA, businesses have only 12 hours to report an incident and 12 more to provide evidence about its occurrence. Remember, regulators are more interested in the impacts a breach has on the economy and the society than the minutiae of the hack and what they want to get from the victim is a remediation path to ensure that the same won’t happen again.
Winstone House, 3rd Floor,
Units 306-309, 2-4 Dollis park,
London, N3 1HF
020 8349 4363
© 2026, Lyonsdown Limited. teiss® is a registered trademark of Lyonsdown Ltd. VAT registration number: 830519543