Logo
Cybersecurity

One Compromised System Rarely Stays One Compromised System

Modern incidents travel through dependencies. Security teams need people who can work out where the damage could go next.

ITSEC AsiaITSEC Asia
|
Sep 30, 2026
One Compromised System Rarely Stays One Compromised System

A business application stops working.

The server itself is fine. The network looks normal. Authentication is available. Then someone discovers that an external service used by the application is unavailable.

Suddenly the incident diagram gets bigger.

ENISA’s Threat Landscape 2026, published on 22 September and discussed in a dedicated webinar on 29 September, puts this problem near the centre of its analysis. ENISA says the growing interconnectedness of digital ecosystems is increasing exposure to cyber risk and continues to observe attacks targeting dependencies, including supply chain and third party relationships. ENISA

For workforce development, there’s a practical lesson here: cybersecurity professionals need to understand dependencies as well as assets.

An Asset List Doesn’t Show the Whole Risk

Knowing what systems an organization owns is useful.

Knowing what those systems rely on is different.

A customer portal might depend on an identity provider, DNS, cloud infrastructure, payment service, API, software library and managed service. Several other applications may rely on exactly the same components.

Compromise one shared dependency and the blast radius changes quickly.

Security teams therefore need skills to identify:

  • Which external services support critical business functions
  • Which applications share the same infrastructure or provider
  • Where software and data originate
  • Which dependencies have privileged access
  • What happens if a dependency becomes unavailable
  • Which alternative processes exist when a service fails
  • Who owns the relationship when investigation or recovery is required

The last question has a habit of becoming surprisingly difficult at 2 a.m.

Incident Response Needs a Dependency View

Dependency knowledge changes how people investigate incidents.

Suppose unusual activity appears in three applications simultaneously. Looking at each application separately may produce three investigations. Knowing that all three depend on the same identity service immediately creates another hypothesis.

The same principle applies to recovery.

Restoring a server doesn’t restore a business process if a required external service remains unavailable. A technically healthy application may still be unusable because its authentication, API or data provider has failed.

ENISA reports that 73% of organizations targeted in the incidents it analysed were entities classified as essential or important under NIS2. Its analysis also says cyber dependencies can increase the scale and impact of incidents across interconnected infrastructure. ENISA

Cyber resilience therefore requires people who can reason across organizational boundaries.

Put Dependencies Into the Exercise

Training can make this capability visible.

Give learners a simulated organization containing several applications, shared infrastructure and external services. Provide the architecture, but don’t reveal every dependency.

Then trigger an incident at one supplier.

Participants must discover which services rely on it, determine what evidence is available, assess business impact and decide which teams or external parties need to be involved.

A more difficult version introduces a recovery decision that fixes one system while breaking another dependency.

This type of scenario fits practical learning at ITSEC Cyber & AI Academy, where cyber range exercises can connect technical investigation with architecture, incident response and operational decision making.

Security teams already ask, “What happened?”

The next useful question is often, “What else depends on it?”

Explore practical cybersecurity and AI training at ITSEC Cyber & AI Academy.

References: ENISA Threat Landscape 2026, 22 September 2026 · ENISA: How Dependencies Weaken Digital Resilience · ENISA Threat Landscape Webinar, 29 September 2026

Share this post

You may also like

Indonesia’s Cybersecurity Talent Problem Is Becoming a Skills Problem
Cybersecurity

Indonesia’s Cybersecurity Talent Problem Is Becoming a Skills Problem

cybersecurity indonesia
cyber security indonesia
cybersecurity di indonesia
cyber security di indonesia
cybersecurity in indonesia
cyber security in indonesia

Indonesia needs more cybersecurity professionals. That part is obvious. What is becoming less obvious is whether the real problem is still about numbers. The 2026 SANS | GIAC Cybersecurity Workforce Research Report found that 60% of surveyed organizations said their teams lacked the right skills to defend against current threats. More concerning, 27% reported breaches directly linked to capability gaps. That changes the conversation. A company can have a security team, a dashboard full of alerts and a stack of expensive tools. The harder question is whether the people behind them know what to do when something unusual happens. CYBERSECURITY WORK IS MOVING FAST Artificial intelligence is making that question harder. AI can already help with alert analysis, vulnerability prioritization and repetitive investigation tasks. Attackers can use the same technology to make attacks faster and easier to scale. In August 2026, Vice Minister of Communication and Digital Affairs Nezar Patria warned that agentic AI could allow cyberattacks to operate with less direct human involvement. He also highlighted threats such as harvest

ITSEC AsiaITSEC Asia
|
Sep 01, 2026 — 3 minutes read
Top Five Cybersecurity Threats to Small Business Owners
Cybersecurity

Top Five Cybersecurity Threats to Small Business Owners

According to a recent Verizon Data Breach Investigations Report, over the past two years, small and medium-sized businesses have become the primary target of cybercriminals, and they are now more affected by cyber breaches than large-scale businesses. Cyberattacks on SMEs have increased because cybercriminals have predicted that small and medium-sized enterprises have fewer resources to dedicate to their security. Most SMEs lack dedicated security professionals, and they are too small to afford them. This makes them vulnerable and easy targets for cybercriminals. In this context, neglecting security is no longer an option, and the assumption that your business is too small to attract the interest of cybercriminals is unrealistic. TOP FIVE CYBER THREATS AFFECTING SMALL AND MEDIUM-SIZED ENTERPRISES Incompatible Operating Systems and Software: Ensure that your computers and the software running on them are up to date. This is crucial and forms a solid foundation for good security practices. Hackers exploit vulnerabilities in outdated software and operating systems, often infiltrating organizations. Failing to apply software and operating system updates when they

ITSEC AsiaITSEC Asia
|
Jul 20, 2023 — 5 minutes read
7 Main Criteria for Quality Managed Security Services Providers That Every Company Must Know
Cybersecurity

7 Main Criteria for Quality Managed Security Services Providers That Every Company Must Know

INTRODUCTION Cyber threats no longer wait for companies to let their guard down. Attacks occur at any time, across sectors, and are increasingly difficult to detect without an integrated monitoring system. According to Gartner, 90% of non-executive board members have no confidence in the value their organizations receive from cybersecurity investments, a gap that continues to widen between leadership expectations and internal team capacity. This is where Managed Security Services (MSS) plays a role. However, not all service providers offer equal protection. Many companies only realize the weaknesses of their vendors when an incident has already occurred. This article discusses seven criteria that should serve as an evaluation reference before you sign a contract with a Managed Security Services provider. Source: gartner.com [http://gartner.com], issglobal.com [https://issglobal.com/perspectives/what-are-managed-security-services/] WHY CHOOSING THE RIGHT MSS IS CRITICALLY IMPORTANT? Throughout 2024 to 2025, companies in the healthcare, automotive, financial, defense, and technology sectors experienced major breaches that cost billions of dollars in losses, exposed millions of data records, and paralyzed operations for months. The pattern found is quite alarming: these

|
Apr 30, 2026 — 6 minutes read

Receive weekly
updates on new posts

Subscribe