Logo
Cybersecurity

One Compromised System Rarely Stays One Compromised System

Modern incidents travel through dependencies. Security teams need people who can work out where the damage could go next.

ITSEC AsiaITSEC Asia
|
Sep 30, 2026
One Compromised System Rarely Stays One Compromised System

A business application stops working.

The server itself is fine. The network looks normal. Authentication is available. Then someone discovers that an external service used by the application is unavailable.

Suddenly the incident diagram gets bigger.

ENISA’s Threat Landscape 2026, published on 22 September and discussed in a dedicated webinar on 29 September, puts this problem near the centre of its analysis. ENISA says the growing interconnectedness of digital ecosystems is increasing exposure to cyber risk and continues to observe attacks targeting dependencies, including supply chain and third party relationships. ENISA

For workforce development, there’s a practical lesson here: cybersecurity professionals need to understand dependencies as well as assets.

An Asset List Doesn’t Show the Whole Risk

Knowing what systems an organization owns is useful.

Knowing what those systems rely on is different.

A customer portal might depend on an identity provider, DNS, cloud infrastructure, payment service, API, software library and managed service. Several other applications may rely on exactly the same components.

Compromise one shared dependency and the blast radius changes quickly.

Security teams therefore need skills to identify:

  • Which external services support critical business functions
  • Which applications share the same infrastructure or provider
  • Where software and data originate
  • Which dependencies have privileged access
  • What happens if a dependency becomes unavailable
  • Which alternative processes exist when a service fails
  • Who owns the relationship when investigation or recovery is required

The last question has a habit of becoming surprisingly difficult at 2 a.m.

Incident Response Needs a Dependency View

Dependency knowledge changes how people investigate incidents.

Suppose unusual activity appears in three applications simultaneously. Looking at each application separately may produce three investigations. Knowing that all three depend on the same identity service immediately creates another hypothesis.

The same principle applies to recovery.

Restoring a server doesn’t restore a business process if a required external service remains unavailable. A technically healthy application may still be unusable because its authentication, API or data provider has failed.

ENISA reports that 73% of organizations targeted in the incidents it analysed were entities classified as essential or important under NIS2. Its analysis also says cyber dependencies can increase the scale and impact of incidents across interconnected infrastructure. ENISA

Cyber resilience therefore requires people who can reason across organizational boundaries.

Put Dependencies Into the Exercise

Training can make this capability visible.

Give learners a simulated organization containing several applications, shared infrastructure and external services. Provide the architecture, but don’t reveal every dependency.

Then trigger an incident at one supplier.

Participants must discover which services rely on it, determine what evidence is available, assess business impact and decide which teams or external parties need to be involved.

A more difficult version introduces a recovery decision that fixes one system while breaking another dependency.

This type of scenario fits practical learning at ITSEC Cyber & AI Academy, where cyber range exercises can connect technical investigation with architecture, incident response and operational decision making.

Security teams already ask, “What happened?”

The next useful question is often, “What else depends on it?”

Explore practical cybersecurity and AI training at ITSEC Cyber & AI Academy.

References: ENISA Threat Landscape 2026, 22 September 2026 · ENISA: How Dependencies Weaken Digital Resilience · ENISA Threat Landscape Webinar, 29 September 2026

Share this post

You may also like

Cybersecurity Has More Entry Doors Than We Think
Cybersecurity

Cybersecurity Has More Entry Doors Than We Think

Picture a cybersecurity team and there’s a good chance you imagine people who studied computing, entered IT and gradually specialised in security. That route exists. It’s hardly the only one. ENISA’s 2026 research into cybersecurity investment and workforce challenges found that many employees in cyber-related roles lack formal cybersecurity qualifications and that a substantial share moved into the field from other professions. Upskilling and reskilling already account for part of the workforce organisations rely on today. NIST is also putting more attention on multiple entry routes. Its cybersecurity career-pathway material, updated on 8 September, focuses on helping people connect their existing interests and strengths with specific work roles in the NICE Workforce Framework. That matters because a cybersecurity talent strategy based entirely on finding finished cybersecurity professionals is competing for a limited supply. Sometimes it makes more sense to build one. CYBERSECURITY BORROWS SKILLS FROM EVERYWHERE Someone moving into cybersecurity doesn’t arrive empty-handed. A network engineer already understands infrastructure and troubleshooting. A software developer knows how applications are assembled. Someone working in audit understands

ITSEC AsiaITSEC Asia
|
Sep 11, 2026 — 3 minutes read
Healthcare Cybersecurity in Southeast Asia: Why Patient Data Systems Are the New Frontline
Cybersecurity

Healthcare Cybersecurity in Southeast Asia: Why Patient Data Systems Are the New Frontline

INTRODUCTION What does it take for an attacker to compromise the personal health records of 1.5 million patients, including a sitting prime minister? At SingHealth in 2018, the answer turned out to be a single unpatched vulnerability, a phishing email, and nearly a year of undetected access before anyone noticed something was wrong. The investigation that followed found no penetration tests had been conducted, no two-factor authentication had been enabled on critical systems, and cybersecurity had been treated as an IT management issue rather than an organizational risk. The Committee of Inquiry described the failures as a catalogue of missed opportunities that a far less skilled attacker could have exploited just as easily. That was 2018. Since then, the threat to healthcare systems across Southeast Asia has not diminished. It has industrialized. Cyberattacks in the region doubled in 2024 compared to the previous year, with healthcare consistently listed alongside finance and government as a primary target. Globally, healthcare accounted for 23% of all data breaches in 2024, overtaking finance for the

ITSEC AsiaITSEC Asia
|
Jun 30, 2026 — 8 minutes read
The Reason Businesses That Skip Digital Forensics Keep Getting Hit Twice
Cybersecurity

The Reason Businesses That Skip Digital Forensics Keep Getting Hit Twice

INTRODUCTION The cybersecurity conversation has long been dominated by prevention. Organizations invest in perimeter defenses, deploy intrusion detection systems, and train employees to recognize phishing attempts. Yet according to IBM's Cost of a Data Breach Report 2024, the average time to identify a breach reached 194 days, nearly half a year of undetected attacker activity inside a network. This statistic reveals a painful truth: prevention alone is not a complete strategy. When an attacker does get through (and modern threat actors have made it a matter of when, not if), organizations need a structured, methodical way to understand exactly what happened, how far the damage extends, and what must change to prevent history from repeating itself. That capability is digital forensics. And the businesses that overlook it are not just leaving questions unanswered. They are setting themselves up to be compromised again. Source: IBM Cost of a Data Breach Report 2024 [https://newsroom.ibm.com/2024-07-30-ibm-report-escalating-data-breach-disruption-pushes-costs-to-new-highs], Ponemon Institute [https://www.ponemon.org] WHAT IS DIGITAL FORENSICS AND WHY DOES IT MATTER? Digital forensics is the process of collecting, preserving, analyzing,

|
Mei 06, 2026 — 7 minutes read

Receive weekly
updates on new posts

Subscribe