Quasa
Use QUASA App
Join the pioneer of Web3 crypto freelancing today!
Open
Technology

Corporate Data Defense: Software Flaws Now Beat Stolen Passwords

|Updated: |Author: QUASA Editorial Team|6 min read| 2208
Corporate Data Defense: Software Flaws Now Beat Stolen Passwords

Corporate data protection now requires a different order of operations. Software vulnerability management should lead the defense program, while strong authentication, restricted access, resilient backups and rehearsed response remain essential supporting controls.

The change is measurable rather than theoretical. The 2026 Verizon breach analysis says software vulnerabilities initiated 31% of breaches, overtaking stolen passwords; ransomware was involved in 48%, and the report covers incidents from November 1, 2024, through October 31, 2025.

Manage protection as a business risk

No company can guarantee that its data will never be compromised. A defensible objective is to reduce the probability of intrusion, limit what an intruder can reach, detect harmful activity quickly and restore important operations without trusting compromised systems.

This requires an accountable owner, an agreed risk tolerance and a current picture of the organization’s systems, data and dependencies. The NIST Cybersecurity Framework 2.0 organizes that work into six concurrent functions: Govern, Identify, Protect, Detect, Respond and Recover. Its addition of Govern makes cybersecurity an enterprise responsibility rather than a collection of tasks left entirely to an IT administrator.

Start by identifying the information whose disclosure, alteration or loss would materially disrupt the company. That may include customer records, payment data, employee files, contracts, source code, product designs and credentials. Record where each important dataset resides, which applications process it, who owns it, who can access it and which suppliers can reach the surrounding environment.

Close the entry routes attackers use now

Patch exposure before polishing peripheral controls. Maintain an inventory of internet-facing services, operating systems, applications, network appliances and cloud workloads. Track whether each product is supported, subscribe to vendor security notices and give exploited or externally exposed vulnerabilities a faster remediation path than routine updates.

An inventory is useful only when it leads to action. Assign every asset an owner, define an exception process for patches that cannot be installed promptly and place unsupported systems behind compensating controls until they can be replaced. External attack-surface checks should also look for forgotten test servers, stale remote-access portals and cloud resources created outside the normal deployment process.

Credentials remain a major line of defense even though vulnerabilities now rank higher as an initial route. Require multifactor authentication for administrators, remote access, email, cloud consoles, source-code repositories and systems holding sensitive data. Prefer phishing-resistant methods such as passkeys or hardware security keys for privileged and high-risk accounts; avoid treating a text message as the strongest available factor.

Separate administrator identities from everyday accounts and do not use privileged accounts for email or general web browsing. Centralize sign-in where practical, block legacy authentication, monitor failed and unusual login patterns, and remove access promptly when a worker changes role or leaves. Emergency accounts need strong protection, monitoring and periodic tests rather than permanent everyday use.

Make one compromised account less valuable

Access should follow business need, not convenience or seniority. Use role-based groups, time-limited elevation for administrators and periodic access reviews for sensitive repositories. A chief executive does not automatically need permanent technical access to every database, and a service account should not inherit broad permissions merely because narrowing them takes more work.

Segment environments so that compromise of a workstation does not provide a direct path to production systems, identity infrastructure or backup administration. Separate development, testing and production; restrict management interfaces; and control movement between network zones. Service accounts should have distinct credentials, narrowly defined permissions and secrets stored in a managed vault rather than scripts, documents or shared chat channels.

Protect the data itself as well. Encrypt sensitive information in transit and at rest, but manage encryption keys separately from the data and restrict who can use or replace them. Establish retention periods so obsolete records are deleted safely: information that no longer serves a legal or operational purpose creates continuing exposure without continuing value.

Treat suppliers as part of the attack surface

A vendor with remote access, an integration token or privileged support account can create another route to corporate data. Before granting access, determine what the supplier can reach, whether that access is continuously required and how the company will revoke it during an incident. Put security duties, incident notification, log availability, data return and deletion expectations into the contract.

Inventory software dependencies and externally hosted services alongside internal assets. Monitor changes in supplier access, rotate shared secrets and disable dormant integrations. For a critical provider, document how the business will operate if the service, its identity system or its support channel becomes unavailable.

Build backups that an intruder cannot erase

A synchronized cloud folder is not automatically a recovery system: destructive changes may also be synchronized. The NCSC’s ransomware-resistant backup principles recommend isolation, separate administrative credentials, multifactor approval for destructive actions, version history, protected retention and alerts for significant changes.

Define backups from business recovery requirements. Decide which systems must return first, how much data loss is tolerable and how long restoration may take. Keep at least one copy beyond the reach of ordinary production credentials, protect backup encryption keys and record the independent access method needed if the primary identity platform is unavailable.

Test restoration, not merely backup completion. A meaningful exercise restores selected data into a clean environment, verifies integrity and records the time, dependencies and credentials required. Include an occasional scenario in which production administration, normal communications and recent backup versions are unavailable.

Detect intrusion and rehearse containment

Collect useful logs from identity systems, endpoints, cloud control planes, critical applications, network boundaries and backup platforms. Protect those logs from alteration and route high-value alerts to people who can act. Alert priorities should include new privileged accounts, disabled security controls, unusual data exports, mass file changes and attempts to alter backup retention.

Endpoint protection and network controls are important, but neither substitutes for response preparation. Write a concise incident plan covering decision authority, system isolation, evidence preservation, legal and regulatory escalation, customer communications, insurer contacts and outside forensic support. Store an accessible offline copy with current contact details.

Exercises should force concrete decisions: who can disconnect a revenue-producing service, how clean administrator accounts will be created, and which data determines whether notification is required. After each exercise or real incident, assign owners and deadlines to the gaps discovered.

A practical first-month sequence

  1. Identify the company’s most consequential datasets, systems, owners and external dependencies.
  2. Inventory internet-facing assets and remediate exposed, exploited or unsupported software first.
  3. Enforce strong MFA and separate privileged identities across remote access, email, cloud and administration.
  4. Remove unnecessary permissions, stale accounts, dormant integrations and embedded secrets.
  5. Isolate critical systems and backups, then complete a documented restoration test.
  6. Confirm logging coverage and run a short incident exercise with business and technical decision-makers.

The target is not “perfect” security. It is a controlled environment in which common entry routes are closed quickly, a stolen account has limited reach, suspicious behavior becomes visible and the company can recover important data without depending on infrastructure an attacker may already control.

Also read:

Share:

Subscribe to our newsletter

Get the latest Web3, AI, and crypto news delivered straight to your inbox.

0