Infrastructure post-mortems

What actually
broke

Reconstructed from the primary record: root cause analyses, consent orders, court filings. Not coverage of them. One a week.

  1. Capital One, 2019

    The Capital One breach was not an SSRF story

    Everyone remembers the server-side request forgery. The regulator's findings never mention it. What the OCC actually penalised was risk assessment and internal audit.

    · 8:19articlevideo