A rack of identical units, each carrying an intact tamper-evident seal. One has only the clean rectangle where a seal was removed.

Specimen VI

The Sponsor

Threat rating
Endemic
Domain
Governance override

First contact

Two thousand people, twenty-five of them in security, and a third-party risk function of comparable size. Every intake gate real: named evidence requirements, review, a refusal path that got used. Getting a single read-only assessment tool through it took months. “We don’t make exceptions,” they said. While that was going on, two other products were bought, rolled out and put into production without touching any of it.

Behaviour

It requires a large apparatus to survive, which is why it is rarely found in small companies. A twenty-person estate has visible gaps and nowhere to put anything. A mature one produces continuous, genuine evidence that its controls function — and that evidence is entirely truthful, because the controls do function, on everything that arrived through the front.

The creature does not defeat the intake process. It enters above it, carried by somebody senior enough that the question stops being asked, and once inside it is protected by the same apparatus it bypassed: every report the security function produces is accurate, and none of them are about this. The gate is real, and it is real in proportion to how little sponsorship you arrived with. Vendors feel this first, because they are the only people put through the process from outside it.

It leaves no finding because a finding requires somebody to have raised one. It appears in no risk register, because registering it would have meant saying no first.

Signs of infestation

Take the list of everything that completed third-party risk assessment. Take the list of what is actually running — from the estate, not the CMDB. For SaaS that is the Entra enterprise application inventory and the OAuth grants behind it, which record what was actually consented to rather than what was declared. Diff them, and work only the second list. For each item on it, establish two things: who introduced it, and whether the decision to proceed without assessment exists anywhere in writing. The second question is the one that matters. An exception that was documented is a decision, and a decision can be reviewed. An exception nobody wrote down is not a control failure — it is a control that was never asked.

Containment

The software will not be removed, and pretending otherwise wastes the meeting. What can be changed is the anonymity of the decision: a named person, accepting a named risk, in writing, with a date and a review point. This is worth doing even where nothing else changes, because it converts a condition back into a decision, and decisions expire. An apparatus enforces nothing on its own. What enforces is somebody’s willingness to say no, and that is not a department.

Recovered note

I pointed it out to the IT staff. What came back was a very heavy “we know.” They had known for a long time, and that was the whole of what they could do about it.