CIO Brief: Managing Risk When a Core Internet Provider Has a Bug
Retrospective: this article looks back at events from February 2017, written in 2026 with the benefit of hindsight.
The short version: In 2017, a bug at Cloudflare, a major internet provider, leaked private data from customer websites, including login sessions. The websites did nothing wrong. A supplier's bug exposed them.
Why this matters to you
Your company relies on providers that sit between your customers and your systems: content delivery networks, firewalls in the cloud, identity providers, email filters. They see your traffic and often your customers' login sessions. When they have a problem, you inherit it.
The business impact
- Account takeover risk for your customers and employees if session tokens leak.
- Response cost: forcing everyone to sign in again and rotating keys takes time and causes friction.
- Disclosure questions: you may need to tell customers about an incident you did not cause.
Questions to ask your team
- Which providers can see our customers' or employees' login sessions or passwords?
- If one of them announced a leak today, how quickly could we reset everything exposed?
- Do we know where all our keys and passwords for other systems are stored?
- Who reads our providers' security notices?
What good looks like
A short list of critical providers, a documented rotation plan, secrets kept in a managed vault, and a team that has practiced resetting them.
The decision
You cannot stop a supplier's bug. You can control how fast you recover. Ask for a provider-incident runbook and a test of it this year — it is one of the cheapest forms of resilience you can buy.
- Cloudbleed (Feb 2017): When Your CDN Leaks Your Customers' Session Tokens Incident Teardowns
- How to Rotate Sessions and Secrets After a Third-Party Provider Leak How-To & Hardening
- Detecting Leaked Session Tokens: Sentinel and GuardDuty Detections Detection & Response