Microsoft 365CIO BriefingsRetrospectives

CIO Brief: Security Vendors Are Part of Your Attack Surface

By OnCloudSec Research Team · Published Oct 6, 2026 · 1 min read

Retrospective: this article looks back at events from January 2021, written in 2026 with the benefit of hindsight.

The short version: In 2021, Mimecast — an email security company — disclosed that a digital certificate its products used to connect to customers' Microsoft 365 email had been stolen by the same group behind SolarWinds. Security vendors often hold the keys to your systems.

Why security tools need oversight too

Email filters, backup tools, monitoring software and IT management platforms need deep access to work. That makes them attractive targets: compromise one vendor, and you may reach many of its customers at once.

The business impact

  • Exposure of email and other data through a trusted vendor connection.
  • Emergency work to disconnect and reconnect integrations.
  • Tough questions from customers and regulators about third-party oversight.

Questions to ask your team

  • Which security and IT vendors have access to our email or cloud environment?
  • What level of access does each have — everyone's mailbox, or only what's needed?
  • How quickly could we cut off a vendor's access if it was compromised?
  • Do we monitor what those vendor connections actually do?

What good looks like

A list of privileged vendor integrations, least-privilege access, monitoring of their activity, and a playbook for disconnecting them quickly.

The decision

Treat your security vendors as privileged users. Review their access annually and include them in your incident response planning.

mimecast certificate compromise impactMimecast certificate2021

More on this story