The Breach That Wasn’t Ours — And Why That’s the Only Kind That Matters Now

Published
July 20, 2026

2 min read

Kraig Faulkner, Field CTO - Infolock

In This Article

Join Our Newsletter

Follow Us

Tags

I had a conversation a few weeks ago that I haven’t stopped thinking about. A large enterprise customer. Good team, reasonably mature security posture, the kind of organization that had already had the internal conversation about data governance and felt good about where they landed.

Then a third-party supplier they worked with got breached.


Not the customer. The supplier.

But the data that got exposed was the customer’s data. And the moment that happened, it stopped being the supplier’s problem and became the customer’s problem, completely. Breach coach, insurance, forensic review, notification obligations — they ran the entire incident lifecycle for a breach that occurred on a network they never controlled and never audited in real time.

I want you to sit with that for a second, because it’s not an edge case anymore. It’s the default condition of doing business in 2026.

For twenty years, the security industry built its entire stack around one idea: keep the bad guys out. Firewalls, endpoint protection, DLP, all of it aimed outward, all of it assuming that if we could just secure the perimeter, the data inside would be safe. That mental model made sense when the perimeter actually meant something. It doesn’t anymore. Your data isn’t sitting quietly inside four walls waiting for someone to break in. It’s already out. It’s with your vendors, your partners, and increasingly, it’s being pulled apart, tagged, and reorganized by AI tools that move faster than any human team can review.

Here’s what I think most organizations still haven’t fully absorbed: you can no longer draw a line between “our risk” and “their risk.” If your data lives on someone else’s infrastructure, and it will, their incident is your incident. Full stop. The customer in my story didn’t have a technology gap. They had a governance gap. Nobody had mapped out what happens, step by step, the moment data outside their direct control gets touched.

This is where I think the industry keeps getting the sequencing backwards. Everyone jumps straight to technology. New tool, new dashboard, new AI-powered discovery platform that promises to tell you where all your sensitive data lives. And to be fair, those tools have gotten remarkably good at the discovery part. The problem is what happens after discovery. Customers run these tools, get a mountain of results back, and then look at each other and ask: now what do we do with this?

That’s not a technology problem. That’s a program problem. Before you buy another tool, you need an answer to one question: do you have a data classification schema that’s actually enforced, not just documented? Most organizations I talk to fall into one of three buckets. Some have never tried. Some have a schema on paper that nobody actually follows. And some have it dialed in and know exactly what to do with what they find. If you don’t know which bucket you’re in, that’s the first thing to figure out, before anything else.

Once you have that foundation, the next question is whether you have an actual program for what happens when things go wrong, not just a tool that flags problems. What’s the response? Who owns it? What are the guardrails? That’s the layer almost nobody has built, and it’s the layer that would have changed the entire experience for that customer.

I’ll be honest about where I think this industry has failed the people trying to solve this. We’ve spent two decades treating data loss prevention as something that disrupts the business — the tool that blocks the email, that stops the file share, that makes everyone’s job a little harder in the name of security. That reputation is deserved, and it’s also exactly backwards. A governance program that’s actually built and enforced doesn’t slow the business down. It’s the thing that lets the business move fast without wondering what happens the day a vendor three steps removed from you gets breached.

Here’s where I think we’re headed, and where I think the best security leaders are already operating. The four walls are gone and they’re not coming back. AI is only going to accelerate how fast data moves and how many places it ends up. The organizations that will handle this well aren’t the ones buying the most tools. They’re the ones who treat data governance the way we’ve always treated incident response: as a program, with owners, with steps, with a plan that exists before the moment you need it, not after.

So here’s my challenge to you. Pull up your last three vendor or partner relationships that touch sensitive data. For each one, ask yourself honestly: if they got breached tomorrow, do you know exactly what happens next, or would you be building that plan in real time while everyone above you is asking questions you don’t have answers to yet?

If you don’t know the answer, that’s not a technology gap. That’s the conversation we should be having.
Ready to get started?
Ready to learn more more – Schedule a call today!

Related Posts

What is Data Risk Management?
Safeguarding Data in Today’s Complex Landscape
Explore "what is data risk management" and its significance in safeguarding data. Dive into its essential components and its role in today's data-driven world.

12 min read

March 25, 2026

What is data risk management? A Comprehensive Infolock Guide
Explore "what is data risk management" and its significance in safeguarding data. Dive into its essential components and its role in today's data-driven world.

12 min read

February 11, 2026

Flip The Script: Let The Attackers “Win”
What does it look like when organizations do their data security and risk management homework upfront,

2 min read

December 5, 2025

Cybersecurity Is Dead — What Now?
We must stop insisting cybersecurity can "win" the war against cybercriminals, because we've already lost.

2 min read

November 10, 2025

4 In 4: 4 Insights From My First 4 Months At Infolock
After four months on the job at Infolock, I want to let prospective customers and employees know.

2 min read

June 18, 2025

Challenge The Status Quo
Quick fix technology solutions aren't a substaitute for hard work and careful planning.

2 min read

October 30, 2025

Data Breach Cynicism Takes Hold
In more than 20 years of working in the IT security industry, I’ve helped literally hundreds of companies

2 min read

May 24, 2025

CISO, We Have A Problem
Since 2001, I’ve worked with hundreds – even thousands – of infosec practitioners: analysts, engineers, technicians,

2 min read

September 17, 2025

It’s The Data, Stupid!
Data is notoriously messy. It’s clear most organizations have lost control of it – or, never had control of it in the first place.

2 min read

August 21, 2025

Peak Vendor: Reclaiming Infosec Priorities And Budgets In The Age Of Big Marketing
I’m not sure when the bubble began. Three years ago? Five? Security needs

2 min read

January 19, 2026

Banishing The Backseat Drivers
If you’re in security, you know how

2 min read

August 16, 2025

Vendors Know You Too Well
Could you imagine walking into a car dealership without:

2 min read

July 13, 2025