A Dallas story
The Tuesday the machine shop almost lost the prime
the second-generation owner of a 48-person machine shop in Grand Prairie that supplies a Fort Worth prime
It is a Tuesday in April and the prime's supplier security questionnaire is due Friday. The owner took over the shop from his father in 2014, 48 people now, and the titanium bracket order on the floor is worth $3.1 million over three years. The drawings for it are controlled unclassified information. They live in one folder.
On Monday the estimator got an email from the prime's supplier portal asking him to re-verify his login before the questionnaire deadline. It looked like every other portal email. He typed his password into a page that was not the portal. He did what the email asked, and the email was good.
At 1:14 on Tuesday morning someone in another time zone tries that password on the shop's cloud account.
The login never gets past the prompt. The engineer watching the console sees the attempt from a country the shop has never shipped to, resets the password before the first shift, and writes it up. On Wednesday the owner answers the questionnaire's question about detecting unauthorized access with Tuesday's log. The prime reads it, and the bracket order stays in Grand Prairie.
The password works, and the only thing between a stranger and the drawings that keep the contract alive is a second factor the estimator has on his phone.
What changes the ending
- MFA on every account that can reach the drawings, so a password from a fake portal is useless at 1 a.m. (CIS 6 Access Control Management).
- CUI in one enclave with access by name, not a shared drive the whole shop can open, which is what NIST SP 800-171 asks for anyway (CIS 3 Data Protection).
- A named engineer watching logins around the clock, so the prime hears about the attempt from you, with evidence, not the other way around (CIS 13 Network Monitoring and Defense).