August 24, 2026
The Next Breach May Begin With Something You Approved
I remember the approval because there was nothing unusual about it.

By Emily Writes
2 min read
Our operations team needed a new application to automate a document-heavy process. They had been spending hours moving information between systems, and the proposed platform could take most of that work off their hands. I reviewed the request, checked the vendor details, looked at the access requirements, and approved it.
It was a straightforward business decision. The application went live. The team adopted it quickly, and after a few weeks, nobody was talking about the implementation anymore.
Until one morning.
"Can you take a look at this?"
It was Daniel from our security team. He had noticed unusual activity involving a service credential associated with the application. I recognized the name immediately.
"That's the platform I approved."
"Exactly."
We started looking at what had happened.
At first, there was nothing that immediately pointed to a serious incident. The credentials were genuine. The application was genuine. The activity was coming through an authorized connection. But the sequence didn't make sense. So, we followed it.
The Part We Hadn't Seen
The application had originally been introduced for one specific workflow. Since then, things have changed. A reporting tool was connected to it. Another team introduced an automated process. A service account had been created to keep the workflow running. Each change had a legitimate reason.
The problem became visible only when we looked at them together. The application was no longer simply handling documents. It had become connected to several parts of our environment that hadn't existed around it when I first approved the request.
I remember asking Daniel:
"How much access does this actually give someone if that credential is compromised?" That was the question we needed to answer.
We Needed to Understand the Bigger Picture
Our existing security tools gave us plenty of information, but we needed to understand how those individual pieces could be used together. That's when we brought in Cyber Advisory Services.
Their team helped us trace the relationships surrounding the application, examine the associated identities, and understand how access could potentially move from one system to another. That investigation uncovered several areas that deserved attention.
Some access had become broader than the original requirement. A few older connections were still active. Certain automated processes had more reach than we had initially considered.
Cyber Advisory Services helped us prioritize those areas and work through the necessary changes without disrupting the business process that the application had been introduced to support. For the first time, we could see how a decision that had looked small months earlier had become part of something much larger.
The Incident Changed the Way I Looked at Approvals
What stayed with me wasn't the application itself. It was how quickly the circumstances surrounding it had changed. When I approved the platform, I was looking at a specific business requirement.
Months later, I was looking at a network of integrations, automated processes and service identities that had developed around that original decision. The approval hadn't changed.
Its context was.
That distinction matters. Technology rarely remains isolated after it enters an organization. Teams connect to new systems. Workflows evolve. Automation expands. Vendors gain additional access. Business requirements change. The decision made on day one may therefore have a very different meaning months later.
What I Ask Now
I still approve of technology when the business case makes sense. But I asked a few more questions before doing it.
What will this connect to?
Who or what will depend on it?
Could its access change as the workflow grows?
What happens if the associated identity is compromised?
And perhaps the most important one:
Could this decision eventually become part of a much larger security story?
Those questions don't prevent progress. They help us understand what we're creating as we move forward. Because that experience taught me something I hadn't fully appreciated before.
A breach doesn't always begin at the moment an attacker gains access. Sometimes, the conditions for it are created much earlier, through a series of ordinary decisions that made perfect sense at the time. Mine started with an approval that I had almost forgotten about. And that's why I still think about that morning.
The next breach may not begin with something an attacker discovers.
It may begin with something we willingly approve.