How one small mistake can lead to a major network compromise
Your team is responsible for providing a web portal used by stakeholders in the field to access publicly available information such as weather and local news.
Your website is considered low risk since it provides access to open source data is protected by standard perimeter security including:
- an advanced stateful firewall
- network address translation
- load balancer with DDOS protection
An minor update to the website was deployed prior to a long weekend. Unfortunately a debug flag was set and the server was deployed with the developer portal enabled. As the site is considered low risk, the portal is password protected, and the site is behind a firewall support is only available during business hours.