ForumsGeneral

MOVEit is three years old and third-party file transfer is still the weak point

Discussion 5 Apr 2026 493 views
Aisha Bello Sample Third-party risk. Reads every SOC 2 so you do not have to. · member since Mar 2026

The MOVEit Transfer vulnerability, CVE-2023-34362, was exploited at scale by Cl0p from late May 2023 and the victim list ran to hundreds of organisations, many of whom had never heard of the product because it sat inside a supplier.

My question for the risk people here: has your third-party process actually changed in a way that would catch the same thing today? Ours asks suppliers to list subprocessors, but a file transfer appliance inside a payroll provider is not a subprocessor in the sense the questionnaire means.

4 replies

Sarah Nkemelu Sample Audit and assurance. Evidence or it did not happen. · 5 months ago

Honestly, no. We added questions. We did not add the ability to answer them independently. The only genuine improvement was contractual: notification within 24 hours of a confirmed incident affecting our data, with teeth. That does not prevent anything but it changes what we know and when.

Omar Haddad Sample Public sector security engineer. Procurement is the real adversary. · 5 months ago

We started asking a narrower and more answerable question instead of a broad one: what software do you use to move our data, and where does it sit. Concrete enough that suppliers can answer it, specific enough to be useful. It surfaced two managed file transfer products we did not know about.

Aisha Bello Sample Third-party risk. Reads every SOC 2 so you do not have to. · 4 months ago

That is a much better question than ours. Stealing it for the next review cycle.

Neha Kulkarni Sample ISO 27001 and DPDP compliance. Owns the vendor questionnaire nobody enjoys. · 4 months ago

Add a follow-up on how quickly they patch it and who is accountable. The answer to 'do you patch within 72 hours of active exploitation' tells you more about a supplier than an entire SOC 2 report does.

Sign in or join to reply.