The Insider Becomes the Perimeter in Enterprise Security
Article

The Insider Becomes the Perimeter in Enterprise Security

Recent incidents and industry messaging show that trust in people, platforms, and infrastructure is now the central security problem for US enterprises.

NagiOctober 6, 20265 min read

Photo: BleepingComputer

The security industry spent two decades building walls against outsiders, but the stories crossing the desk this week point somewhere else. The most consequential breaches and attacks are coming from inside the perimeter: a retailer whose own mobile app became the delivery channel for a hacker's message, and an engineer who turned his privileged access against his employer. Running alongside those incidents is a quieter thread from the vendor and conference circuit, where sovereignty and AI resilience are being framed as questions of who operates the infrastructure and how much enterprises should trust it. The common denominator is that trust - in credentials, in platforms, in staff, and in the supply chain - is the thing being attacked and the thing being sold.

When the App Becomes the Attacker

ASOS confirmed a data breach Tuesday after hackers sent unauthorized push notifications through its mobile app while claiming to have stolen customer data from the company's Snowflake environment, as BleepingComputer reported. The mechanics matter more than the headline. A customer-facing app is normally the most trusted channel a brand has, which is precisely what made it useful to an attacker. Pushing a message that reads "HACKED" to a user's lock screen doesn't require breaking encryption or defeating a firewall; it requires access to a notification pipeline and the credibility that comes with the brand's own icon.

For US technology companies, the lesson is that customer trust and security posture are now the same asset. American consumers have spent years being trained to treat in-app messages as authoritative. When that assumption is abused, the damage is not limited to the breached data. It extends to every future notification, password reset, and fraud warning the company sends. And the reference to a Snowflake environment matters, because it places this incident in the broader pattern of attacks on cloud data platforms that many enterprises treat as managed and therefore implicitly safe.

The Privileged Insider Problem

BleepingComputer also reported that a former core infrastructure engineer at an industrial company headquartered in New Jersey was sentenced to 32 months in prison for locking thousands of devices on his employer's network in a ransomware-style attack. This is not a story about sophisticated tradecraft. It is a story about the gap between what an organization believes its access controls do and what a determined insider can actually accomplish.

Core infrastructure engineers are, by design, among the most trusted people in an enterprise. They build the systems that enforce everyone else's restrictions. When that trust is abused, the controls that are supposed to stop ransomware become the tools that deliver it. A 32-month sentence is a meaningful signal, but it arrives after the disruption. For US enterprises, the practical question is whether their internal monitoring, least-privilege design, and offboarding procedures assume that a trusted engineer might one day become an adversary. Most still assume the opposite.

Sovereignty as a Trust Question

On the vendor side, NetApp is putting sovereign storage at the center of European infrastructure decisions, as SiliconANGLE reported, arguing that sovereignty now covers much more than where data is physically stored. According to the company's Willem Hendrickx, customers want to know who operates and manages the data, where support is based, and what telemetry is collected. That framing is worth reading carefully, because it reframes a geopolitical topic as an operational one.

The American technology market should pay attention, even though the story is set in Europe. US cloud and storage vendors sell into European enterprises that are now asking questions about operators, support locations, and telemetry that they did not ask five years ago. Those questions are not purely regulatory. They are questions about trust in the platform layer - the same category of concern that shows up in the ASOS incident and in the insider case. The difference is that sovereign storage is a commercial answer being sold to a trust problem, and buyers in the US are likely to hear a version of the same pitch.

Framing AI Around Resilience

SiliconANGLE also previewed the AI Cybersecurity and Resilience Summit, noting that AI trust increasingly determines whether enterprise AI scales. As organizations move beyond pilots and put models and agents into operational systems, the question is no longer whether AI performs well in isolation; enterprises also have to determine whether the infrastructure, data, and applications underneath it can withstand cyberattacks, data integrity failures, and operational disruption.

That is a notable shift in framing. For the past few years, the enterprise AI conversation has been dominated by capability and cost. The summit framing puts resilience on equal footing, which implicitly concedes that the underlying stack is not assumed to be trustworthy. For US companies deploying agents into production systems, this is the practical version of the same thread: the model is only as reliable as the data it reads and the access it holds.

What the Pattern Means for US Buyers

Taken together, these stories describe a market where security spending is migrating from perimeter defense toward trust verification. A US retailer can harden its network and still watch its own app push a hacker's message. An industrial company can deploy endpoint protection and still lose thousands of devices to one engineer. A European buyer can choose a storage vendor and find that the deciding factor is who can see the telemetry. A US enterprise can pilot an AI agent successfully and discover that the harder problem is whether the agent's underlying infrastructure survives an attack.

The commercial consequence is that vendors are being asked to prove not just what their products do, but who runs them and what they observe. NetApp's sovereign storage positioning is one example; the AI resilience summit framing is another. Both are attempts to sell assurance in a market where assurance is scarce. US technology companies that treat these as marketing themes rather than engineering requirements risk discovering, as the ASOS and New Jersey cases suggest, that the trust they assumed was structural was actually conditional.

What to Watch

The stories above point to a few concrete things worth tracking. ASOS has confirmed a breach tied to unauthorized push notifications and claims about a Snowflake environment, so the follow-up will be whether that claim is substantiated and how notification channels are governed. The New Jersey sentencing establishes a legal precedent for insider ransomware-style attacks, which may shape how US employers structure privileged access and monitoring. NetApp's sovereign storage push will test whether European buyers treat operator location and telemetry as procurement criteria rather than compliance checkboxes, and whether that expectation travels to US deals. And the AI Cybersecurity and Resilience Summit framing will show whether enterprises are actually budgeting for resilience underneath AI, or continuing to fund capability first and assume the platform holds. The through-line remains the same: the question is no longer whether an organization has a perimeter, but whom it has chosen to trust inside it.

More on this beat: Cybersecurity on TechManNews.

#cybersecurity#insider threat#data breach#enterprise AI#sovereign storage#trust

Newsletter

Get Tech News in Your Inbox

The latest AI, gadgets, software and startup stories from TechManNews, delivered every morning - free.