When Everything Depends on Everything
Security doesn't fail in silos. It fails in cascades. The slides from the talk, the sources behind every claim, and the three things to do Monday morning.
-
1. Draw one edge.
Take your worst-scored domain. Write down, by hand, three things in other domains that break if it stays broken. Hand the page to whoever owns the other end of each line and ask: did you know this depended on you?
-
2. Find the tokens.
Ask whoever runs your data platform for every integration, service account, and API key that can read your top two data stores. Ask your security lead which of those they recognize by name. The difference between the two lists is your Anodot.
-
3. Change the board slide.
Retire the eight-squares slide. Replace it with one cascade path and what it costs when it fires. The board's question changes from "are we secure" to "what fails first."
- Sidekick Security, The Trust Map (2026). The public dependency model the talk's graph is built on. trust-map.sidekicksecurity.io
- Vimeo security incident, disclosed April 28, 2026. Third-party analytics provider Anodot; stolen authentication tokens; Snowflake and BigQuery. BleepingComputer coverage
- Same shape, different logos: MOVEit Transfer (2023) · Snowflake customer credential campaign (2024) · Cleo (2024–25).
- Obligations named in the cascade math: AICPA SOC 2 Trust Services Criteria (CC6, CC7, CC9.2) · PCI DSS v4.0 (12.8, 12.10) · HIPAA, 45 CFR 164.308(b), 164.404, 164.410 · N.C. Gen. Stat. § 75-65 · GDPR Art. 28 and 33.
The graph numbers in the talk (76 practices depending on Policies & RACI; 19 on Third-Party Risk across 8 domains) are derived from the Trust Map's public dependency data and were re-verified against the source in September 2026. Version one treats every dependency as equal; weighting the edges is the next piece of work.
If you'd like to draw your own first edge with someone who has done it a few times, that's a thirty-minute conversation.