THE DEEP TAKE
The vault held. The help desk didn't.
EY got breached this spring. Not the audit systems. Not the crown jewels. The IT help desk.
An intruder sat inside a third-party support-ticket platform from March 28 to April 12. They downloaded documents tied to EY's clients. The files held Social Security numbers, financial account codes, and tax filings. EY caught it around April 23 and told the public on July 15.
Read that timeline again. The firm that audits other companies' controls lost client tax data through a ticketing tool. Not through the systems it guards. Through the one nobody threat-models.
Here is the part worth your attention. Support-desk platforms quietly become the most sensitive data store you own. An engineer troubleshooting a tax workflow attaches the actual return. A finance user opens a ticket and pastes an account number. Multiply that by every ticket, every quarter, for years. The help desk becomes an unindexed lake of the exact data your DLP is built to catch. It rarely gets the scrutiny your ERP or your warehouse does.
Now widen the lens. This was EY's vendor, holding EY's clients' data. If you use a Big Four firm, an outside law firm, or a managed provider, they hold your sensitive files the same way. Your controls stop at your perimeter. Their ticketing hygiene is invisible to you. That gap, between your controls and your vendors', is exactly the kind of exposure the DoGood network exists to surface for enterprise IT leaders.
So do two things next week. First, ask where sensitive attachments pile up inside your own ITSM and support tools. Put a retention limit on them. A ticket does not need to keep a tax return for three years. Second, pull your top vendors' data-handling answers out of the annual questionnaire and ask the specific question. Where do our files live in your support systems, and how long do they stay. The breach that reaches you may not be yours to patch.
Powered by the DoGood network
The data in this issue came from priority submissions by 5,000+ enterprise IT leaders. If you run IT or security at a $100M+ company and want to see what your peers are funding — and earn rewards for participating in vetted meetings with the vendors worth your time — apply to join DoGood.
QUICK HITS
The Salesforce extortion crew opened a storefront
The group behind the year's Salesforce thefts, now calling itself Scattered Lapsus$ Hunters, launched a public leak site this month. It lists 39 companies at once, with data samples from each, and household names sit on it. The crew also posted a separate demand aimed at Salesforce itself: pay us, or roughly a billion customer records go public. The entry point was never a Salesforce flaw. It was voice phishing that tricked staff into approving a malicious OAuth app. That app then had standing access to the whole instance. Your move this week is boring and effective. Pull the list of connected OAuth apps in your Salesforce org, revoke the ones nobody recognizes, and require admin approval for new ones. A stale token is a door left propped open.
The AI compliance clock hits zero on August 2
The EU AI Act's next enforcement wave lands August 2. The rules for general-purpose AI models and the core transparency obligations become live, not aspirational. Penalties are real: up to 35 million euros or 7 percent of global revenue for the worst violations, and 15 million or 3 percent for high-risk ones. This reaches you even if you are US-based. If your product touches EU users or employees and uses AI, you are in scope. The work is documentation and disclosure, not a code change. Before the deadline, confirm three things. Can you name every AI system you deploy? What can each one access? And do you tell people when they are talking to a machine? The teams that scrambled for GDPR in 2018 already know how this ends.
Meta is spending like the AI buildout is a war
Meta told investors this week it will spend up to 135 billion dollars on infrastructure in 2026, most of it on AI. In the same breath it cut 700 roles from its AI unit. Its planned El Paso data center went from 1.5 billion to more than 10 billion dollars. The signal for you is not the drama at Meta. It is capacity. When the hyperscalers pour their balance sheets into GPUs and power, they set the price and the availability of the compute you rent. Do not plan your 2027 AI roadmap assuming cheap, on-demand capacity is waiting. Reserve what you need early, and put GPU and power scarcity in your budget as a real line, not a footnote.
THE NUMBER: 4 straight weeks
Every week this month, CISA added freshly exploited vulnerabilities to its must-patch list. July 7, July 14, July 22, plus off-cycle alerts in between. This is not a monthly dump you can plan around. It is a weekly drip of bugs already being used in live attacks. The list of what attackers are actively exploiting now refreshes every week. A patch process that meets once a month is structurally weeks behind. Stop treating the monthly maintenance window as the heartbeat. Wire your emergency-patch path directly to the exploited-in-the-wild feed, and let the calendar handle everything else.
Third-party data custody is exactly the kind of question the DoGood network helps enterprise IT leaders pressure-test with peers before they hand a vendor access. Ask the room before you sign.
The CXO Brief is powered by the DoGood network, 5,000+ IT leaders sharing what they are actually working on.
Know a CIO who needs this? Forward it and they can subscribe here.
Enterprise IT leader at a $100M+ company? Apply to join DoGood.
