"Mixed, Active Directory and Okta maintain asset ownership and permissions, but logging is rolling over due to a lack of storage and lack of log retention policies."
"No idea if POLP has been implemented. UNKNOWN, and no record of assessments or audits."
"Unknown, IAM is disorganized, no records of assessments or audits can be found."
"Unknown, IAM is disorganized, no records of assessments or audits can be found."
"Unknown"
"KNOWN, Intellectual Property has been exfiltrated and used competitively against our organization."
"UNKNOWN - Users do not seem affected."
"UNKNOWN. Intellectual property has been exfiltrated, but no IOC or TTPs have been determined."
"UNKNOWN"
"KNOWN.Intellectual property has been exfiltrated, causing revenue loss to Chinese knockoffs. <confidentiality> "
"KNOWN. Intellectual property has been exfiltrated, causing revenue loss to Chinese knockoffs"
"KNOWN. Intellectual property has been exfiltrated, causing revenue loss to Chinese knockoffs. Current security posture is not known, assessed, addressed and then audited for quality, and therefore inadequate."
"KNOWN. Intellectual property has been exfiltrated, causing revenue loss to Chinese knockoffs. Current security posture is not known, assessed, addressed and then audited for quality, and therefore inadequate. If not remediated, we will lose our PCI standing and will not be able to conduct business."
"KNOWN- We have 18 Third Party Vendors, but no record of Security/ Risk interviews or registers exist with them."
"KNOWN, No listed Security or Privacy controls have been designed, declared nor implemented.
"KNOWN, none detected"
"KNOWN, Previous security team, Director and CISO have been terminated due to gross negligence."
"KNOWN, there is currently no oversight, assessments, advisory or audit process in place."
"KNOWN, we are losing business to Chinese knockoffs."
"KNOWN, the SIEM is down and isn't operational due to data capacity planning failures. A re-spec of the storage hardware is required, and must meet PCI-DSS standards for data collection and retention."
"KNOWN, no Security Awareness training has been conducted."
Swing by for a cup of coffee, or whatever.
ACME COMPANY
2228 Blake St
Denver, Denver County 80205
USA
 1.800.555.0123
 acmecompany.ciso@gmail.com