The ASOS cyber attack reported on 6 October 2026, has raised fresh questions about third-party access, SaaS security and how modern organisations manage an increasingly connected attack surface.
The incident became public in an unusual way: customers received an unauthorised mobile push notification through the ASOS app claiming the retailer had been compromised. ASOS later confirmed that basic personal information, including names and contact details, may have been accessed. At the time of writing, the company says it does not believe payment-card information or account passwords were affected, while its website and app continue to operate normally.
The group claiming responsibility has alleged access to ASOS’s Snowflake environment. Neither ASOS nor Snowflake has confirmed that claim, and there is currently no public evidence establishing how the incident occurred.
There will be plenty of speculation about the technology involved, the attacker and the point of entry. For IT and security leaders, however, there is a broader question worth asking now: ‘How much of your organisation’s attack surface sits outside the infrastructure you directly control?’
For most organisations, that answer is: more than you think.
What Happened in the ASOS Cyber Attack?
ASOS’ public statement confirmed it was investigating unauthorised activity involving third-party platforms used to communicate with customers. The retailer said basic personal information, including names and contact details, may have been accessed, while payment-card information and account passwords were not believed to be affected at the time of writing.
We don’t yet know the full route of compromise, and it would be premature to attribute the incident to a particular technology, vulnerability or security failure. What we can see is the potential impact of gaining access to a connected business system.
What Does the ASOS Cyber Attack Tell Us About Third-Party Security Risk?
An attacker doesn’t necessarily need to take an entire company offline to create a serious security incident. Access to one platform could potentially provide a route to customer data, while another may control communications and another may contain privileged integrations into other systems.
This is what makes the modern attack surface so difficult to manage. It isn’t a neat collection of servers, endpoints and firewalls anymore, it is an interconnected environment of:
- cloud infrastructure
- SaaS applications
- employee and privileged identities
- APIs and integrations
- customer communication platforms
- endpoint devices
- contractors and third parties
- data stores
- security tooling
- IT management platforms
Every connection creates functionality but it can also create another route that needs to be understood and controlled.
What is Third-Party Cyber Risk?
Third-party cyber risk is the security exposure created when external providers, software, services or partners have access to your organisation’s systems, users or data. That doesn’t mean third-party technology is inherently insecure, the main problem is visibility.
A modern organisation can run hundreds of applications and services, procured by one department, administered by another, and rarely reviewed as a whole. Over time, accounts accumulate and integrations are set up then forgotten, while permissions shift as employees leave and suppliers change. The environment keeps moving, whether anyone is tracking it or not.
Over time, it becomes difficult to answer basic questions such as:
- What systems do we actually have?
- What data can each one access?
- Which systems are connected to each other?
- Who has administrative access?
- Which external organisations can access our environment?
- Which identities still have privileges they no longer need?
- What would happen if one of these platforms or accounts were compromised?
If those answers live across spreadsheets, dashboards, individual employees and separate IT and security teams, identifying risk becomes considerably harder.
Why SaaS Has Changed The Security Boundary
The traditional security model assumed that organisations largely controlled their own technology environment, but in recent years, that boundary has disappeared.
A typical employee now might authenticate through one identity provider, work from a managed laptop, access half a dozen SaaS platforms, upload information to cloud storage and use applications connected through APIs all before lunch. Meanwhile, customer-facing teams may use completely different systems for CRM, marketing, support, payments and communications.
Each system can have its own users, permissions, configuration and integrations. This creates a fundamental change in the way organisations need to think about cyber security: Your security boundary now extends to every identity, platform and connection capable of accessing your environment or acting on your behalf.
Therefore, we are now living in a time where protecting the corporate network alone is no longer enough.
Why Modern IT Environments Are Harder To Secure
Few businesses set out to build a fragmented IT environment; it accumulates over years and across successive leadership teams. A tool gets bought to solve a pressing problem, a department signs up for another SaaS application, someone builds an integration to save themselves hours of manual work, and a supplier is granted access that was only ever meant to be temporary. Each decision is reasonable at the time it’s made. Taken together, they leave behind an estate that grows harder to understand with every addition, and the gap widens further when IT operations and cyber security are run as separate functions.
IT tends to know the systems, while security knows the threats, but neither team necessarily sees how infrastructure, applications, identities and access fit together, or where the risk sits between them. Attackers have no interest in how your organisation divides its responsibilities. They will take whichever route gets them in.
Four Questions IT Leaders Should Be Asking Following The Asos Cyber Incident
Incidents like the one currently being investigated by ASOS are a good reason to review your own environment without waiting for your next security audit.
1. Do we know every platform that can access sensitive data or communicate externally?
Start with visibility: Your inventory shouldn’t stop at laptops, servers and network devices.
Identify SaaS applications, cloud services, integrations, customer communication systems and third-party platforms that can access company or customer information and then establish who owns each one. If nobody can produce a reliable inventory, that is a security problem in itself.
2. Who can access those platforms?
Applications are only part of the attack surface, identity is another. Make sure to review:
- administrator accounts
- privileged users
- service accounts
- former employees
- contractors
- supplier access
- dormant accounts
- shared credentials
- API credentials and tokens
Access that was appropriate six months ago may no longer be necessary today.
The principle is simple: users and systems should have the access they need, for as long as they need it and no more.
3. Can we detect when something changes?
Knowing what exists is only the start: Organisations also need to see when behaviour moves away from what’s expected. That might include:
- unusual authentication attempts
- unexpected administrative activity
- changes to permissions
- new integrations
- suspicious account behaviour
- configuration changes
- unusual data access
- security alerts across endpoints, networks and cloud services
The faster those signals can be connected, the faster a team can understand whether it is dealing with an isolated event or a wider incident.
4.Can we actually respond?
A security alert is only useful if somebody can act on it. If a connected platform or privileged identity were compromised tomorrow, ask yourself:
- How quickly could you identify what it could access?
- Could you revoke credentials?
- Could you isolate affected devices or systems?
- Could you remove a malicious integration?
- Could you identify affected users?
- Could your IT and security teams work from the same information?
The difference between detecting suspicious activity and controlling an incident often comes down to operational readiness.
Why IT Operations and Cyber Security Can No Longer Be Separated
For years, organisations have treated IT operations and cyber security as neighbouring disciplines, related but run apart, and that arrangement is becoming harder to defend. Security depends on operational knowledge at almost every turn: an endpoint can’t be protected if nobody knows it exists, an identity is only as safe as the way its access is managed, and an integration can’t be assessed without understanding which systems sit on either end of it. Investigating suspicious behaviour requires visibility across the infrastructure beneath it, and responding to an incident stalls when the security team has found the problem but another team holds the keys to the affected system.
So cyber security increasingly begins with sound IT operations. Asset management, identity, patching, configuration, access control, monitoring and response all describe the same environment from different angles, and treating them as separate conversations leaves the gaps an attacker needs.
How Can Organisations Reduce Third-Party Cyber Risk?
There is no single security product that removes third-party risk. A better approach is to continuously know, control, monitor and respond.
Know: Maintain an accurate view of your devices, applications, identities, integrations, suppliers and data connections. You cannot secure what you cannot see.
Control: Limit access and privileges. Remove accounts, applications and integrations that are no longer required. Apply strong authentication and regularly review administrative access.
Monitor: Watch for suspicious activity and configuration changes across endpoints, identity, networks, SaaS platforms and cloud environments. Individual alerts become far more useful when they can be viewed in context.
Respond: Make sure someone is responsible for acting. Detection without response simply tells you that something has gone wrong. Organisations need the people, processes and technology to investigate incidents, contain affected systems and remediate weaknesses quickly.
The Attack Surface Is Now The Whole IT Environment
We don’t yet know the complete story behind the ASOS cyber attack, at the time of writing this is still under investigation. However, IT leaders don’t need to wait for the post-incident report to take something useful from it.
The modern attack surface is bigger than the corporate network. It extends through identities, SaaS applications, cloud platforms, integrations, suppliers and every system trusted with access to your organisation.
The challenge isn’t simply adding another security tool, it’s being able to see the environment as one connected system. Then, having the ability to operate, secure and improve it continuously. When your technology is connected, your approach to IT and security needs to be connected too.
How ThreatSpike Helps Reduce Third-Party Security Risk
ThreatSpike brings managed IT and cyber security together under one platform, operating as one service, combining day-to-day IT operations with defensive security and continuous security testing. Rather than managing infrastructure, identities, monitoring and security though disconnected teams and tools, ThreatSpike gives organisations one view across their IT and security environment, backed by a team that can act on what it finds.

