Latest / Tech Talks With Kinsoft / Canvas LMS Data Breach – Australian Schools and Universities Hit
Transcript
- 0:00Welcome to Tech Talks with Kinsoft. Glad to be
- 0:02here. So I want you to imagine returning to your
- 0:05home after a long day at the office. You know,
- 0:08you unlock the front door, you disarm the alarm,
- 0:11and you step inside. Right. Standard routine.
- 0:14Exactly. And the television is exactly where
- 0:16you left it. Your laptop is still sitting right
- 0:19there on the dining table. But as you walk toward
- 0:21the kitchen, you notice a single cabinet door
- 0:24is open by like half an inch. Oh, I hate that
- 0:27feeling. Right. And maybe a chair has been subtly
- 0:30shifted away from the wall. The windows are perfectly
- 0:33intact. The locks aren't broken. And, you know,
- 0:36nothing of obvious financial value appears to
- 0:39be missing. But you just know. Yeah, you're hit
- 0:41with this immediate visceral realization that
- 0:44someone unauthorized was just, well, walking
- 0:47around inside your house while you were completely
- 0:48unaware. And that realization completely strips
- 0:52away your baseline sense of security. It really
- 0:54does. what might be gone, but from the the maddening
- 1:02uncertainty of what that intruder was doing,
- 1:04like what were they looking at or planning during
- 1:06that time? They had free reign over your private
- 1:08environment. Exactly. And that unsettling scenario
- 1:11is exactly what we are examining today. But we
- 1:14are scaling it up to a massive global digital
- 1:18infrastructure. A very big house, so to speak.
- 1:20A huge house. Our focus today is the major cybersecurity
- 1:24incident that recently hit. instructors canvas
- 1:27platform yeah this is a big one it is for anyone
- 1:29listening who is you know a university student
- 1:32an educator or maybe an i .t administrator within
- 1:34the education sector Canvas is just a ubiquitous
- 1:38presence. Oh, absolutely. It's everywhere. It
- 1:40functions as the central learning management
- 1:42platform across a vast majority of Australian
- 1:44universities, vocational providers, and secondary
- 1:48schools. We are talking about the core digital
- 1:50architecture of the modern classroom here. Right.
- 1:53It holds assignment submissions, internal communications,
- 1:56grading rubrics, and the foundational identities
- 1:59of millions of users. To give you, the listener,
- 2:03a clear, factual breakdown of this incident,
- 2:06we are grounding our discussion entirely in two
- 2:09primary sources. Always good to stick to the
- 2:11facts. Exactly. The first is an official media
- 2:14statement from the University of Canberra, which
- 2:16really details their specific local institutional
- 2:19experience of the event. Which is super valuable
- 2:22to see the ground level impact. Yeah. And the
- 2:24second source is the formal response and guidance
- 2:26issued by the Office of the Australian Information
- 2:29Commissioner, or, you know, the OAIC. right so
- 2:32Analyzing both that localized institutional view
- 2:35alongside the overarching national regulatory
- 2:38perspective, it really gives us the technical
- 2:41and legal parameters we need to properly evaluate
- 2:44an incident of this magnitude. Spot on. Our mission
- 2:47for you today is to cut through the inevitable
- 2:49rumor mill that always follows a breach. Oh,
- 2:51the rumors are always wild. Always. So we are
- 2:53going to map out the verified timeline, detail
- 2:56the exact specific data sets that were compromised,
- 2:59and evaluate the coordinated... We basically
- 3:04want to equip you with an understanding of the
- 3:06mechanics behind the breach rather than just
- 3:09reading the scary headlines. Because understanding
- 3:11the mechanics is really the only reliable way
- 3:14to assess your actual risk profile. Exactly.
- 3:17You can't protect yourself if you don't know
- 3:19how the machine broke. Well said. So let's start
- 3:22with the timeline outlined in that University
- 3:24of Canberra statement, because, you know, establishing
- 3:26the window of exposure is critical. Yeah. The
- 3:29timeline is everything. Instructure officially
- 3:31disclosed that they first became aware of an
- 3:33anomaly or an incident on April 25, 2026. OK.
- 3:38However, the criminal threat actor was officially
- 3:40detected and their access to the platform was
- 3:42completely revoked four days later on April 29,
- 3:452026. Right. Instructure then subsequently advised
- 3:48that there are no further indicators. of an ongoing
- 3:50threat. So that time frame from April 25 to April
- 3:5429 is what the cybersecurity industry refers
- 3:56to as the dwell time. Dwell time, right? Yeah.
- 3:58This metric represents the total duration a malicious
- 4:02actor remains undetected, just, you know, sitting
- 4:05inside a target network. And four days of dwell
- 4:08time feels agonizingly long when we apply it
- 4:11back to our earlier analogy of a physical intruder
- 4:13in your house. It does feel like a long time.
- 4:15I mean, giving an attacker 96 hours to map out
- 4:18the floorboards, open digital cupboards, and
- 4:20establish back doors, that seems like an eternity
- 4:23for a platform managing millions of users. Sounds
- 4:26bad, sure. Right. Because I imagine for a massive
- 4:29global tech company, the expectation is that
- 4:32automated security systems would just sever that
- 4:34connection in minutes, not days. Well, the physical
- 4:37intrusion analogy breaks down slightly when we
- 4:40actually look at the historical realities of
- 4:42network forensics. Okay. How so? A decade ago,
- 4:45the average dwell time for a sophisticated threat
- 4:47actor was routinely measured in hundreds of days.
- 4:51Wait, really? Hundreds? Oh, absolutely. attackers
- 4:55would quietly establish persistence, slowly escalate
- 4:59their privileges, and exfiltrate data in these
- 5:02tiny, imperceptible bursts just to avoid triggering
- 5:05any bandwidth alarms. Wow. So they'd just live
- 5:08in the walls, basically. Precisely. So while
- 5:11four days exposes a massive volume of data, From
- 5:14a purely technical incident response standpoint,
- 5:17identifying, isolating, and ejecting an attacker
- 5:21in under a week actually indicates that Instructure's
- 5:24Endpoint Detection and Response Systems, their
- 5:26EDR, were actively parsing logs and flagging
- 5:30anomalous lateral movement relatively quickly.
- 5:33So they caught the footprint in the logs before
- 5:35the attacker could fully deploy something truly
- 5:38catastrophic, like ransomware across the entire
- 5:41network. Exactly. It could have been much, much
- 5:42worse. But those four days were still enough
- 5:44time to execute a compromise on a staggering
- 5:46scale. Undoubtedly. The University of Canberra
- 5:49noted that this breach impacted 9 ,000 separate
- 5:52institutions worldwide. 9 ,000. That is huge.
- 5:55It is. And narrowing that down to our region,
- 5:57it affects 20. Australian and New Zealand universities
- 6:00alongside a multitude of vocational providers
- 6:02and schools. That blast radius is enormous. It
- 6:05really is. And that's what I don't get. A single
- 6:07vulnerability doesn't usually compromise 9000
- 6:09standalone networks simultaneously, you know,
- 6:12unless they are fundamentally linked somehow.
- 6:14Right. And the linkage there is the architecture
- 6:16of modern software as a service or SOS. When
- 6:20a university adopts a platform like Canvas, they
- 6:23aren't installing a proprietary air -gapped piece
- 6:26of software onto physical server racks sitting
- 6:29in some campus basement. Like they used to back
- 6:32in the day. Right. Instead, they are logging
- 6:34into a centralized, highly scalable cloud environment.
- 6:37This is known in the industry as a multi -tenant
- 6:40architecture. Meaning those 9 ,000 institutions
- 6:43are effectively renting distinct locked apartments
- 6:47inside the exact same digital skyscraper. That's
- 6:50a perfect way to look at it. So they share the
- 6:52plumbing, the elevators, and the foundation.
- 6:54And crucially, they share the lobby. In a multi
- 6:58-tenant cloud application, the underlying code
- 7:00base, the authentication APIs, and the database
- 7:04infrastructure are all unified. So it's all one
- 7:06big system underneath. Exactly. The walls separating
- 7:09the University of Canberra's data from, say,
- 7:11a university in London are purely logical barriers.
- 7:15They're enforced by software permissions, not
- 7:17physical hardware gaps. Okay, I see where this
- 7:20is going. Right. So if a threat actor discovers
- 7:22a zero -day vulnerability in that shared infrastructure,
- 7:25perhaps... an authentication bypass flaw in how
- 7:29the main API handles session tokens, they don't
- 7:33need to breach 9 ,000 individual firewalls. They
- 7:36just break the main door. They compromise the
- 7:37centralized control plane, which instantly gives
- 7:40them a vantage point to peer into the individual
- 7:42tenant environments. Wow. And because the blast
- 7:46radius extends directly into those tenant environments,
- 7:49we have to look at the collateral damage, which
- 7:51is, of course, the data itself. This is the critical
- 7:53part for the users. Right. According to Instructure's
- 7:56advice to the impacted institutions, the threat
- 7:58actor managed to extract highly specific categories
- 8:01of user data. Yeah. We were looking at names,
- 8:04university assigned email addresses, student
- 8:07ID numbers, and internal messages sent among
- 8:09users within the Canvas platform. And, you know,
- 8:12the composition of that specific data. said is
- 8:15highly revealing about the attacker's methodology
- 8:18and their intent. Well, it's interesting you
- 8:19say that because the University of Canberra was
- 8:21really quick to issue a crucial reassurance in
- 8:24their statement. Right. About the passwords.
- 8:26Yeah. They noted that Instructure's forensic
- 8:28investigation found absolutely no indication
- 8:31that passwords, dates of birth, government identifiers,
- 8:35or financial information were touched. Which
- 8:37is initially great news. Exactly. The standard
- 8:40reaction to hearing no financial data or passwords
- 8:44were taken is this massive sigh of relief. Of
- 8:47course it is. Users assume that without a password,
- 8:49the hacker just hits a dead end. But looking
- 8:53at the specific data they did acquire, internal
- 8:55messages and student IDs, I suspect the real
- 8:58threat here is sophisticated weaponization. Oh,
- 9:02you are entirely correct to be suspicious of
- 9:03that. Right, because if an attacker possesses
- 9:06a student's ID, their university email, and the
- 9:09exact context of a private message they sent
- 9:11to a lecturer regarding an assignment, I mean,
- 9:14they don't need to crack a password. No, they
- 9:16don't. They have the ultimate raw material for
- 9:18a highly targeted spear phishing campaign. Your
- 9:20deduction aligns perfectly with how modern cyber
- 9:23criminal syndicates actually operate today. Okay,
- 9:26so it's not just about... brute force anymore?
- 9:28No, not at all. The objective isn't always direct
- 9:31brute force access to a bank account. Data often
- 9:35acts as a preliminary currency specifically utilized
- 9:38for what we call initial access brokering. Initial
- 9:42access broker. Right. The threat actor leverages
- 9:45the seemingly mundane data, the internal messages,
- 9:47the unique student IDs, to engineer a contextually
- 9:52flawless communication. Because a generic phishing
- 9:55email asking you to reset your password is, you
- 9:58know, it's usually easy to spot because it lacks
- 10:00context. It's vague. Exactly. Dear customer,
- 10:03that sort of thing. But if I receive an email
- 10:06that addresses me by my full name, arrives at
- 10:08my secure university inbox, my specific student
- 10:11ID and references a message I sent yesterday
- 10:14on Canvas about a specific grading rubric, my
- 10:17cognitive defenses are completely bypassed. Because
- 10:19it looks entirely legitimate. It does. It creates
- 10:22a veneer of absolute institutional trust. And
- 10:25once that trust is established, the attacker
- 10:28prompts the user to click a link to re -authenticate
- 10:31their session. And people click it. They do.
- 10:33And when the user types their credentials into
- 10:35that spooked login page, the attacker doesn't
- 10:38just steal the password. they often capture the
- 10:41live session token. Oh, wow. Yeah. This allows
- 10:44them to bypass standard security measures, seamlessly
- 10:48hijacking the user's authenticated state without
- 10:51ever needing to interact with the underlying
- 10:53database infrastructure again. So the mundane
- 10:56data from Canvas is effectively weaponized to
- 10:59crack far more secure environments down the line.
- 11:02Precisely. Which means the danger lies entirely
- 11:04in the secondary exploitation of the data. Yes.
- 11:07Knowing that risk, the immediate question for
- 11:10everyone becomes one of accountability and remediation.
- 11:13Who is actively managing this crisis? That's
- 11:16a huge operation. It seems like it. According
- 11:18to the UC statement, Instructure is working directly
- 11:21with external forensic experts, law enforcement
- 11:24agencies and global partners to investigate the
- 11:26technical roots of the breach. Right. And that
- 11:29represents the vendor side response. They are
- 11:31executing the root cause analysis, parsing those
- 11:34server logs to determine the exact initial access
- 11:38vector and obviously applying the necessary patches
- 11:41to the code base to seal the vulnerability. But
- 11:44the institutions aren't just sitting around waiting
- 11:45for technical updates. North America, are they?
- 11:48Oh, they can't afford to. Right. UC emphasized
- 11:50that they are treating the privacy of personal
- 11:53information as a matter of the highest importance,
- 11:55and they're independently monitoring their localized
- 11:58risk. Which they have to do. Furthermore, due
- 12:01to the sheer volume of impacted organizations,
- 12:04and remember that's 25 universities in this region
- 12:06alone, we are actually seeing a massive coordinated
- 12:09national response. Yes, the scale requires it.
- 12:12The National Office of Cybersecurity, the Federal
- 12:15Department of Education, and Universities Australia
- 12:17have all been mobilized. And it's worth noting
- 12:20the OAIC response also specifically highlights
- 12:24the involvement of the National Office. of cybersecurity
- 12:27as the central coordinating entity here. It really
- 12:31functions remarkably like a multi -agency response
- 12:34to a major environmental crisis. That's a great
- 12:37comparison. It's like a bushfire. Right. You
- 12:39have the international vendor acting as the aerial
- 12:42water bombers, you know, putting out the central
- 12:44technical fire at the source. Right. Then you
- 12:47have the local universities acting as ground
- 12:49crews protecting their specific perimeters and
- 12:52triaging their local population. Yeah. And. overarching
- 12:56all of this the federal government bodies are
- 12:58running the command center ensuring resources
- 13:01and intelligence are distributed exactly but
- 13:04in a complex software supply chain breach like
- 13:07this i am curious how the burden of legal and
- 13:10communicative responsibility is divided i mean
- 13:14Instructure lost the data, but the university
- 13:16owns the relationship with the student. Right.
- 13:19And this division of labor is actually formalized
- 13:21in the tech industry. It's known as the shared
- 13:23responsibility model. Shared responsibility model.
- 13:25Okay. Yeah. In a cloud environment, the vendor,
- 13:28so in this case Instructure, is strictly responsible
- 13:31for the security of the cloud. Security of the
- 13:34cloud. Right. They maintain the structural integrity
- 13:37of the application, manage the network firewalls,
- 13:39and ensure the servers themselves are impenetrable.
- 13:43Therefore, the technical remediation and the
- 13:45forensic investigation fall entirely on their
- 13:48shoulders. Because they own the infrastructure,
- 13:50so they have to fix the broken lock. Precisely.
- 13:53Conversely, the institutions, so the universities
- 13:56and the schools, are responsible for the security
- 13:59of what is in the cloud. Ah. They are the designated
- 14:02data custodians. So, under the shared responsibility
- 14:06model, the burden of user communication localized
- 14:09risk assessment, and adherence to specific data
- 14:12breach notification laws rests entirely with
- 14:15the university. That makes sense. Yeah. They
- 14:17must evaluate how the exposed data impacts their
- 14:20specific student body and enact their own internal
- 14:22incident response playbooks. And where do the
- 14:25federal bodies come in? The federal bodies step
- 14:27in to provide the connective tissue. The National
- 14:29Office of Cybersecurity aggregates threat intelligence
- 14:32from Instructure and distributes it across the
- 14:35entire education sector. So they keep everyone
- 14:37talking. Right, ensuring that a tactical indicator
- 14:39of compromise discovered at one university is
- 14:42instantly mitigated across the other 24 before
- 14:45the attacker can pivot. Man, the coordination
- 14:48between vendor, custodian and government is incredibly
- 14:52intricate. It's a massive logistical undertaking.
- 14:55But, you know, for the listener whose internal
- 14:57messages and ideas are currently circulating
- 14:59out there, understanding the macro level response
- 15:01is really only half the battle. You ultimately
- 15:04need to know how the law actually protects your
- 15:07specific information and what recourse you have.
- 15:09And that's where things get a bit messy. Very
- 15:11messy. The guidance issued by the OAIC dives
- 15:14right into this, and it reveals a legal framework
- 15:17that is honestly surprisingly fragmented. Yeah,
- 15:21the application of privacy law to digital infrastructure
- 15:23in this country is characterized by some very
- 15:26significant jurisdictional complexities. Complex
- 15:29is one word for it. The OAIC guidance points
- 15:31out a fascinating detail regarding jurisdiction.
- 15:34Not all educational institutions are bound by
- 15:37the Federal Privacy Act of 1988. Which surprises
- 15:39a lot of people. It completely surprised me.
- 15:42They clarified that state and territory government
- 15:45schools are typically governed by state -specific
- 15:48privacy legislation. Right. And perhaps most
- 15:51surprisingly, public universities and TAFEs are
- 15:54generally exempt from the Federal Privacy Act
- 15:57entirely unless they are operating in the capacity
- 16:00of a private entity. Yep. I mean, the legislation
- 16:03governing a student's digital identity depends
- 16:05entirely on the geographical and structural classification
- 16:08of their school. This legislative patchwork is
- 16:11actually a byproduct of Australia's constitutional
- 16:14design. Really? How so? Well, the Federal Privacy
- 16:17Act generally derives its authority from the
- 16:19external affairs and corporate powers of the
- 16:21Constitution. It specifically targets Australian
- 16:24government agencies and private sector organizations
- 16:26with an annual turnover exceeding $3 million.
- 16:30Okay, that covers a lot of ground. It does. However,
- 16:33public universities and state schools are statutory
- 16:35bodies established under specific state or territory
- 16:38legislation. Because they are creations of the
- 16:41state government, they fall outside the standard
- 16:43purview of Commonwealth corporate law. Oh, so
- 16:46they aren't corporations. They are state entities.
- 16:49Exactly. Therefore, their data governance practices
- 16:52are regulated by the specific privacy, records,
- 16:56or information acts of their respective states
- 16:58or territories. That is wild. A student at a
- 17:02public university in New South Wales operates
- 17:05under a completely different legal privacy framework
- 17:07than a student at a private university in the
- 17:10exact same city. Even though both of their data
- 17:13sets were compromised in the exact same Canvas
- 17:16server breach? Exactly. Wow. Navigating that
- 17:19jurisdictional maze must be incredibly frustrating
- 17:22for a student or a staff member who simply wants
- 17:24to lodge a formal complaint about their exposed
- 17:27data. Oh, it is a massive headache. I bet. Because
- 17:30if a user discovers their internal Canvas messages
- 17:33have been leaked and they want to hold the institution
- 17:35accountable, the OAIC has a very strict protocol.
- 17:38Very strict. You cannot bypass the system and...
- 17:41escalate directly to the information commissioner.
- 17:43The OAIC mandates that any individual privacy
- 17:46complaint must first be lodged directly within
- 17:49structure or the specific education provider.
- 17:52Yeah, the regulatory framework is designed to
- 17:54force dispute resolution at the lowest possible
- 17:56level before a federal regulator intervenes.
- 17:59Right. So the user has to submit their grievance
- 18:01directly to the entity that failed to protect
- 18:03their data. And crucially, the OAIC stipulates
- 18:07that the entity must be granted a minimum of
- 18:0930 days to adequately respond to the complaint?
- 18:12Yes, the 30 -day window. Only after that 30 -day
- 18:15window expires, or if the response is deemed
- 18:18wholly inadequate, only then can the user escalate
- 18:21the issue to the OAIC for a formal investigation.
- 18:24That 30 -day service level agreement, or SLA,
- 18:28is a standard mechanism in privacy law. It feels
- 18:31like a long time for the victim, though. It does.
- 18:33But it acknowledges the reality that following
- 18:36a massive breach, an institution's absolute immediate
- 18:39priority has to be technical containment and
- 18:41forensic investigation. Putting out the fire.
- 18:43Exactly. The 30 -day window provides the organization
- 18:46the necessary time to complete their internal
- 18:48audits, understand the exact scope of the compromise
- 18:51regarding that specific user, and formulate a
- 18:54legally sound response. Okay, that makes sense.
- 18:56Yeah, an immediate regulatory investigation on
- 18:59day one would just actively impede the technical
- 19:02incident response. Well, that definitely makes
- 19:04logistical sense for the institution. Waiting
- 19:0730 days is cold comfort for a user worried about
- 19:10immediate spear phishing attacks. Oh, absolutely.
- 19:12The anxiety is real. And recognizing that immediate
- 19:15vulnerability, both the OAIC and the Australian
- 19:18government have provided users with three highly
- 19:21specific technical steps to secure their personal
- 19:25infrastructure right now. And people need to
- 19:27pay attention to these. Yes. These aren't just
- 19:29polite suggestions. They are vital defensive
- 19:32measures against the weaponization we discussed
- 19:34earlier. Implementing these steps directly neutralizes
- 19:37the value of the compromised Canvas data. So
- 19:40the first directive is to establish multi -factor
- 19:43authentication, or MFA, on absolutely every available
- 19:46platform. Standard. But crucial. Right. If an
- 19:50attacker leverages your Canvas data to craft
- 19:52a flawless phishing email and successfully tricks
- 19:55you into handing over your password, MFA serves
- 19:57as the critical circuit breaker. It really does.
- 20:00They possess the credentials, sure, but they
- 20:02cannot authenticate the session without the secondary
- 20:05cryptographic proof generated by your specific
- 20:07device. Right. And the second directive from
- 20:09the government focuses on the complexity of access
- 20:12controls. They explicitly recommend utilizing
- 20:15passphrases that are 14... or more characters
- 20:18in length, emphasizing that these must be entirely
- 20:21unique for every single account. 14 characters.
- 20:24Now, the distinction between a complex password
- 20:27and a 14 -character passphrase is, mathematically
- 20:30speaking, quite significant, right? It is massive.
- 20:32Because a standard 8 -character password, even
- 20:35with symbols and numbers, can often be cracked
- 20:37rapidly by modern computing power using rainbow
- 20:40tables or brute force algorithms. Very easily,
- 20:42yeah. But a 14 -character passphrase like, say,
- 20:45a bizarre memorable sentence, exponentially increases
- 20:49the entropy. Exactly. It renders brute force
- 20:51attacks computationally unfeasible, securing
- 20:54your accounts even if one set of credentials
- 20:56is leaked somewhere else. The math just makes
- 20:59it impossible for them to crack in a reasonable
- 21:01time frame. And then the final technical directive
- 21:04is the immediate installation of software updates
- 21:07across all personal devices to patch known vulnerabilities.
- 21:11Don't ignore those update prompts. Never. Additionally,
- 21:14the OAIC directs users to the National Anti -Scam
- 21:18Center's ScamWatch platform. Right, ScamWatch.
- 21:21Yeah, this serves to educate the public on identifying
- 21:24the specific tactical signatures of the targeted
- 21:27phishing campaigns that, quite frankly, inevitably
- 21:30follow a data exfiltration event of this nature.
- 21:33Because by enforcing MFA and utilizing those
- 21:36high entropy passphrases, you are effectively
- 21:38isolating the breach. You're boxing them out.
- 21:40Exactly. The attacker might have the floor plan
- 21:43of the lobby, going back to our analogy, but
- 21:45you have systematically upgraded the deadbolts
- 21:47on every single internal door of your digital
- 21:50life. Which is really all you can do as an end
- 21:52user. But as we conclude our discussion of this
- 21:55incident, it leaves us with a profound operational
- 21:57question regarding the architecture of our modern
- 22:00digital ecosystems. I think I know where you're
- 22:02going with this. The adoption of centralized
- 22:05platforms like Canvas across 9 ,000 institutions
- 22:08offers unparalleled efficiency, data uniformity,
- 22:12and administrative convenience. It's incredibly
- 22:14convenient. But this incident... perfectly illustrates
- 22:17the inherent peril of software supply chain consolidation.
- 22:21It creates an unfathomably large single point
- 22:25of failure. When a solitary vendor experiences
- 22:28a vulnerability, the shockwaves instantly trigger
- 22:30a crisis for 9 ,000 separate educational networks.
- 22:34It's terrifying when you put it like that. It
- 22:36is. Supply chain cybersecurity has evolved beyond
- 22:39a standard IT concern. It is now a fundamental
- 22:42risk to the operational continuity of global
- 22:44sectors. We really must critically evaluate whether
- 22:47the administrative convenience of a single centralized
- 22:49system justifies the concentrated catastrophic
- 22:52risk it introduces. The efficiency of a massive
- 22:56shared digital skyscraper is undeniable right
- 22:59up until the foundation is compromised. Exactly.
- 23:01If evaluating the mechanics of this breach has
- 23:03prompted you to consider the resilience of your
- 23:05own digital architecture, we warmly encourage
- 23:08you to take proactive control. Don't wait for...
- 23:10Absolutely. Whether you are looking to audit
- 23:13your personal data security or fortify your organization's
- 23:16IT infrastructure against supply chain vulnerabilities,
- 23:19visit www .kinsoft .com .au to discuss your security
- 23:25and IT needs with experts who truly understand
- 23:27the complexities of this evolving landscape.
- 23:30Get ahead of the threat. You have the power to
- 23:32secure your perimeter before an incident forces
- 23:34your hand. Thank you for joining us on this thorough
- 23:37examination of the Canvas incident. By staying
- 23:39informed on the mechanics of a breach, applying
- 23:41robust authentication measures, and remaining
- 23:44vigilant against targeted social engineering,
- 23:46you can ensure your digital environment remains
- 23:48secure. Stay safe out there. Stay informed, stay
- 23:51secure, and we will catch you next time.