Why Retired IT Equipment Can Become a Cybersecurity Blind Spot
The security team at a mid-sized insurer spent eighteen months hardening everything that faced the internet. They rotated credentials, tightened their identity provider, and ran tabletop exercises until the incident playbook felt routine. Then a contractor bought a pallet of decommissioned laptops at a regional auction and found four of them still booting into a cached domain profile. Nothing had been breached. The data simply walked out through the loading dock, on equipment the company had already stopped thinking about.