> the assertion here is that Palantir being unable to defend its own networks against a fairly rudimentary and mundane attack throws its entire business offering around cybersecurity into question
I think you're right. I would imagine this will prompt some tough questions both within their existing customer franchise and in pitches for new business.
Here's how Palantir describe their company cybersecurity platform on their own website[0]:
> With Palantir, your enterprise can finally detect advanced threats that lie hidden within your data. All of it. Structured network logs from proxy to IDS, VPN, anti-virus, DLP, DNS queries, malware tools, and application logs. Contextual data like email, print logs, facility access logs, internal chat logs, and human resources data. Open source and third party data. Our technology integrates it all into a single environment, and separates actionable signal from the noise so you can protect your network.
So the obvious question if you're the CEO or CISO of a company that does or is considering doing business with Palantir is, "You guys have unfettered access to your own network -- you can deploy your own cyber solutions without any restraints whatsoever. And yet you couldn't detect these intruders on your own system?"
Importantly, I'm not sure this would be a fair criticism -- it sounds like the white hat hackers they hired were very very good at covering their tracks -- but there's no doubt this leak is going to result in some tough conversations.
I think you're right. I would imagine this will prompt some tough questions both within their existing customer franchise and in pitches for new business.
Here's how Palantir describe their company cybersecurity platform on their own website[0]:
> With Palantir, your enterprise can finally detect advanced threats that lie hidden within your data. All of it. Structured network logs from proxy to IDS, VPN, anti-virus, DLP, DNS queries, malware tools, and application logs. Contextual data like email, print logs, facility access logs, internal chat logs, and human resources data. Open source and third party data. Our technology integrates it all into a single environment, and separates actionable signal from the noise so you can protect your network.
So the obvious question if you're the CEO or CISO of a company that does or is considering doing business with Palantir is, "You guys have unfettered access to your own network -- you can deploy your own cyber solutions without any restraints whatsoever. And yet you couldn't detect these intruders on your own system?"
Importantly, I'm not sure this would be a fair criticism -- it sounds like the white hat hackers they hired were very very good at covering their tracks -- but there's no doubt this leak is going to result in some tough conversations.
[0]: https://www.palantir.com/solutions/cyber/