Unexpected, concise, clear, communicated with both summaries and details, and action-oriented. As it pertains to emails about technical topics, it doesn't get much better than this.
I now feel that much more confident that Stephen isn't just thinking about doing the tasks he is assigned... he is thinking about the overall picture and health of Lessonly as we navigate this journey we are on.
HI everybody,
As you may or may not be aware there was a massive hack on solarwinds which provides infrastructure software to many companies. ( https://www.solarwinds.com/securityadvisory ).
I want to present to this group the (preliminary) findings as I investigated our exposure because industry-wide implications and more customers are going to be asking about this. It is going to be beneficial to have some sort of statement to respond with.
If you would like me to work with somebody on what that statement should be please let me know. And if you have any guidance on verbage before we craft such a statement I would appreciate it.
Executive Summary
We use a small unaffected Solarwinds product in non production environments. A couple of our vendors had similar exposure. Our biggest risk is Twilio which actually used an affected product, but they believe they were not impacted by the breach.
Our Direct Exposure
We do not use their software directly in our data centers.
PaperTrail
We use a product called PaperTrail in non-production environments for logging. No sensitive information should be sent there. This product
Vendors
Vendors known to have some exposure to SolarWinds Products
Twilio (Sendgrid, Twilio, Segment)
The company Twilio owns 3 services that we use. Twilio did use the affected software "in a limited fashion." They have been working with SolarWinds and believe they were ultimately unaffected by the breach
Twilio is our biggest risk, but at this point I believe it to be mitigated.
Harness
Harness used an unaffected SolarWinds product (Pingdom). Ultimately I see no risk here, but they did share this for transparency.
CloudBees (Codeship)
CloudBees owns the codeship product that we use. They, like Harness, used some unaffected SolarWinds products