Third Parties in the Incident Path: The Response Plan Gap CISA Documented
Of the three lessons in CISA advisory AA25-266A, the third-party one is the easiest to skim past. The agency's incident response plan did not enable it to engage third parties promptly, nor to grant those third parties access to the resources they needed, and that omission delayed elements of the response.
That is a governance failure with a technical surface attached, and it deserves its own treatment because most response plans are silent on the same point.
What the advisory says happened
The timeline recorded in the advisory runs from the discovery of suspicious activity on a public-facing application, through the exploitation of CVE-2024-36401 on two hosts, lateral movement to a web server and a SQL server, and finally detection via endpoint alerts on the database server roughly three weeks later.
The lesson about third parties concerns the response phase. Engaging external help requires contracts, contact details and access provisioning, and none of those are instant. When the plan has no procedure for them, an organisation loses time at the point in an incident when time is most expensive.
The exposure dimension of readiness
Readiness has a measurable component too. An organisation cannot pre-agree access for a vendor to systems nobody has documented. Exposure records give a concrete way to test whether the asset register underlying the response plan is complete.
ZoomEye exact-match observations on 2026-09-29, for the product named in the advisory:
| Query | Exact count |
| --- | --- |
| app="GeoServer" | 57,663 |
| app="GeoServer" && service="http" | 47,664 |
| app="GeoServer" && port="8080" | 9,770 |
| app="GeoServer" && port="8443" | 625 |
For any single organisation, the useful exercise is smaller in scale and sharper in effect: take your own public fingerprint matches, and check whether each one appears in the documentation that your response plan depends on. Every host that does not appear is a host an external responder cannot be pre-authorised to examine.
Building third-party readiness into the plan
The advisory's recommendations imply a short list of pre-work.
- Name the third parties and the circumstances for engaging them. Contracts and legal review take longer than the incident.
- Pre-provision access paths. Know in advance how an external responder obtains read-only access to endpoint telemetry, web logs and the relevant cloud or on-premises consoles.
- Define what the third party may and may not touch, in writing, so that access can be granted quickly rather than negotiated live.
- Exercise the arrangement. An access path that has never been tested is an assumption, and the advisory's wording about the plan not enabling prompt engagement suggests exactly that gap.
- Keep the escalations current. Contacts, on-call rotations and authorisation levels change, and a plan that is not reviewed drifts out of date.
The compounding effect
The three lessons in this advisory reinforce each other. An unpatched public service creates the incident. Missing detection coverage lets it run for three weeks. A response plan with no third-party procedure slows the response once it is finally noticed. Each is individually survivable; together they explain why a known vulnerability on a reachable host became a multi-week intrusion.
For organisations that rely on external providers or integrators to run parts of their estate, there is an additional angle. Those providers hold the deployment knowledge for services that internal teams may never have documented, which makes them both a source of inventory truth and a dependency during response.
Conclusion
Third-party readiness is not a procurement detail. It is the difference between a response that starts when the alert fires and one that starts when the paperwork allows. The advisory records a plan that was not exercised and did not enable prompt external assistance; reviewing that clause in your own plan is a low-cost change with a direct effect on mean time to respond.
References
- CISA, "CISA Shares Lessons Learned from an Incident Response Engagement," AA25-266A, September 23, 2025. https://www.cisa.gov/news-events/cybersecurity-advisories/aa25-266a
- ZoomEye search observations, exact-match counts, collected 2026-09-29 05:15 UTC. https://www.zoomeye.ai/
Top comments (0)