Stay connected: follow us on LinkedIn and explore more at
www.CherryHillAdvisory.com.

Subscribe now to join the Risk Register community:

Source: Reuters
Summary: Boston Scientific disclosed a cybersecurity incident detected August 25, 2026 that impaired access to operating systems and business applications, interrupting manufacturing, order processing, and shipments. Early‑September updates said product‑quality analysis found no impairment to product function, remote‑monitoring activation was restored for certain cardiac‑device communicators, and manufacturing resumed at most facilities, with backlogs and recovery work ongoing. The company said the disruption will materially affect third‑quarter and full‑year 2026 results and could hurt 2026 sales and profit. No actor was named, and the company said no ICS‑specific malware was identified.
Internal Audit Implications: An IT compromise that halts manufacturing is a direct test of operational resilience and ICFR under stress. Act this quarter to close the audit gap between cyber, production, and finance. - Incident response and resilience: Review incident governance, escalation, and decision logs from August 25 onward. Compare actual RTO/RPO for operating systems, business applications, and plant systems to stated objectives. Validate backup/restore evidence and recovery sequencing (ERP, MES, order entry, shipping). - OT/IT containment: Assess control design for segmentation between corporate IT and manufacturing networks; review emergency access approvals and privileged account activity during containment and restart. - Product and service restoration: For the restored remote‑monitoring activation on certain cardiac‑device communicators, test change management, validation, and rollback readiness. Trace the product‑quality analysis that found no impairment to product function—verify independence, sampling, and documentation. - Revenue, inventory, and disclosure: Stress‑test ICFR around revenue recognition and cutoff where order processing and shipment were disrupted. Reconcile backlog estimates to subsequent shipments; test inventory valuation adjustments arising from delays. Evaluate disclosure controls for estimating and updating the material impact on 2026 results. Controls to test: business continuity plans; disaster recovery runbooks; network segmentation and EDR in manufacturing zones; privileged access reviews; manual order‑entry and shipment approvals; backlog and deferred revenue reconciliations; post‑incident change management. Expect audit committee questions: What single points of failure allowed IT to stop production? Were RTO/RPO met? How is backlog quantified and prioritized? What changed to prevent recurrence? Are ICFR and disclosure controls operating effectively? What emerging risks were added to the risk register?

Source: U.S. Securities and Exchange Commission (EDGAR)
Summary: Veradigm’s September 8, 2026 Form 8‑K reports a cybersecurity incident at a third‑party vendor where an unauthorized party accessed the vendor’s environment and downloaded customer data via compromised credentials tied to a company API. The filing states some customer data, including Social Security numbers, were involved. Veradigm said no clinical data or its internal systems were compromised. The company activated incident response, notified law enforcement, and is investigating, while offering credit monitoring to affected individuals. The 8‑K specifies the vendor credential compromise method and timely SEC disclosure.
Internal Audit Implications: Treat this as a concrete scenario to tighten third‑party and API controls now. Start with a targeted risk assessment of all APIs exposed to vendors: inventory service accounts/keys, their scopes, where secrets are stored, rotation cadence, and anomaly alerting on usage. Disable unused credentials, enforce least privilege for data access, and require IP allow‑listing or equivalent controls where feasible. Evaluate vendor risk governance end‑to‑end: due diligence, security requirements in contracts (breach notice SLAs, credential standards, data minimization/retention), onboarding attestations, and continuous monitoring. Confirm data maps show precisely which customer PII flows through each vendor, so incident scoping is fast and accurate when SSNs or similar identifiers are implicated. For SOX 404, assess disclosure controls and procedures for cyber incidents: evidence of timely escalation, legal/IR review, and board‑level communication that supported the 8‑K filing. Consider whether reserves or accruals are triggered for response activities like credit monitoring and customer notification. Controls to test: API secrets management (vaulting, rotation evidence, key ownership), service‑account provisioning and termination, least‑privilege data entitlements, API rate‑limiting and geolocation alerts, vendor access reviews, incident‑response playbooks for third‑party breaches, and customer notification workflows. Expect audit committee questions: What data categories and jurisdictions are affected? How were API credentials protected and what changed to prevent reuse? Which vendors hold sensitive identifiers and why? How fast can we revoke access and rotate credentials? Are SOX disclosure controls operating effectively?

Source: SANS Institute (NewsBites)
Summary: SANS NewsBites reports the FBI opened an inquiry into “Nexus,” a dark‑web service claiming scans of identity documents for an estimated 170 million people in the U.S. and Canada. Reported counts include over 153 million driver’s licenses, more than 10 million identification cards, about 1.9 million travel documents, roughly 1.3 million international IDs, and at least 579,000 medical cards. Brian Krebs linked samples and timestamps to a third‑party ID verification provider, IDScan.net. SANS noted Nexus added nearly 400,000 new records in 24 hours and later reported the site was unavailable; public statements were pending.
Internal Audit Implications: This is a vendor and data‑retention wake‑up call. Assume your organization’s customers, patients, or employees are represented in ID document datasets and act accordingly. Prioritize a rapid risk assessment of ID‑verification services and any vendor storing document scans or images: what data elements they hold, where, how long, and why. Internal audit should test data minimization and retention controls: do policies prohibit storing full scans when attributes suffice, and do vendors evidence deletion on schedule? Sample vendor deletion logs and tickets; trace requests to confirmations. Verify encryption requirements for data in transit and at rest in contracts, and that vendors attest to compliance. Re‑evaluate breach notification governance: do contracts mandate prompt notice, clear points of contact, and cooperation on regulator and individual notifications? Tabletop a vendor‑originated breach scenario to validate playbooks, contact trees, and dark‑web monitoring handoffs. Strengthen risk governance: update the risk register to reflect this emerging risk, with explicit ownership, metrics (e.g., number of vendors holding ID images), and remediation timelines. Require business owners to justify the continued collection of scanned IDs and to implement a kill switch to pause data flows to a vendor under investigation. Controls to test: vendor due diligence and continuous monitoring; data maps of PII at vendors; retention/deletion evidence; contractual security clauses; access reviews for file repositories receiving ID images. Audit committee will ask: Which vendors store ID scans? What’s our deletion evidence? How quickly can we suspend transfers? What’s our notification posture if our data appears in a Nexus‑type leak?
Disclaimer: This content is provided for general informational purposes only and does not constitute legal, accounting, tax, investment, or other professional advice. Portions were generated using AI tools from public web sources and may contain errors or omissions — verify important details against the primary sources linked above before relying on them. Any example prompts, scripts, templates, or other artifacts are provided “as is” without warranty of any kind, express or implied; test them on non-production data and apply your own professional judgement before use. Cherry Hill Advisory disclaims all liability for any loss or damage arising from the use of, or reliance on, this content or any artifact it contains.
Subscribe now to join the Risk Register community: