russ@signalint.net · all
Brief email with some concerns about IT security
Wed Sep 09, 2026 · 01:27 PM EDT
Team,
I'm still piecing together forensics.... typed this up to summarize my thoughts to Mike or Phil... so i'm sending this to you guys now for review.
Email to mike below, please give me feedback or suggestions.
Mike,
We have to operate as one team. What is happening now is not a reliable or dependable way to run production IT from a business continuity, information security OpSec perspective, or from a business efficiency standpoint.
Our team prioritizes dependability, reliability, secure operations, and operational efficiency with our IT policies, security controls, and overall technology stack...
I'd like to address a concern regarding the organization's IT procedures that I have observed at Rockland, not meant as a personal offense or targetting anyone, nor the organization Rockland Bakery, which I would like to not that we have a high amount of respect for.
Unannounced changes to production IT infrastructure, production applications, code, and IAM are being pushed with no notice to the people who keep the systems running and legitimately require safe and consistent IAM, Active Directory security controls.
Making changes to live IAM policies without involving or communicating to the impacted teams, or the owners of systems that are impacted by these IAM policies. It is a major issue usually if a production IAM policy change impacts a user or automated system, without proper announcement and communication from the IT Security team.
( these types of changes are usually a security-hardening policy change, implementing a new network ACL )
We need those systems steady and dependable. There is no time for to be fighting fires internally and spinning our gears, when we have important and urgent work to attend to.
Our team must be made aware of these changes, ahead of time, so that our operations are not impacted, and that we can ensure business continuity and dependable IT systems.
Our team had zero communication, no warning or the announcements whatsoever. There were no attempts to reach out to us throughout this entire process. We cannot have sperate isolated teams working without communication.
The Rockland AD password rotation policy is a clear example. I won't belabor this point. However, NIST, CISA, CIS all agree that frequent password rotation policies are ineffective and sometimes counter-effective. These are actively discouraged in the information security community today; frequent rotation policies have been shown to actually weaken the security posture of an enterprise.
NIST SP 800-63B is explicit on this:
Do not expire a password on a calendar. Change it when there is evidence of compromise. Calendar rotation trains people to pick simple, reused passwords and they foster an attitude of apathy from users. ....
We should implement MFA with a standard TOTP implementation, FIDO Yubi-key based authentication, or implement a strong enterprise password vault with pass-keys
( this is not an exhaustive list of issues, but i am cutting it short to save time. however, another relevant subject is zero-trust cryptographic systems and entperprise password/secrets/key/HSM vaults )
when it's all cut and dried, we are on the same team here, so we should all be aware of major IAM and domain changes. Also, there should be a proper production schedule for making IAM and ACL changes during proper maintenance window, with some semblance of a control review board or index of changes. This is how we can best avoid outages and ensure dependable IT systems.
Russell
CISSP