Sync a voice

russ@signalint.net · all

Re: Brief email with some concerns about IT security

Wed Sep 09, 2026 · 01:45 PM EDT

From
Andrew Chalfin <andrew@broadbandtelatom.com>
To
Tom Turner <tom@broadbandtelatom.com>, Russell Dwyer <russ@signalint.net>

Russ don't send for now we need hard data.

Get Outlook for Androidaka.ms/AAb9ysg
________________________________
From: Tom Turner <tom@broadbandtelatom.com>
Sent: Wednesday, 09 September 2026 13:29:42
To: Russell Dwyer <russ@signalint.net>
Cc: Andrew Chalfin <andrew@broadbandtelatom.com>
Subject: Re: Brief email with some concerns about IT security

AD report manager, purview auditing, exchange mail trace tool.

> On Sep 9, 2026, at 1:27 PM, Russell Dwyer <russ@signalint.net> wrote:
>
> Team,
>
> I'm still piecing together forensics.... typed this up to summarize my
> thoughts to Mike or Phil... so i'm sending this to you guys now for
> review.
> Email to mike below, please give me feedback or suggestions.
>
> Mike,
>
> We have to operate as one team. What is happening now is not a
> reliable or dependable way to run production IT from a business
> continuity, information security OpSec perspective, or from a business
> efficiency standpoint.
>
> Our team prioritizes dependability, reliability, secure operations,
> and operational efficiency with our IT policies, security controls,
> and overall technology stack...
>
> I'd like to address a concern regarding the organization's IT
> procedures that I have observed at Rockland, not meant as a personal
> offense or targetting anyone, nor the organization Rockland Bakery,
> which I would like to not that we have a high amount of respect for.
>
>
> Unannounced changes to production IT infrastructure, production
> applications, code, and IAM are being pushed with no notice to the
> people who keep the systems running and legitimately require safe and
> consistent IAM, Active Directory security controls.
>
> Making changes to live IAM policies without involving or communicating
> to the impacted teams, or the owners of systems that are impacted by
> these IAM policies. It is a major issue usually if a production IAM
> policy change impacts a user or automated system, without proper
> announcement and communication from the IT Security team.
>
> ( these types of changes are usually a security-hardening policy
> change, implementing a new network ACL )
>
>
> We need those systems steady and dependable. There is no time for to
> be fighting fires internally and spinning our gears, when we have
> important and urgent work to attend to.
>
> Our team must be made aware of these changes, ahead of time, so that
> our operations are not impacted, and that we can ensure business
> continuity and dependable IT systems.
>
>
>
> Our team had zero communication, no warning or the announcements
> whatsoever. There were no attempts to reach out to us throughout this
> entire process. We cannot have sperate isolated teams working without
> communication.
>
>
> The Rockland AD password rotation policy is a clear example. I won't
> belabor this point. However, NIST, CISA, CIS all agree that frequent
> password rotation policies are ineffective and sometimes
> counter-effective. These are actively discouraged in the information
> security community today; frequent rotation policies have been shown
> to actually weaken the security posture of an enterprise.
>
> NIST SP 800-63B is explicit on this:
> Do not expire a password on a calendar. Change it when there is
> evidence of compromise. Calendar rotation trains people to pick
> simple, reused passwords and they foster an attitude of apathy from
> users. ....
>
> We should implement MFA with a standard TOTP implementation, FIDO
> Yubi-key based authentication, or implement a strong enterprise
> password vault with pass-keys
>
> ( this is not an exhaustive list of issues, but i am cutting it short
> to save time. however, another relevant subject is zero-trust
> cryptographic systems and entperprise password/secrets/key/HSM vaults
> )
>
> when it's all cut and dried, we are on the same team here, so we
> should all be aware of major IAM and domain changes. Also, there
> should be a proper production schedule for making IAM and ACL changes
> during proper maintenance window, with some semblance of a control
> review board or index of changes. This is how we can best avoid
> outages and ensure dependable IT systems.
>
> Russell
> CISSP