Cybersecurity breaches orchestrated by malicious attackers can have painful consequences for victim organizations. Such events show how breaches can occur and what factors lead to them. This study offers a point of reflection from theoretical and security-posture perspectives, focusing on the Mercer Advisors Inc. data breach. While acknowledging the limitations of public records, the study contributes to the literature by examining theoretical and security-posture aspects, such as the lack of multi-factor authentication at all required levels and the possible failure to implement a robust defense-in-depth strategy, both of which can result in adverse consequences for organizations.
The Mercer Advisors data breach through the essential eight: lessons and analytical limits
Indra Abeysekera

