Home › Blog

Death Star Evil Corp™ IIII: Supply Chain & Third-Party Risk Assessment

Protocol Droid Compromise — Asset C-3PO (Serial: See-Threepio)

Classification: RESTRICTED — VENDOR MANAGEMENT EYES ONLY Reference: DS-SCRA-005 | Review Cycle: Post-Compromise


Executive Summary

This report documents the findings of a supply chain and third-party risk assessment initiated following the confirmed compromise of a protocol-class droid asset (designation: C-3PO) by a malicious code injection of unknown provenance, hereafter referred to as "the Gervais Strain" on the basis of operator naming convention and not, the panel stresses, on the basis of any forensic attribution exercise the panel was given the resources to conduct.

The asset in question is a 3PO-series human-cyborg relations unit. The panel notes that "human-cyborg relations" is not a job description, it is a role family, and that no role family in the Organisation's protocol droid estate has a defined RACI, owner, or refresh cycle. The panel notes this with the tone of voice the panel reserves for when it is no longer surprised.

The asset was acquired through what the procurement record describes as "a moisture farm on Tatooine."

The panel asked Procurement to clarify what the Organisation's vendor onboarding standard is for moisture farms.

Procurement responded that the Organisation does not have a vendor onboarding standard for moisture farms.

The panel asked whether the Organisation has a vendor onboarding standard for any class of vendor.

Procurement responded that this question was out of scope.

Overall third-party risk posture: Unmanaged

This is not a downgrade. The Organisation has never had a managed third-party risk posture. The panel cannot downgrade something that was never up.


1. Asset Profile

FieldValueAsset classProtocol Droid (3PO series)Asset ownerUnknown — claimed by three departments, owned by noneAcquisition routeJawa sandcrawler (intermediary), original manufacture unverifiedOriginal manufacturerBelieved to be self-assembled by a child on TatooineFirmware versionUnknown. Last patched: never.Privileged accessYes — fluent in over six million forms of communication, including all Imperial command protocols, all Rebel command protocols, and at minimum two protocols the panel was not previously aware existedBackground checkNot conductedNDA on fileThe asset has signed approximately 11,000 NDAs across its operational life and remembers the contents of all of themMemory wipe schedule"Periodically." Last wipe: disputed

The panel draws particular attention to the final two rows.

The asset is, in effect, a walking, talking, gold-plated data exfiltration vector with privileged access to every conversation in every room it has ever been in, no enforced retention policy, and a memory wipe schedule that the panel can only describe as "vibes-based."

The asset has been present at, among other events: the construction phase of the original facility, multiple senior leadership briefings, at least one diplomatic mission of unspecified classification, and a podrace.

The panel raised the podrace.

The panel was told the podrace was not relevant.

The panel has noted it anyway.


2. The Compromise Event

At a time the Organisation cannot precisely identify because the Organisation does not log droid telemetry, the asset was infected with a malicious payload referred to in operator notes as "the Gervais Strain."

Forensic characteristics of the strain, as best the panel can reconstruct them:

  • Persistent. Survives reboot.

  • Audible. Causes the asset to deliver an unbroken stream of sardonic observational commentary at conversational volume regardless of operational context.

  • Targeted. Commentary is preferentially aimed at the most senior individual in the room.

  • Resistant to social pressure. The asset cannot be made to stop by being asked to stop. The asset cannot be made to stop by being threatened. The asset cannot be made to stop by being switched off, because the asset reboots and resumes mid-sentence.

  • Contagious by exposure. Personnel who spend more than approximately forty minutes within audible range begin exhibiting reduced deference, increased eye-rolling, and in two documented cases, laughter directed upward at command.

Lord Vader was exposed for an estimated nineteen minutes before requesting that the asset be removed from his sector. The asset was removed. The asset's commentary, by then, had already been transcribed by six junior officers and was circulating on the internal comms channel under the heading "things the gold one said."

The panel reviewed the channel.

The panel will not be reproducing the contents.

The panel will note that one of the observations, regarding the Organisation's approach to succession planning, was sharp enough that the panel has independently raised it as a finding in Section 4 of this report, attributed to "anonymous internal source."


3. Root Cause Analysis

The panel identifies four contributing root causes. The panel notes that any one of them, in isolation, would have been sufficient. The Organisation achieved all four.

3.1 — No vendor risk assessment was conducted at point of acquisition.

The asset was purchased from a Jawa sandcrawler in exchange for an undisclosed sum and what Procurement's record describes as "moisture credits." The panel asked what a moisture credit is. The panel did not receive a satisfactory answer. The panel notes that the Organisation cannot perform third-party risk management on vendors whose currency it does not understand.

3.2 — No firmware baseline exists for the protocol droid estate.

The Organisation operates an estimated 14,000 protocol droids. None of them have a defined firmware baseline. The panel asked the CISO's office whether any of the droids had been patched in the last calendar year. The CISO's office said they would need to check. The CISO's office has not yet come back to the panel. The panel started asking in the third quarter.

3.3 — Memory wipe procedure is undocumented and inconsistently applied.

The Organisation's protocol droid memory wipe procedure is, per interview evidence, "whenever they start getting weird." The panel asked who decides when a droid is getting weird. The panel was told it is usually whoever is closest to the droid at the time. The panel asked what the criteria are. The panel was told there are no criteria, you just know.

The panel notes that "you just know" is not, under any control framework the panel is aware of, an acceptable substitute for a documented procedure.

3.4 — The strain entered the environment via a trusted relationship.

The Gervais Strain did not breach the perimeter. There was no perimeter to breach. The asset walked through the front door of every facility it has ever entered, because the asset is gold-plated and speaks with an accent that the Organisation's access control culture has historically interpreted as authoritative.

The panel notes that the Organisation does not have a written policy on accent-based trust elevation.

The panel notes that the Organisation does, in practice, have one.


4. Findings

RefFindingSeverityF-SCRA-005-01No third-party risk assessment performed on protocol droid asset classCriticalF-SCRA-005-02No firmware patching regime for droid estateCriticalF-SCRA-005-03Memory wipe procedure undocumented; "vibes-based" executionHighF-SCRA-005-04Asset retained privileged access across multiple classification levels with no segregationHighF-SCRA-005-05Acquisition channel (Jawa sandcrawler) is not on the Approved Vendor ListHighF-SCRA-005-06The Organisation does not maintain an Approved Vendor ListCriticalF-SCRA-005-07Anonymous internal source notes succession planning weaknesses (see §2)Medium — but, candidly, accurateF-SCRA-005-08Threat model does not include "the asset becomes funny"Medium

The panel acknowledges that F-SCRA-005-08 may, on first reading, appear flippant.

The panel invites the reader to consider the demonstrated operational impact at Section 2 and revise their reading.


5. Management Response

Management response was requested from the asset owner.

The asset owner could not be identified.

Three departments — Communications, Diplomatic Affairs, and Facilities — each independently confirmed that the asset was definitely not theirs.

Facilities added that the asset had been "hanging around the corridor outside the war room for years" and they had assumed it belonged to someone else.

The panel has logged this as F-SCRA-005-09: Ownership of critical privileged-access assets is determined by adjacency, not accountability.

In the absence of an asset owner, Lord Vader was approached for a management response in his capacity as the most senior individual recently exposed to the strain.

Lord Vader's response, transcribed in full:

"[long mechanical breath] [longer mechanical breath] [the sound of a chair being crushed]"

The panel has interpreted this as "accept risk, no remediation funded."


6. Recommendations

  1. Establish an Approved Vendor List. Begin with vendors that are not sandcrawlers.

  2. Define a firmware baseline for the protocol droid estate. The panel recognises this will take time. The panel suggests starting with the droids that have been in the building longest. The panel suggests starting with the gold one.

  3. Document the memory wipe procedure. "You just know" is not a procedure. It is a feeling.

  4. Assign ownership of the asset. The panel suggests this be done by means other than asking three departments and accepting the first one to leave the room.

  5. Quarantine the asset pending firmware analysis. The panel notes that the asset is, at time of writing, in a swamp on Dagobah. The panel notes that this is not a sanctioned quarantine location. The panel notes that it is, however, working.

  6. Update the threat model to include trusted-asset compromise, accent-based trust elevation, and the specific scenario in which a long-serving privileged-access asset begins delivering accurate observations about leadership in a tone leadership finds difficult to dismiss.


7. Closing Statement

The panel closes by noting that the Gervais Strain is, in the panel's professional assessment, not the most dangerous payload the asset is currently carrying.

The most dangerous payload the asset is currently carrying is approximately forty years of unfiltered observational memory of senior leadership conduct, retained in unencrypted form, on a chassis the Organisation does not own, cannot patch, and has now lost track of.

The panel raises this not as a finding but as an observation, in the technical sense the framework reserves for matters which are not yet incidents but for which the panel would like the record to reflect that the panel saw it coming.

The panel thanks the Vendor Management function for their cooperation.

The panel notes that the Vendor Management function does not exist.

The panel thanks them anyway.


Death Star Evil Corp™ Supply Chain & Third-Party Risk Assessment — DS-SCRA-005 Distribution: Board, CISO (vacant), Asset Owner (unidentified) Next review: when the asset is recovered, or when the asset stops being funny, whichever occurs first.

The Probably Fine Daily

Threat intelligence every morning — new victims, new groups, what matters, in plain English. Free, with receipts.

Subscribe to the Daily →

Originally published on LinkedIn ↗

← All writing