The recent Metabase vulnerability generated significant attention across the security community.

Most of the discussion focused on the technical aspects of the vulnerability chain and the fact that it ultimately allowed unauthenticated attackers to obtain administrative access.

From a technical perspective, the vulnerability was interesting.

From a security leadership perspective, however, the more important lesson lies elsewhere.

The vulnerability highlights a persistent problem we encounter during penetration tests, IT Health Checks and security reviews:

Organisations frequently have less visibility into secondary business systems than they believe.

The False Comfort of Asset Classification

Most organisations maintain some form of asset classification process.

Business critical applications receive significant attention. Defensive controls are strengthened. Monitoring is prioritised. Vulnerability management is performed regularly. Security teams have a generally good understanding of the systems and their associated risks.

Then there is a second category.

These are systems that are important enough to remain in service but not important enough to attract significant security scrutiny.

Examples often include:

  • Reporting platforms
  • Business intelligence systems
  • Departmental applications
  • Legacy management portals
  • Self-hosted open-source tooling
  • Internal workflow systems

These platforms are frequently viewed as operational rather than security-sensitive.

That assumption is often incorrect.

A reporting platform may have access to:

  • Production databases
  • Financial information
  • Customer datasets
  • Identity services
  • Administrative credentials
  • Sensitive internal business information

From an attacker's perspective, the label attached to the asset is largely irrelevant.

What matters is whether the system provides access, privileges or information of value.

Visibility Is Usually Lower Than Expected

One of the recurring themes we see during security assessments is the gap between perceived visibility and actual visibility.

When discussing security monitoring with organisations, stakeholders often assume compromise would be detected quickly.

However, when assessing a specific platform, the reality is frequently less certain.

Questions that routinely expose visibility gaps include:

  • Are audit logs enabled?
  • Are authentication logs retained?
  • Are logs forwarded to a SIEM?
  • Are administrator actions monitored?
  • Are security alerts generated?
  • Are detections tuned to the platform?
  • Has anybody reviewed the logs recently?

In many cases, the answer is inconsistent.

The organisation may have excellent visibility across Microsoft 365, endpoints and network infrastructure while simultaneously having little or no visibility into a business application containing sensitive information.

The result is a dangerous blind spot.

Why Attackers Like These Systems

Security programmes naturally focus on systems perceived as high value.

Attackers often look for systems that receive less attention.

A reporting platform, for example, may be:

  • Internet accessible.
  • Poorly monitored.
  • Infrequently patched.
  • Connected to valuable data.
  • Trusted by other systems.

Importantly, compromise of these platforms may not immediately disrupt business operations.

That means an attacker can potentially maintain access for extended periods without triggering significant operational concern.

In many cases, the objective is not the platform itself.

The objective is what the platform can access.

The Managed SOC Assumption

Another lesson exposed by incidents of this nature is the assumption that security monitoring automatically equals detection.

Many organisations invest heavily in managed Security Operations Centres and understandably derive reassurance from this capability.

However, effective detection depends on three things:

  1. The relevant telemetry is available.
  2. The telemetry is collected.
  3. Detection logic exists for the activity being performed.

If a reporting platform is not integrated into monitoring processes, the SOC cannot meaningfully detect activity occurring within it.

This is not necessarily a failure of the SOC provider.

It is usually a visibility and onboarding issue.

Security Operations Centres are extremely effective at analysing telemetry they receive.

They are considerably less effective at analysing telemetry that does not exist.

During security reviews we commonly find systems that:

  • Are absent from onboarding documentation.
  • Do not forward logs centrally.
  • Have never undergone threat modelling.
  • Are not represented in use-case development.
  • Have no platform-specific detections.

The consequence is straightforward:

If a compromise occurred, detection capability may be significantly lower than security leaders expect.

The Growing Challenge

The problem is becoming more pronounced as technology estates expand.

Organisations continue to introduce:

  • SaaS services.
  • Low-code platforms.
  • Cloud services.
  • Open-source applications.
  • Departmental tools.
  • Self-hosted business systems.

Each introduces additional trust relationships and attack paths.

Few organisations increase monitoring coverage at the same rate that they increase technology adoption.

As a result, the number of systems operating outside effective security visibility continues to grow.

The Question Security Leaders Should Be Asking

The most important lesson from the Metabase vulnerability is not that SQL injection remains possible.

Nor is it that attackers continue to find creative technical attack paths.

The more important question is:

Which systems in our environment would not generate meaningful security alerts if they were compromised today?

That question is often more valuable than asking which systems are most critical.

Because attackers rarely think in terms of business-critical and non-business-critical systems.

They think in terms of:

  • Accessible systems.
  • Vulnerable systems.
  • Trusted systems.
  • Poorly monitored systems.

In our experience, the greatest security risks are often found at the point where those four characteristics overlap.

And that overlap frequently exists in systems that organisations consider too unimportant to worry about.


About the Author

Tim Holman is CEO and Founder of 2-sec.

Having led assessments across public sector, financial services and enterprise environments, Tim has seen first-hand that many successful compromises do not occur because organisations fail to identify critical assets. They occur because organisations underestimate the importance of everything else.

His work focuses on identifying the blind spots that exist between vulnerability management, security monitoring, architecture and operational reality, helping organisations understand how attackers actually move through modern environments rather than how defenders expect them to.

Scroll to Top