Nemstar Insights

When Your Security Platform Becomes the Attack

By Sean Hanna, Founder & Director of Nemstar

March 12, 2026

 

A lesson from the Stryker cyber incident. 

Yesterday, reports emerged that Stryker was dealing with a major cyber incident affecting systems across its Microsoft environment.

Devices were reportedly wiped.
Systems taken offline.
Staff unable to access corporate machines.

Cyber incidents causing disruption are unfortunately nothing new.

But one detail being discussed in early reporting makes this case particularly interesting.

The possibility that the attacker may have used the organisation’s own device management and security tooling to trigger the damage.

If that proves accurate, this is not simply a malware story.

It’s a control story.

The management layer is where the real power sits

Modern organisations rely on powerful cloud management platforms to control their device estates.

Systems like Microsoft Intune allow security teams to:

Deploy updates.
Enforce security policies.
Control access to corporate resources.
And if necessary wipe devices remotely.

Those capabilities are essential for managing large environments securely.

But they introduce a critical dependency.

Control of the platform itself.

If an attacker gains administrative access to that management layer, they inherit the same authority as the security team.

At that point they no longer need to hack individual machines.

They can simply use the management platform.

The system designed to protect the environment becomes the mechanism used to damage it.

The cloud security misunderstanding

Many organisations adopt Microsoft cloud platforms because they believe the cloud is inherently safer.

In many respects, it is.

The infrastructure and platform security are extremely strong.

But cloud security has always followed a simple principle.

Microsoft secures the platform.

You secure control of the platform.

Identity.
Privileges.
Administrative access.

If those controls are compromised, the attacker effectively inherits the same power as your administrators.

At that point technology alone is not the protection.

Governance becomes the deciding factor.

The playbook gap

Incidents like this often expose another weakness.

Most organisations design incident response playbooks around the threats they expect.

Ransomware.
Malware outbreaks.
Phishing campaigns.

All sensible scenarios.

But how many organisations have a response plan for this situation:

An attacker using your own cloud management platform to issue destructive commands across your entire device estate.

In my experience, very few.

Because this is not primarily a technology failure.

It is a control and governance failure.

The questions leadership should be asking

If your organisation relies heavily on cloud platforms, this incident should trigger some simple but important questions.

Who controls the management layer of our environment?

How tightly protected is privileged administrative access?

What monitoring exists around high-impact administrative actions?

And if those actions were triggered maliciously…

how quickly would we know?

Because the most powerful systems in your environment are not the endpoints.

They are the systems that control them.

A final thought

After more than two decades working in cyber security, one lesson remains constant.

There is a big difference between knowing how technology works and understanding how it can be abused.

When leadership truly understands that difference, the right decisions about governance, control and resilience usually follow.

Incidents like the one affecting Stryker remind us of something simple.

Security tools are powerful.

But the real security question is not the tool.

It is who controls it.

Coming soon


About the Author:

Sean Hanna

Founder & Director

Sean Hanna founded Nemstar in 2009, leveraging 20+ years of cybersecurity expertise to deliver business-focused technical training. As EC Council’s Global Security Trainer of the Year, he has trained thousands globally, including at Microsoft, GCHQ, and the U.S. Navy. Sean led Microsoft Exchange 2000’s technical training launch and helps organizations strengthen their cybersecurity defenses.

Explore Other Courses

Want to find out more about CRISC?