Skip to content
The Cyber Security Place

The data protection authority was breached, and it was probably compliant

Event dated 10 February 2026 · Published 2 September 2026 · 3 sources

Two zero-day flaws in Ivanti Endpoint Manager Mobile, tracked as CVE-2026-1281 and CVE-2026-134, were reported under active exploitation on 10 February 2026. Among the organisations confirming they were reached were the European Commission and the Netherlands' data protection authority and judicial council. The product is a mobile device manager: the system that enrols, configures and can wipe every corporate phone, which makes it a single point of control over an entire fleet rather than one more server. The regulator that enforces breach obligations was almost certainly meeting them.

There is an easy version of this story and it is not worth writing. The data protection authority had a data breach; the irony writes itself and teaches nothing.

The useful version starts from the likelihood that the authority was compliant. A regulator that enforces obligations knows what they are, files what it should, and has the documentation. It was reached anyway, by a flaw with no patch available at the time, in a product it had every reason to run.

Two different properties

Compliance asks whether an organisation can demonstrate a set of measures. Security asks whether an adversary can achieve their objective. The two overlap and are not the same, and the gap between them is exactly the class of event where the answer to the first question is yes and the answer to the second is also yes.

A zero-day sits squarely in that gap. No framework requires patching a flaw nobody knows about, so no audit finds the exposure and no evidence file records it. The organisation is fully compliant right up to the moment it is not secure, and afterwards, and the documentation is unchanged throughout.

Why device management is the wrong thing to lose

Mobile device management is unusual in the reach it holds by design. It enrols devices, pushes configuration, installs and removes software, and can wipe a handset. Those powers are the product. There is no version of it that holds less and still works.

So a compromise of the manager is not a compromise of a server that happens to be important. It is standing authority over every phone in the organisation, including devices that are somewhere else, belonging to people who will not be told, running the authentication applications that protect everything else.

What follows for anybody running one

The first question is exposure rather than version. A management console reachable from the public internet is reachable by whoever finds the next flaw in it, and that reachability is a decision an organisation controls entirely, unlike the existence of the flaw.

The second is what the console can do without a human present. A platform that can push an application to every device on a schedule is a platform that can push one at three in the morning to somebody who is not you. Requiring a person for the small number of genuinely fleet-wide actions costs very little and removes the worst outcome from the list.

Neither of those appears in a compliance questionnaire, which is the point the February disclosures make more sharply than any argument: passing the audit and being difficult to attack are related, and they are not the same work.