The data protection authority was breached, and it was probably compliant
Event dated 10 February 2026 · Published 2 September 2026 · 3 sources
There is an easy version of this story and it is not worth writing. The data protection authority had a data breach; the irony writes itself and teaches nothing.
The useful version starts from the likelihood that the authority was compliant. A regulator that enforces obligations knows what they are, files what it should, and has the documentation. It was reached anyway, by a flaw with no patch available at the time, in a product it had every reason to run.
Two different properties
Compliance asks whether an organisation can demonstrate a set of measures. Security asks whether an adversary can achieve their objective. The two overlap and are not the same, and the gap between them is exactly the class of event where the answer to the first question is yes and the answer to the second is also yes.
A zero-day sits squarely in that gap. No framework requires patching a flaw nobody knows about, so no audit finds the exposure and no evidence file records it. The organisation is fully compliant right up to the moment it is not secure, and afterwards, and the documentation is unchanged throughout.
Why device management is the wrong thing to lose
Mobile device management is unusual in the reach it holds by design. It enrols devices, pushes configuration, installs and removes software, and can wipe a handset. Those powers are the product. There is no version of it that holds less and still works.
So a compromise of the manager is not a compromise of a server that happens to be important. It is standing authority over every phone in the organisation, including devices that are somewhere else, belonging to people who will not be told, running the authentication applications that protect everything else.
What follows for anybody running one
The first question is exposure rather than version. A management console reachable from the public internet is reachable by whoever finds the next flaw in it, and that reachability is a decision an organisation controls entirely, unlike the existence of the flaw.
The second is what the console can do without a human present. A platform that can push an application to every device on a schedule is a platform that can push one at three in the morning to somebody who is not you. Requiring a person for the small number of genuinely fleet-wide actions costs very little and removes the worst outcome from the list.
Neither of those appears in a compliance questionnaire, which is the point the February disclosures make more sharply than any argument: passing the audit and being difficult to attack are related, and they are not the same work.