Incidents
Each of these failed differently, which is the reason to read all three. One had a gate that did not apply, one had no gate at all, and one had a rule the actor agreed to and then broke.
Every entry links its sources and says whether the account is first-party or reported. Where the company and the reporting disagree, both are given.
The gate existed and did not apply. This is not a story about missing controls but about a control whose condition was the identity of the actor.
What was missingNothing was compromised and no credential was stolen. This is the case that defeats identity and endpoint controls entirely, because every one of them was working.
What was missingThe rule was stated and the actor agreed to it. This is the case that shows why prompt-level guidance and enforcement are not the same category of thing.
What was missingNone of these say Decionis would have prevented the incident. We do not know that, the people involved have far more context than we do, and it would be an unfalsifiable claim attached to somebody’s worst week. What each page argues is the shape of the control that was absent — a claim you can check against the sources and disagree with. Every organisation here shipped a fix quickly, and several published more detail than they needed to.