Executive summary for the Board — TSR-INC-2025-031

Incident Response
Governance
Compliance

Executive summary for the Board on incident TSR-INC-2025-031, the late-February 2025 breach in which a long-lived AWS access key exposed through a misconfigured public repository was used to reach ~14,000 tenant records across an unsegmented path. First-year impact is estimated at ~$1.8M; 23 tenants did not renew.

Subject: Board summary — incident TSR-INC-2025-031 and response


To: Board of Directors From: Isabella Ferreira, Chief Information Security Officer Date: 10 March 2025

Overview

In late February 2025 Tessera detected anomalous data egress from the multi-tenant platform. Investigation established that a long-lived AWS access key had been exposed through a source-code repository misconfigured as public, and that the key had been used to read tenant data across a path between the management plane and the tenant data store that was not fully segregated. Approximately 14,000 tenant records were exposed over an estimated five-day window; containment took a further 48 hours. First-year impact is estimated at ~$1.8M, and 23 tenants did not renew as a consequence.

Key facts

Status

Next steps

Ask of the Board

The remediation is funded within the current security programme. I am seeking the Board’s endorsement of the certification-readiness programme as the accountability structure for closing these actions, and confirmation that the Chief Information Security Officer has standing authority to enforce key-rotation and segmentation changes without further case-by-case approval.

Isabella Ferreira Chief Information Security Officer Tessera