← All posts

The DHS Breach That Should Terrify Every Board: When “Unclassified” Doesn’t Mean “Unimportant”

On July 1, the Department of Homeland Security confirmed what cybersecurity professionals had feared for weeks: unknown attackers breached the Homeland Security Information Network, the federal government's primary platform for sharing sensitive operational intelligence across every level of American government and its private-sector partners.

The timing could not have been worse. The breach occurred between late May and early June — squarely in the middle of security planning for FIFA World Cup matches being hosted across 16 cities in the United States, Canada, and Mexico. For weeks, attackers had potential access to the coordination backbone that federal, state, and local agencies rely on for event security, emergency response, and threat intelligence sharing.

Senator Mark Warner, vice chair of the Senate Intelligence Committee, put it bluntly: “The information in HSIN, while not classified, is highly sensitive, and its exposure risks national security.”

That single sentence captures a lesson every corporate board in America needs to internalize.

The “Sensitive But Unclassified” Trap

Here is the detail that should keep executives awake at night: HSIN carries a “Sensitive But Unclassified” designation. That classification means mishandling carries administrative consequences rather than criminal penalties. And because it is not formally classified, HSIN receives less rigorous security engineering than systems holding data of comparable operational sensitivity.

This is the same mistake I see in boardrooms every quarter. Organizations classify data by regulatory category — PII here, PHI there, financial records in another bucket — and then allocate security resources based on those labels. The data that falls into the gaps between formal categories often holds the greatest operational value to an attacker.

Think about your own organization. Your classified equivalents — trade secrets, source code, customer financial data — probably sit behind your strongest controls. But what about the operational coordination data? The project plans that reveal your strategic direction? The vendor communications that map your entire supply chain? The internal Slack channels where your security team discusses active investigations?

In Cyber Risk Is Business Risk, I call this the first of the Three Questions every board must be able to answer: What do we have? The compliance framework tells you what you're required to protect. An adversary decides what it actually wants to take. The HSIN breach proves those two answers are rarely the same size.

A SharePoint Vulnerability With Perfect Timing

The technical vector makes this story even more instructive for the private sector. CISA added CVE-2026-45659 — a deserialization vulnerability in on-premises Microsoft SharePoint Server — to its Known Exploited Vulnerabilities catalog on July 1, the same day DHS confirmed the HSIN breach. The vulnerability carries a CVSS score of 8.8 and requires only Site Member permissions, the lowest tier of SharePoint access, to exploit.

DHS has not confirmed that this specific CVE was the entry point. But the coincidence is instructive: Microsoft had issued patches for affected SharePoint versions back in May. If the HSIN environment was running unpatched SharePoint — and the breach window of late May to early June lines up uncomfortably well — then this is a patch management failure of the most basic kind.

Every organization running on-premises SharePoint should be asking a pointed question right now: are we patched? SharePoint Server Subscription Edition, SharePoint Server 2019, and SharePoint Enterprise Server 2016 were all affected. CISA's mandate under BOD 26-04 gives federal agencies three days to patch after a KEV listing. What is your organization's equivalent commitment?

What to Ask Your CISO This Week

The HSIN breach is not just a government problem. It is a case study in the gap between compliance posture and actual security. Here is what your board should be asking:

“Do we have a complete inventory of data that would be operationally valuable to an attacker, beyond what compliance requires us to protect?” Most organizations can account for their regulated data. Few have mapped their operational intelligence — the coordination data, the strategic plans, the vendor relationships — with the same rigor.

“What is our patch cycle for collaboration platforms like SharePoint, Teams, and Confluence?” These platforms are where your people do their actual work. They hold meeting notes, project timelines, security discussions, and strategic decisions. If your patch cycle for these systems is measured in months rather than days, you have an HSIN-sized gap in your own environment.

“If our ‘sensitive but not regulated’ data were exposed tomorrow, what would the business impact be?” The HSIN breach matters not because classified secrets leaked — DHS says they did not — but because operational coordination data for a major international event may have been compromised. Your equivalent might be a product launch timeline, an M&A communication thread, or a security incident response plan.

The Accountability Dimension

Senator Warner demanded that DHS and DOJ investigate who breached HSIN, what the attackers accessed, and ensure all partners receive timely notification. The House Homeland Security Committee has sought its own briefing. This is exactly the kind of oversight pressure that I argue in Cyber Risk Is Business Risk should be standard at the board level — not just after a breach, but before one.

The personal liability picture for directors keeps getting sharper. When a breach reveals that data of obvious operational value was protected with controls calibrated to a lesser classification, the “we followed the compliance framework” defense grows thinner by the year. The HSIN breach is a federal case study, but the pattern — valuable data under-protected because its label did not match its actual sensitivity — repeats in every sector.

The Bottom Line

The DHS breach is a warning that resonates far beyond government. The attackers did not need to penetrate classified systems to compromise national security coordination. They found the gap between what was formally protected and what actually mattered.

Every organization has that gap. The boards that close it will be the ones asking the Three Questions before their own HSIN moment arrives — not after.