Among the measures that would have changed the outcome of the period's incidents, one recurs and is almost never done: being able to list which integrations are active and what each one reaches.
The absence of that list has a simple explanation. Integrations get added by business unit decision on usefulness grounds, and removed practically never, because removing requires knowing who still depends on them.
The accumulation creates an uncomfortable situation: the company granted access to dozens of services over years, and nobody can say offhand which remain active or what permissions each holds.
Reversing that is tedious work requiring no tooling: open the connected applications list in each main system, remove what nobody uses, reduce the scope of what remains, and note who owns each one.
A morning resolves most of it, and the result shows up precisely when a connected supplier is compromised, which was the most common entry path in the documented incidents.
