CenterPoint Energy confirmed a breach after a hacker published what they claim are 7.5 million customer records. Confirmation followed the dump. If your cybersecurity program still treats a sampled audit as proof that threat-protection is alive, you are watching the same sequence from the cheap seats.
Texas customers lost billing identity, service locations, and whatever else sat in the same extract. Once a utility dump is public, incident response is theater you perform for people who already have the files. The attacker set the timeline. You inherited it.

You already know the feeling. The firewall report looks calm. Brute-force alarms fired on some forgotten VPN last month and someone ticketed them. The quarterly assessment called access reviews substantially complete. The question that mattered on leak day is narrower. Could anyone prove, that morning, that bulk customer export still required a living control?
Late Proof Is How Customer Files Leave Quietly
Hack-and-leak puts your cyber security program on a clock you do not own. CenterPoint’s confirmation is useful and late. The records moved first. Legal, comms, and the SOC arrived second. That lag is where copycat claims and regulator letters get their leverage.
Defense in depth is supposed to catch an extract in motion. In practice, a lot of that depth sits at the edge: packet filters, MFA banners, EDR on laptops. The system that can pull 7.5 million rows sits behind all of that, often with a service account that has not been reviewed since the last ERP cutover. Threat detection that only watches inbound exploits will miss a quiet copy over an allowed path.
Any shop that bills, meters, ships, or insures has a file that looks like this. The blast radius is the customer table plus every replica you made for reporting. Those replicas are where a “read only” account becomes a full export. Nightly dumps to a vendor SFTP share. A BI warehouse that still trusts last year’s subnet. A cloud snapshot that nobody listed in the system of record.
SecurityWeek’s control-monitoring argument lands here for a reason. A point-in-time sample can be accurate and still miss the job that ran in August. You sampled twenty access reviews in March. The export never appeared in the sample. The control you show an auditor is a policy. The control the attacker met is a database role that still worked.
Point-in-time audits and sampled assessments offer only snapshots. Continuous monitoring is how you show a control still worked this morning, on this host, against this export path.
Operators learn this the expensive way because customer platforms get treated as back office. They are production. They hold the only copy of identity the public will recognize. If your evidence of a working deny is a slide from last quarter, the dump site is already the better logger.
672 CVEs Will Not Become Cybersecurity Evidence
Oracle’s September 2026 Critical Security Patch Update is the other pile on your desk this week. Tenable counts 672 unique CVEs across 673 updates, with 104 rated critical. Oracle E-Business Suite took 159 patches. Fusion Middleware took 153, including 78 issues reachable over the network without authentication. Oracle Utilities Applications picked up two patches, one of them remotely exploitable without a login.

If you run those stacks, you patch. You do it with a queue, a change window, and a regression test someone will try to skip. Security hardening starts with the install. Evidence is the follow-up test: the old call dies, the deny lands in the log your incident response runbook actually reads, and the reporting replica still refuses a desktop VPN session.
Monthly CSPUs, which Oracle started in May 2026, will keep arriving between the big quarterly dumps. High-severity items are 503 of this month’s 673 updates. Critical is 104. The matrix is a work queue. The failure mode is treating the bulletin as a control attestation. Two weeks in CAB with no artifact showing that customer-data threat detection fired on a real bulk read in the last 30 days leaves you in snapshot land with a larger ticket pile.
Patch the internet-facing bits first. Unauthenticated remote bugs in middleware. Anything on a shared VIP. Anything that shares a trust domain with billing. Then keep the test artifact with the change record. A screenshot from last quarter puts you back where CenterPoint’s customers already are: hoping the next extract needs a control you last proved on paper.
If You Cannot Show It Working Today, Cut the Path
You need evidence you can pull on a Tuesday. Immediate work is ugly and finite. Ongoing work is a habit. Both beat another green dashboard.
Start with the systems that can emit a customer file. Name the owners, the replicas, and the accounts that can read them. If that inventory takes more than a day, you already found the incident.
- Today: ticket every bulk-export path you can name, including reporting databases, vendor SFTP drops, and “temporary” data lakes. Disable the unused ones before lunch. Rotate the service accounts that can still SELECT the customer table. Snapshot IAM and database audit logs before anyone “cleans up.”
- Today: restore identity and billing from backups you actually restore. Walk the incident response steps for records already posted, including customer-notice drafts and regulator contacts you can reach after hours.
- Every week: keep a pass/fail that authorization still denies bad reads and that volume anomalies still alert. Store the result. A pass is export telemetry that fired, plus a deny you can show, on a date a lawyer could read.
- Every patch window: re-test reachability after ERP and middleware updates so security hardening does not rot between CSPUs. Customer-data hosts should refuse general VPN pools. Break-glass should live on a separate control plane.
Keep the firewall. Keep the brute-force lockouts. Treat them as table stakes. The control that would have caught a 7.5 million-row extract lives on the data path, in authorization, in volume alerts, and in a restore you have actually done.
The next leak will not wait for your quarterly sample. Pull the proof now, while the records in the news still belong to someone else.
Sources
- Texas Utility CenterPoint Energy Confirms Breach After Hacker Leaks Data
- “We Think the Security Control Is Working” Is No Longer Good Enough
- Oracle September 2026 Critical Security Patch Update addresses 672 CVEs
Take Control of Your Server Security
Don't let brute-force attacks slow you down. Try IPBan Pro risk-free for 30 days.
Secure. Automated. Lightweight.
Take Control of Your Server Security
Don't let brute-force attacks slow you down. Try IPBan Pro risk-free for 30 days.
Secure. Automated. Lightweight.
