Cracked network cable leaking dark fluid onto the white floor of a server room

An outdated integration is a data breach waiting to happen

Your CRM, your webshop, your accounting package and your customer portal are linked by integrations that were set up with care at some point and never looked at again. They do their work quietly, year after year. That silence is precisely the risk: a connection that was secure five years ago can be a weak spot today that nobody is watching.

If things go wrong there, a data breach through such an integration is no minor technical incident. It brings a duty to report, possibly a fine, and almost certainly a difficult conversation with customers whose data has been exposed. Reason enough to have the consequences clear before it gets that far.

How an integration ages without anyone noticing

An integration leans on the systems at both ends, and those systems do not stand still. They receive updates, new versions and stricter security requirements; the integration itself rarely grows along with them. The result is a connection that still works technically but runs on outdated protocols, a library full of known vulnerabilities or a login method that has long since stopped counting as secure. For an attacker, that is attractive: why force the front door when a door round the back stands open with nobody paying attention?

Add to that the fact that old integrations often carry broader permissions than they need. An API key that was once allowed access to everything for convenience gives an attacker that same freedom after interception. And it is precisely valuable data that flows across these connections: customer records, payment details, sometimes personnel files.

The consequences reach further than a fine

The best-known risk is legal. The GDPR, in force since 2018, carries fines for serious violations of up to 20 million euros or 4 per cent of worldwide annual turnover, whichever is higher. A data breach must also be reported to the Dutch Data Protection Authority (Autoriteit Persoonsgegevens) within 72 hours of discovery, and those affected can claim compensation. Negligence weighs especially heavily: if your organisation had known about outdated integrations for some time without acting, the regulator will hold that against you.

The greatest damage often sits elsewhere. Customers and partners trust you with their data; a breach puts that trust under pressure, and that carries on for years. Add the direct costs of investigation, recovery and halted processes, and the contrast with the price of timely maintenance becomes painful.

Why a breach like this stays invisible for so long

An integration that functions attracts no attention. As long as the orders come in and the invoices add up, nobody looks at what else travels across that connection. Without logging and monitoring on the integration itself, nothing raises the alarm when someone is reading along or siphoning off data. A breach can stay open for months this way, and the longer that lasts, the more data leaks away and the more complex the aftermath becomes, technically and legally.

Five signs an integration deserves a review

You do not need to be an engineer to point out the risky integrations in your own organisation. Watch for these signs:

  • The vendor has marked the API version you use as deprecated.
  • The connection uses old protocols such as TLS 1.0 or 1.1 for encryption.
  • Nobody can tell you exactly what runs across the integration; logging is missing.
  • The documentation has gone missing and the original developer is out of the picture.
  • One of the connected systems had a major upgrade without the integration being adjusted.

If you recognise more than one of these points, a security review is not excessive caution but overdue maintenance.

From silent connection to managed infrastructure

Prevention starts with treating integrations as a full part of your infrastructure: taking stock of which connections are running, recording what data flows across them, applying modern authentication and encryption, and setting up monitoring that flags unusual behaviour. Most of that is a one-off effort; after that, the maintenance is limited and predictable.

Unsure about the state of your own integrations? Our engineers examine existing API integrations and renew them where needed, with security, documentation and monitoring as a standard part of every data integration. In a first conversation we work out together where the greatest risk sits, before anything gets built.

Let’s talk

Every good solution starts with a conversation.

Have a question about something you read here? Get in touch - we’re happy to talk it through.