
How Accenture puts its clients at risk.

Our research first raised alarms back in 2019, when we discovered CNNIOC issued “999-year” digital certificates inside an Accenture Gold Standard flagship corporate laptop during a session attended by Accenture senior leadership and their PKI expert.
These 999 years CNNIC digital certificate with full admin access handed near-permanent administrative access to anyone who possessed the corresponding keys.
Instead of triggering an emergency response, the finding was quietly brushed aside and covered up.
Then within two years, Accenture fell victim to a massive 2021 cyber incident, a flashing red siren for any organisation claiming to be a global authority on digital transformation and security.
But rather than seize the moment to overhaul its questionable security foundations, the company allowed the same systemic weaknesses to persist.
Today TLS/SSL failures, DNSSEC breakage, certificate mismatches, and erratic PKI governance continue to expose Accenture, their clients, governments, partners and employees to unnecessary and avoidable risk.
This wasn’t a one-off mistake: it continues to be exposed.
This is a pattern of negligence, a widespread corporate culture that treats cybersecurity as an accessory instead of the backbone of trust.
And the world’s largest enterprises are left to absorb the consequences and fallout.
Accenture have secured their DNS records and servers for the last 6 years which is great especially when compared to the majority, however, as harsh as it may seem, cyber criminals only require one configuration error, Not Secure subdomain, or unsecured server to get a foothold and launch an attack.
Andy Jenkinson is on LinkedIn
at https://www.linkedin.com/in/andy-jenkinson-96210727/

About this section
From FinTech to RegTech, from "AI" to security, from the terraverse to the metaverse, if there's a technology element, we're interested. But this is not an area for PR. It's an area for considered, structured articles that advance arguments. Think Op-Ed with a purpose.
Opinion pieces or "Op-Eds" are the home-made bombs of the publishing world. So long as they meet editorial standards, are not intentionally offensive with a view to causing hurt or insult and are relevant to our field of endeavour, we will look at submissions.
We like contentious, we like contrarian views. We don't like pretty much any -ism . We recognise that Opinion pieces are one person's view and are not balanced (if they are balanced and reach a reasoned conclusion, they are probably more suited to the Articles section). We do not like empty expressions (reaching out, going forward, circling back etc), acronyms and buzzwords. English, only please.
To submit an Opinion / Technology piece, please complete the Contact form.
