None shall pass!
In Monty Python and the Holy Grail the Black Knight loses both arms and both legs and calls it a flesh wound. Plenty of real breach statements follow the same script: Medibank, LastPass and Okta each opened with a scratch and revised it upward over the following weeks and months. The fix is boring: log every read at the data, so the first number you announce is closer to the last one.
Me, on the door of the data. Wrong century of helmet, I know. Both arms still attached, so this is early in the scene.
Too many breach statements are the Black Knight scene with a press release attached. If you can’t say what was read, that is the script you will end up reading from.
What happens in the Black Knight scene?
King Arthur cuts off all four of the Black Knight’s limbs, and the knight calls it a scratch, then a flesh wound, then a draw.
In Monty Python and the Holy Grail (1975), Arthur (Graham Chapman) meets the Black Knight (John Cleese) guarding a small bridge over a stream in a forest. Arthur offers him a seat at the Round Table. The knight says nothing until Arthur tries to cross, then delivers the line every security team secretly wants on a T-shirt: “None shall pass.”
Arthur takes off the left arm. “’Tis but a scratch.” Then the right. “Just a flesh wound.” (Not “it’s just a flesh wound”. Everyone adds the “it’s”. The script doesn’t.)
Then a leg (“I’m invincible!” and, in the third person, “The Black Knight always triumphs!”), then the other leg, at which point the Black Knight offers: “All right, we’ll call it a draw.”
Cleese told Wired in 2015 that the idea came from a story he heard in English class about an ancient wrestler who won his bout and died doing it, with the moral “If you never give up, you can’t possibly lose.” It would make a decent motto for an incident comms team.
Is the Black Knight a good security model?
As a perimeter, he’s actually quite good. He dispatches the Green Knight in the opening seconds with a sword through the eye slit, which is a pen test finding if ever I saw one.
The problem is that he is the whole model. All the security sits in one bloke at one crossing, and once he’s in pieces the bridge is open to anyone, including a man banging two coconuts together. Nothing on the far side asks who you are. (I made the serious version of that argument earlier this week, about AI agents walking around a refusal. This is the version with coconuts.)
What does “’tis but a scratch” look like in a real breach?
It looks like a sequence of press releases, each one missing another limb. Three real ones, quoted straight, because they don’t need my help:
| Company | ’Tis but a scratch (first statement) | Second arm (revised) | No limbs left (final count) |
|---|---|---|---|
| Medibank, 2022 | 13 Oct: “no evidence that any sensitive data, including customer data, has been accessed” | 25 Oct: the criminal had accessed all its private health insurance customers’ personal data | 7 Nov: about 9.7 million current and former customers |
| LastPass, 2022 | 25 Aug: “no evidence that this incident involved any access to customer data or encrypted password vaults” | 30 Nov: access to “certain elements of our customers’ information” | 22 Dec: a copy of “a backup of customer vault data” |
| Okta, 2023 | 20 Oct: files uploaded by “certain Okta customers” | 3 Nov: “134 Okta customers, or less than 1%” | 29 Nov: names and emails of “all Okta customer support system users” |
Every number went one way: up.
As far as anyone has shown, none of them was lying, which is the interesting part. The knight can see his arm on the ground. A company usually can’t, not until someone has worked out from the logs what was actually read. (LastPass’s CEO, Karim Toubba, later said “I accept the criticism and take full responsibility”, which is more than the Black Knight ever managed.)
Isn’t “no evidence” technically true?
Usually, yes, on the day it is said, and that is exactly the problem.
“No evidence” is a statement about the investigation, not about the data. It means “we haven’t found it yet”, and customers hear “it didn’t happen”. The gap between those two readings is where the limbs come off.
The law has quietly made room for this. GDPR Article 33 asks for notice within 72 hours where feasible, then adds that “the information may be provided in phases”. Australia’s Notifiable Data Breaches scheme gives 30 calendar days to assess a suspected breach. Between them, Brussels and Canberra have more or less legislated the Black Knight.
How do you count the limbs on day one?
Log every read at the data, so “what did they take?” is a query, not a six-week dig. Boring old audit logs, kept where the data lives.
My read: the scratch-to-draw arc happens when the only record of who read what lives out at the bridge, and the data itself keeps no diary. I suspect most of the weeks between the first statement and the last go on rebuilding reads from logs that were never built to answer that question.
Okta’s own root-cause write-up is candid about it: “For a period of 14 days, while actively investigating, Okta did not identify suspicious downloads in our logs.” The attacker had pulled files through the Files tab, which wrote “an entirely different log event” to the one Okta’s investigators were searching for. (So the logs were there. The read just showed up as a different kind of event.)
That’s why every access decision, by a person or an AI agent, is logged in the governed AI data platform I originated, now carried forward at Sovrata, the AI data-governance venture out of Senetas. Rob Linton (yes, me, in the third person, which the Black Knight would respect) made the call to keep that tamper-evident trail at the data, where you can hand it to an auditor. It won’t stop the arm coming off. It does mean you can count the limbs that came off at the data.
The honest caveat
Logs at the data only count the reads that go through the data, so one of my three exhibits is partly an argument against me. LastPass’s vault data left as a copied backup from cloud storage, and I suspect a log on the vault service’s own read path would never have seen it. Anything that leaves by a side door (a backup, a snapshot, anything outside the blast radius you thought you had) still needs its own guard.
Net: keep the knight on the bridge by all means. Just make sure the castle keeps its own diary, so the first number you give the press comes out of a query. Leave “’tis but a scratch” to John Cleese, who at least knew it was a joke.
Sources
- Black Knight (Monty Python) · Wikipedia
- Monty Python and the Holy Grail, Scene 4 (transcript) · Monty Python scripts archive
- The inspiration behind the Black Knight's famous line · No Film School (citing Wired, 2015)
- Medibank's data breaches, as they happened · Cyber Daily · 2022-10
- Medibank confirms hacker accessed all customers' personal data · ABC News · 2022-10-25
- Medibank refuses to pay ransom · ABC News · 2022-11-07
- Notice of recent security incident · LastPass · 2022-08-25
- LastPass cyberattack timeline · Cybersecurity Dive · 2023-03
- Tracking unauthorized access to Okta's support system · Okta · 2023-10-20
- Unauthorized access to Okta's support case management system: root cause and remediation · Okta · 2023-11-03
- October customer support security incident: recommended actions · Okta · 2023-11-29
- Okta breach affected all customer support users · Krebs on Security · 2023-11-29
- Art. 33 GDPR: Notification of a personal data breach to the supervisory authority · GDPR (EU) 2016/679
- Part 4: Notifiable Data Breach (NDB) Scheme · Office of the Australian Information Commissioner
