Emergency situation meant they left immediately, and potentially left the whole government vulnerable to future attacks in the process
Emergency situation meant they left immediately, and potentially left the whole government vulnerable to future attacks in the process
The report I saw before was one of her staffer's computers was unlocked. Was there a report about her personal computer? (Does she even use one..?)
It's slightly surprising there's not an emergency evacuation procedure for people who work in the building that involves locking all devices that remain in the building via a hot-key or hot-corner. Come to think of it, I wonder if a screen lock command is something that could be pushed from a Windows domain controller...and if so, why wasn't that used?
Relying on humans locking their PC in event of a terrorist attack isn't a IT-Security concept.
Security consists of a threat model and many layers of security measures. Many many outer layers have failed here. I wouldn't blame an individual nor a department here. It's one of those events that probably wasn't in the scope. Additionally, roles/security clearance levels etc. still work regardless of the account beeing open to anyone.
Things like Smartcards, Yubikeys, auto-lockscreen could have failed the same way. Maybe a GPO failed, or a windows update broke the auto-lock.... that's why all these many layers exist.
Even if it's not a common feature, it's not like I'd be surprised to learn these computers are imaged with some custom software, one of which could be a lock on command (or loss of connectivity to home).
I have no idea how important these machines were, of course.