[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$f0lVQpdUh_bdNx4ChnW3YiRzoVwu_EYosC37_MW8-XVc":3},{"lesson":4},{"id":5,"slug":6,"article_id":7,"title":8,"body":9,"prevention":10,"framework_refs":11,"status":23,"created_at":24,"published_at":25,"article":26,"tags":30,"podcasts":49},"f5d18058-3655-4fee-a0ec-1f5c0ff1d9b7","paragon-spyware-lacks-oversight-controls-despite-abuse-allegations","f11c7901-150b-4f39-9c93-022247cbaa80","Paragon Spyware Lacks Oversight Controls Despite Abuse Allegations","Paragon Solutions admitted it has no technical capability to monitor how customers use its Graphite spyware, nor any remote kill switch to halt misuse — a fundamental failure of product accountability and vendor oversight. This means that once the software is deployed, the vendor has zero visibility or control over whether it is used against journalists, activists, or other protected individuals. The decision to cancel contracts was driven by reputational risk rather than a genuine investigation, revealing an absence of meaningful incident response processes. This case illustrates how surveillance technology vendors can create systemic human rights and security risks when they lack built-in governance, auditability, and enforceable use policies. Organizations and governments procuring such tools must demand verifiable accountability mechanisms, not just contractual promises.","**Immediate actions:**\n- Require all third-party software vendors to demonstrate auditable logging and usage monitoring capabilities before procurement.\n- Establish contractual clauses mandating remote disable ('kill switch') functionality for any deployed offensive or dual-use security tools.\n\n**Vendor & Supply Chain due diligence:**\n- Conduct thorough human rights impact assessments when evaluating surveillance or offensive security tool vendors.\n- Audit vendor acquisition and merger events (e.g., Paragon + REDLattice) to reassess risk posture and inherited liabilities in existing contracts.\n- Require vendors to provide transparency reports and incident disclosure obligations as a condition of contract renewal.\n\n**Long-term governance improvements:**\n- Implement an internal ethics and oversight committee to review procurement of dual-use or surveillance technologies.\n- Establish a formal incident response process for vendor-linked abuse allegations that triggers investigation — not just reputational risk review.\n- Align procurement policies with international frameworks (e.g., Wassenaar Arrangement, UN Guiding Principles on Business and Human Rights) to ensure legal and ethical compliance.",[12,13,14,15,16,17,18,19,20,21,22],"CIS Control 15: Service Provider Management","CIS Control 8: Audit Log Management","NIST SP 800-161: Supply Chain Risk Management","NIST IR-4: Incident Handling","NIST AU-2: Audit Events","NIST AU-12: Audit Record Generation","GDPR Article 28: Processor Obligations","GDPR Article 5(2): Accountability Principle","ISO\u002FIEC 27036: Supplier Relationships","UN Guiding Principles on Business and Human Rights (UNGPs) Pillar 2","Wassenaar Arrangement on Export Controls for Dual-Use Goods","published","2026-10-01T10:20:48.503869+00:00","2026-10-01T10:20:48.429+00:00",{"id":7,"url":27,"slug":28,"title":29},"https:\u002F\u002Fwww.wired.com\u002Fstory\u002Fthe-secrets-of-the-us-spyware-king\u002F","the-secrets-of-the-us-spyware-king-ff20b7","The Secrets of the US Spyware King",[31,37,43],{"id":32,"name":33,"slug":34,"description":35,"color":36},"1732a005-556e-411c-a9db-5edec3058571","Logging & Monitoring","logging-monitoring","Missing logs, no alerting, blind spots","#a855f7",{"id":38,"name":39,"slug":40,"description":41,"color":42},"c0dcc566-3654-4d70-8ede-262a198e732f","Regulatory Compliance","regulatory-compliance","GDPR, NIS2, DORA, sector-specific violations","#ec4899",{"id":44,"name":45,"slug":46,"description":47,"color":48},"f0c2a0af-58aa-4128-87c9-6acd30f2dc48","Supply Chain","supply-chain","Third-party risk, compromised dependencies","#8b5cf6",[]]