Roche published an advisory on FortiBleed, the exposure of credentials and configuration data from roughly 75,000 internet-facing Fortinet FortiGate firewalls worldwide. Roche assessed its environment and products and reported no evidence of impact.

The value is in the publishing, not the outcome. A manufacturer documenting that it checked, and found nothing, is what a customer wants to see when a widely-used piece of infrastructure gets breached. F5 in October, Fortinet now: the vendors whose gear sits in front of everyone become single points of failure for everyone downstream. When a foundational vendor is compromised, have the answer to did-you-check ready and published before your customers ask.