The bottom line: Approved tracking code can lead to uncontrolled data access through fourth-party layers and should be minimized through strict inventory management and controls.
Approved marketing tags can silently load fourth-party code and thereby grant access to forms, customer data and checkout pages. A webinar shows how these approval gaps arise and how security teams can close them.
The so-called Approval Gap describes a security risk in modern advertising infrastructures: a single tracking tag approved by marketing can subsequently load code modules unknown to security teams. These fourth-party scripts thereby gain access to sensitive areas such as form fields, customer profiles and payment pages.
For CISOs and security executives, this pattern is particularly relevant because it typically arises between organizational silos: marketing teams approve tags based on business requirements without checking the full dependency chain. Security teams often discover these hidden dependencies only during penetration tests or audits – too late.
The webinar provides concrete methods to close such gaps: inventory management for all tags and external scripts, technical verification of dependency structures, and governance processes between marketing and security. The focus is on practical steps before regulators, auditors or attackers discover vulnerabilities – relevant for NIS2 Directive compliance and other regulatory requirements for information security in the financial services and e-commerce sectors.
Source: thehackernews.com · Published 15 July 2026
Lumi AI News — AI-assisted curation pursuant to Article 50 EU AI Act. Paraphrasing and classification by Lumi News Pipeline v1.7.3.