Every large platform gets breached. Not because the people running it are careless — many have security teams larger than my whole client list — but because a system holding the data of millions is worth millions of attempts. Sooner or later one of them works.

I build custom software for a living, so read this with that in mind. But the argument is not mine. It is in the breach notices.

The evidence

Four incidents from the past eighteen months, in software that almost every large organization runs:

WhenSoftwareWhat happenedReach
May 2026Instructure CanvasThe platform was breached, then its login page replaced with a ransom note; Instructure ended up reaching an agreement with the attackersNearly 9,000 schools
June 2026Oracle PeopleSoftA flaw needing no login was exploited for two weeks before Oracle published a fix100+ organizations, 68 % of them universities
August 2025SalesforceStolen tokens of a popular add-on were used to export customer data — 1.5 billion records by the attackers' count760 companies, including Cloudflare, Palo Alto Networks and Zscaler
July 2025Microsoft SharePointA zero-day chain in on-premises servers, exploited by state-backed groupsAbout 400 organizations, including the US nuclear weapons agency

Notice the pattern. In most of these cases the victims did nothing wrong inside their own walls: the flaw was in software they bought or subscribed to, and it was exploited before anyone could fix it. The Salesforce list includes three security companies — with security teams — sitting on the same shared platform as everyone else.

Why big platforms are the target

For an attacker, a popular platform is the best return on investment there is: one codebase to study, and every flaw found pays out across thousands of customers at once. Its documentation is public, its versions are catalogued, its login page looks the same everywhere. Criminal groups, state services and bored teenagers probe that same surface every day.

Your data sits inside that surface next to everybody else's. Whether it leaks is decided by the weakest link in a chain you do not control: the vendor, the vendor's integrations, and every other tenant's password habits.

AI changed the attacker's economics

Until recently a serious intrusion needed serious people: weeks of reconnaissance, custom tooling, someone to sift through what was stolen. Anthropic's September 2026 threat report puts the change bluntly: "sophisticated attacks no longer require sophisticated attackers." Reconnaissance, exploitation, tool development and data processing are now handed to AI models running at machine speed and in parallel. One compromise it documents went from a single stolen developer token to full control of a cloud environment in roughly three hours.

The same report makes a point I will not skip, because it cuts against the lazy version of my argument: when attacks cost almost nothing, less obvious targets become worth hitting too. Being small and unknown is no longer a defence on its own.

Why custom still wins — for the right reasons

So the case for custom software is not "nobody will find you". It is three things that hold up against an attacker with unlimited patience.

  1. A smaller blast radius. When a shared platform is breached, you are breached with it. A custom app is its own system: a flaw found in it reaches your data, not yours plus that of 9,000 schools, and a mass campaign against a popular product does not land on you by default.
  2. A smaller attack surface. Off-the-shelf platforms ship every feature any customer might want, each with its own code, settings and integrations to exploit. A custom app exposes only what your business actually uses. Code that does not exist cannot be attacked.
  3. Security built in, not bolted on. Least-privilege access, multi-factor authentication, audit trails, secrets kept out of the database, dependencies kept current — decided at design time for your data, rather than left on a settings page most tenants never open.

None of that happens by itself. A custom app written by someone who does not know what they are doing is worse than any platform: all of the exposure, none of the security team. The advantage exists only when the software is designed and reviewed by a qualified developer who has built and defended real systems. That is the part of the purchase that actually matters.

The old objection: custom is hard to maintain

For twenty years the counter-argument was sound. Custom apps were expensive to build, slow to change and tied to whoever wrote them; when that person left, the code rotted.

AI-assisted coding has changed that — in experienced hands. The same models attackers use let an engineer who knows what good software looks like write tests, documentation and consistent code at a pace that used to take a team, refactor without fear, and keep dependencies current as routine work instead of a yearly project. The judgement stays human: what to build, what to refuse, what a change could break. The typing and the boilerplate no longer set the price.

The result is software that is cheaper to build and easier to maintain than it was five years ago, with a paper trail — tests, reviews, conventions — that another qualified developer can pick up. The failure to avoid is the mirror image: AI in inexperienced hands produces a lot of code very fast, and nobody who understands it.

What this means for an SME

You do not need to rebuild everything. Start where your most sensitive data lives and ask two questions: how many other companies share that system with you, and how much of it do you actually use? If the answers are "thousands" and "a fraction", a purpose-built tool is worth pricing.

And whatever you run, shared or custom, have it looked at by someone who knows how attackers work today. That costs less than reading your company's name in a breach notice.