Bitsight often gets questions about expired certificates on service provider systems. In many cases, the organization asking the question doesn't believe there's a risk, particularly if they haven't used the provider or host for weeks, months, even years.
At some point, the organization decided to use the service provider and went through contract negotiations, hopefully a third-party risk assessment, and an onboarding process. Most enterprises undergo a similar process when hiring and onboarding new employees and contractors: interviews, a background check, an employment contract. Then the employee is issued a company ID and/or door badge, provisioned access to facilities and computer systems, and outfitted with a desk, personal computer, and office supplies.
On the other side of employment, organizations demand the return of IDs and computers, and deprovision employees' access when they leave the company. However, in our experience few organizations institute a thorough offboarding process for service providers, sometimes resulting in leftover certificates that expire after a time, stale records at the Regional Internet Registries (RIRs, e.g., ARIN, RIPE, APNIC, LACNIC, and AFRINIC), and other artifacts as organizations beat a retreat from contracts.
Latent Risks
Finding an expired certificate on a Content Delivery Network (CDN) provider, for example, isn't necessarily a risk in itself. To continue the analogy of employee offboarding, if you know Mathilda left the company a year ago, but you find a record of Mathilda in a company directory, you'd guess there's a good chance there are other artifacts of Mathilda, possibly even active accounts. So when Bitsight finds an expired certificate, it calls into question whether there are still accounts and data on the service provider's assets.