"were taken from a Sitel support engineer’s computer upon which an attacker had obtained remote access using RDP. This device was owned and managed by Sitel. The scenario here is analogous to walking away from your computer at a coffee shop"
It really is not analogous at all.
That RDP was enabled, let alone could be accessed from outside the network is worrying.
To me this would appear that, to save a buck, they outsource a lot of functions that then meant customer security was partly out of their hands, and relied upon another company having their security ducks in a row. I'm sure in their marketing materials they boast about state-of-the-art security, but that's only as good as the weakest point in the chain.
We can extend that - "after we've promised our customers that a computer would never be left unlocked and logged in to sensitive things in a public place, but would instead be behind multiple locked doors."
It's really not the "see, this is something you might do! It's not so bad!" out they thought it would be.
It really is not analogous at all.
That RDP was enabled, let alone could be accessed from outside the network is worrying.
To me this would appear that, to save a buck, they outsource a lot of functions that then meant customer security was partly out of their hands, and relied upon another company having their security ducks in a row. I'm sure in their marketing materials they boast about state-of-the-art security, but that's only as good as the weakest point in the chain.