5
8 Comments

Cybersecurity concerns for a small company

Our company has been working with a small, outside team of developers more or less since day one. They have essentially built us a custom website from scratch, and we have relied on them for most of the ongoing changes and updates to the website. We have really enjoyed working with them, and they have done some quality work at a highly competitive rate. However, recently they have come to us with a new contract, drafted and mediated by a third party. After doing some digging, we have discovered that this third party is a state body. In the interests of privacy, I won't specify the country. But suffice to say, the government in question is a notoriously corrupt and unreliable one. After reading the contract, we have the suspicion that this state agency is going to be taking a significant cut from now on, and will also have the power to mediate any conflicts or disputes.

In light of this development, we have decided with some regret that the most prudent thing to do is to end our relationship with this team of developers. However, we are slightly spooked now that the state is sniffing around. We are also aware of the fact that this team of developers has/has had access to a huge amount of our more sensitive information. Though we have no reason to suspect the developers will intentionally use such information against us, nor attempt to sabotage our website, we want to be as cautious and careful as possible as we wind down this relationship. And so we are working under the assumption of worst-case scenarios.

The problem is that we are not sure if there are certain standard cybersecurity protocols that a business should follow when ending a relationship with third parties who have/had access to sensitive information? What steps should we take to minimise our cybersecurity risk in such a circumstance? Does anyone have any tips as to how we should manage the ending of this relationship in a way that will insulate us from malicious acts, either by the developers themselves or (much more likely) by the government in question?

I'd really appreciate any advice, or if you could point me to useful resources. Thanks!

on December 9, 2020
  1. 2

    Access control-wise, just change all the password, rotate the keys like the ones on Amazon and SSH keys to the server. Not sure what privacy info you have in mind. If you're deploying to Heroku you'll need a system administrator to do that. Since you're already not working with the company you mentioned, you'll need one anyway for your deploys? Then the dev op should know how to do that. Check your domain names records to make sure there's no 3rd party records from the previous company and they don't have access to your DNS. If you're really worried, get a 3rd party audit of the code they've supplied to you to check for vulnerability because if the government is so nasty they can attempt to find an exploit into your system. That can be pretty costly but a good idea anyway. Change passwords for internal users, as well as force external customers to change theirs. That can affect your brand but you can explain that you haven't been hacked and that's only for security reasons due to legal requirements or something like that. Remove any software tools they've supplied to you as part of your relationship. Change database connection stings. Nuke all VMs and create new ones but have your own guy set them up, if that's how you deploy, or create new accounts on CDN.

    1. 1

      Wonderful, thanks so much for your advice! Really appreciate it.

  2. 1

    Some good points below. Also don't forget the social engineering part, keep your own knowledge and your team training up to date.

  3. 1

    Have you found a solution and if so, would you be willing to share?

  4. 1

    Hey @creatureoflight is this still relevant? Happy to help if so