A San Francisco story
The Tuesday the enterprise deal almost died at 2 a.m.
the co-founder of a 40-person software company in SoMa, three weeks from closing its first enterprise customer
It is a Tuesday in May, Karl the Fog still sitting on Twin Peaks, and the co-founder has a security questionnaire due Friday. The company is 40 people on Townsend Street, four years of work, and the enterprise customer that would double revenue wants question 14 answered: describe how you detect and respond to unauthorized access.
A contractor left in January. He was good, and busy, and nobody remembered that his console account had read access to the production database. His password turned up in a breach dump in April. At 2:07 on Tuesday morning someone in another time zone tries it.
The login succeeds.
The engineer on watch sees a January departure logging in from a country he has never worked from, disables the account at 2:10 and pages the co-founder with a summary, not a panic. No query ran. On Wednesday question 14 gets answered with Tuesday's log, timestamps and all. The customer's security team reads it, and the deal closes in three weeks.
A contractor who left in January is inside the cloud console, and the account still holds read access to every customer record.
What changes the ending
- Every departure closes every account the same day, and a quarterly review catches the ones it missed (CIS 5 Account Management).
- MFA on the cloud console and the production database with no exceptions for contractors, so a password from a breach dump is not a key (CIS 6 Access Control Management).
- Someone watching logins at 2 a.m. who can disable an account in minutes, which is also the honest answer to question 14 (CIS 13 Network Monitoring and Defense).