Article image
Digital Housekeeping: Revoking SSH Keys and Admin Accounts After a Client Project Ends
The project is over. The final invoice is paid, the launch party is a wrap, and your agency team has successfully deployed a beautiful, high-performing web application. High-fives all around. Your team immediately pivots to the next client, archiving the Slack channel and moving on.
But lurking in the background of that completed project is a massive, silent liability: a web of active admin accounts, API tokens, and SSH keys that your agency still holds.
Picture the scenario six months later: the client's server is breached, and a threat actor installs a cryptominer that drains the client's AWS budget by tens of thousands of dollars. When the forensic audit concludes, the entry point is discovered — an orphaned, compromised SSH key belonging to one of your former freelance developers. Because your agency failed to revoke developer access and clean up its digital footprint, you are n
Discussion
Get the discussion rolling
A single comment can start something great.