4 ms·
Adding to the list of what's already been said: 1. Passwords / Secrets management. Ensure there are no shared accounts in use, no credentials or passwords on t
by computershit 5y ago
Adding to the list of what's already been said:
1. Passwords / Secrets management. Ensure there are no shared accounts in use, no credentials or passwords on the company wiki. Implement adoption of a password manager (LastPass if commercial, BitWarden if you can selfhost) for team and individual secrets.
2. Identify all public-facing endpoints and do an initial once over on the software that's backing them and any vulnerabilities (especially if they have anything Atlassian in their stack).