- Job title
- Chief Technology Officer
- Sector
- Printing
- Organization type
- 8-person team
- Joined
- Aug 2023
- Message
- 275
We are a 25-person fintech company developing payment gateway integrations. We are signing an Incident Response Retainer with an independent cybersecurity firm to handle potential ransomware, data leaks, or critical outages. We agreed on a 140,000 TL annual retainer fee.
To eliminate delays during a crisis and respond within the first 30 minutes, the firm is requesting a permanent, pre-configured VPN/SSH tunnel into our production jump host and firewall. They are asking for redundant credentials with full root/admin privileges.
We are extremely uneasy about leaving a persistent backdoor open for a third party inside our infrastructure. Keeping these accounts active without an active incident directly violates our security policy. What technical mechanisms and contractual clauses should we include to strictly govern the provider's remote access both legally and technically?