Service · Cybersecurity

Application security

Business software tends to be well defended at the front door and wide open inside. Ordinary users can browse far beyond their job, the shop-to-warehouse link runs under an administrator login because it was quickest to set up, and the KSeF token lives in a text file on the accountant's desktop. We fix this on Comarch ERP Optima, enova365, Subiekt nexo or a CRM your developers built.

1 integration
= 1 identity with minimum rights
6-monthly
role review
No keys
left in config files
Change log
edits and exports recorded

Included in this service

Every application is treated twice over: as a store of your data and as a possible exit route for it.

Talk the scope through with an engineer

Roles and rights

Permissions follow job descriptions instead of blanket access. A sales rep should not be able to pull the full contractor database in one click.

Integration identities

Each connection, whether BaseLinker, a payment gateway or the accounting sync, receives a separate account or Entra ID app registration holding precisely the permissions it uses.

Keys and tokens

Secrets move from config files into a vault, are pinned to known IP addresses and rotated on schedule. KSeF tokens carry only the scope their task demands.

App consents

We list the third-party apps employees have authorised against Microsoft 365 or Google Workspace data and introduce stricter approval for future ones.

Change history

A record of who altered prices, exported client lists or raised their own privileges. Without it an investigation has nothing to work on.

Patching and libraries

A fixed update routine tested on staging, plus monitoring of third-party components in custom-built software.

How we work together

Department managers decide who needs what. We convert those decisions into configuration.

01

Inventory

Every application in use, its users, the data inside and the places it sends that data.

02

Role design

Managers and we agree the roles and their contents, captured in a spreadsheet that is simple to maintain.

03

Implementation

Roles applied, integrations moved to their own identities, secrets tidied and logging enabled.

04

Recurring checks

Regularly, for example every six months, rights are matched against current positions, because staff change teams and their access tends to follow them.

An integration account is frequently the strongest identity in the company. It has full rights, a password that never changes and sign-ins nobody reviews. Steal its key and an attacker has everything at once, with no employee involved.

Questions and answers

Common, but avoidable. Access to a handful of modules is usually enough, and full rights can be granted temporarily for a specific upgrade. We change the password after each such session.

In a secrets vault or inside the system that uses it, never in a desktop file or an email. It should carry only the permissions the integration needs and be replaced when the person who generated it leaves.

This service covers configuration, permissions, integrations and dependencies. A full vulnerability hunt in the code is a penetration test, available separately in the testing and QA area.

Yes, above all where someone could change a supplier's bank account number or export data. If the system supports sign-in via Entra ID or Google Workspace, we connect it to the company identity with MFA, and access ends automatically when an employee leaves.

Tidy up access across your systems

Name the systems your business relies on and how they connect. We will suggest where to begin.

Hours
Mon-Fri 8:00-18:00 CET, reply within one working day
Meetings
Online via Teams or Google Meet

We set strictly necessary cookies only: they keep the site running and remember the city you chose. Nothing here is used for advertising or tracking. More in our privacy policy.