• Home
  • Tech
  • Attack Surface After Downsizing or an Office Closure
Attack Surface After Downsizing or an Office Closure

Attack Surface After Downsizing or an Office Closure

Closing an office is a property exercise with a long technical tail. The lease ends, the furniture goes, and the broadband line, the static addresses, the site-to-site tunnel and a cabinet of equipment carry on quietly. Months later that connection is still terminating on your network, still permitted by a firewall rule, and no longer in a building anybody from your company visits.

What tends to be left running

Start with connectivity. Site-to-site tunnels, leased lines and broadband connections with static addresses often remain active because the contract runs to a different date and cancelling requires an account nobody has. Then there is the equipment: firewalls, switches, wireless controllers and occasionally a server, all reachable from your network and no longer physically secured. Building systems belong on the list too, since alarm panels, cameras and door controllers frequently have their own connections arranged by a facilities contractor rather than by anyone in IT.

See also: Balancing Technology and Human Life

The records that keep pointing at nothing

DNS entries for a closed site outlive the site by years. Where a record points at an address you no longer control, somebody else may eventually be allocated it, which turns your hostname into their server. The same applies to cloud resources provisioned for that location and to firewall rules referencing its addresses. Each is a small piece of untidiness on its own. Together they make your perimeter description inaccurate, which means your testing scope is inaccurate as well, and the addresses nobody claims are the ones an attacker will investigate first.

“The physical side gets forgotten completely. When a site closes, that cabinet full of kit usually contains configuration with credentials for your network, and it often leaves the building in a skip or with a contractor. The Information Commissioner’s Office has published clear guidance on disposing of IT equipment holding data, and following it costs less than explaining why you did not.”

William Fieldhouse, Director, Aardwolf Security Ltd

A decommissioning checklist that works

Write it once and use it for every site. Cancel the connectivity and confirm the address ranges are released. Remove firewall rules and routes referencing the site. Delete or repoint DNS records. Collect the equipment, wipe it to a documented standard and record the disposal. Disable accounts and access cards belonging to staff who left rather than moved. Update the asset register and the perimeter scope so the next test reflects reality. Assign each item an owner and a date, because a checklist with no names gets half completed.

Proving the cleanup happened

Verify from outside rather than trusting the tick boxes. An external perimeter assessment after the closure will show whether anything at those addresses still answers, and it frequently finds a management interface or a camera that nobody knew was still connected. Internal security reviews cover the other half, checking that the routes and rules pointing at the old site are gone and that no dormant trust remains, which matters most in an estate that has grown by acquisition.

Frequently asked questions about site closures

These questions come up whenever a business consolidates its offices.

How long should a connection stay live after a move?

Long enough to confirm nothing depends on it, which is usually a fortnight of monitoring rather than months of hedging. Disable it first and remove it once the silence is confirmed, so reversal is quick if something surfaces.

What about equipment going into storage?

Wipe it before it is stored, not before it is disposed of. Kit in a cupboard with live configuration is a risk for as long as it sits there, and storage rooms have a habit of being cleared by people who do not know what they are handling.

Leave a Reply

Your email address will not be published. Required fields are marked *