Compliance

Phase 1, Phase 2, then keep it running

A fixed-price gap analysis, remediation through to your audit, and upkeep after it. All in a workspace you keep.

All compliance →
Security

Testing, review and leadership

Led by a published security researcher with five CVEs. One standard report, letters for your buyers, and retests of your fixes.

All security →
Who we help

Prove you are secure

To the people you sell to, raise from or answer to.

All industries →
Resources

Learn the space

Original research, free tools, and plain-language guides on security and compliance, from a published security researcher.

Read the blog →
Security

How to Check if an Edge Appliance Was Compromised After You Patch It

Patching an internet-facing appliance fixes the vulnerability. It does not remove webshells, planted accounts, stolen session tokens or config changes an attacker made before you got there. After you apply the update, you need a deliberate compromise check: review authentication logs, compare the running configuration against a known good baseline, look for unexpected files and accounts on the appliance, and invalidate every active session and credential that passed through it.

This comes up now because the Canadian Centre for Cyber Security issued alert AL26-024 on September 27 for two critical vulnerabilities in Citrix NetScaler ADC and NetScaler Gateway, then updated it again on October 3. When the same alert moves twice in a week, the situation on the ground is changing, not the paperwork.

What to look for after the patch

  • Config diff. Export the running config and compare it to your last known good copy. Attackers add authentication policies, bind scripts and redirect rules that survive an update.
  • Accounts and keys. List local admin accounts, API keys and SSH keys on the device. Anything you cannot trace to a person or a ticket gets removed.
  • Files on disk. Appliance shells are restricted for a reason, but if the vendor gives you a way to list recently modified files in web-accessible directories, use it. Webshells are the common persistence method on gateways.
  • Authentication logs. Look for logins from unusual geographies, successful authentications without a matching MFA event, and sessions that ran long after business hours.
  • Outbound traffic. Check your firewall or flow logs for connections initiated by the appliance itself to addresses you do not recognize. A gateway should rarely be the one calling out.
  • Session and credential reset. Kill all active sessions, rotate the device admin credentials, rotate any service account the appliance holds, and force reauthentication for users whose tokens could have been captured.

If you find something you cannot explain, stop touching the device and preserve what you have. A support bundle and a log export taken before you start cleaning are worth more than a tidy box.

Free weekly email

Get The Compliance Brief every Tuesday

One email a week from Jacob Masse: the security and compliance stories that changed something that week, and what each one means if you sell software to enterprise buyers. Five stories, a take on each, five minutes to read.

Free. Unsubscribe in one click, and replies reach Jacob directly. Read the latest issue or browse the archive.

Nobody owns the gateway

In assessments, the edge appliance is almost always the piece of the stack with no named owner. It was installed by someone who has since left, it sits outside the configuration management the application team uses, and its patch cadence depends on whoever happens to read the vendor bulletin. That is why it gets compromised. Put a person's name against every internet-facing device in your asset inventory, with a documented patch window and a defined source for vendor advisories. The security side of the house gets much easier once that list is real.

What auditors expect to see

Under SOC 2 and ISO 27001, the control is not "we patched it." It is evidence that you detected the advisory, assessed exposure, acted inside your own stated timeline and considered whether an incident occurred. Keep the advisory link, the date you were notified, the affected asset list, the patch confirmation and the compromise assessment notes together in one ticket. That single artifact answers a vulnerability management question, a change management question and an incident response question at once.

Set a standing rule: any critical vulnerability on an internet-facing device triggers both a patch and a compromise check, with the second step written down even when it finds nothing. The empty result is the evidence.

This started as a story in The Compliance Brief. Every Tuesday, Jacob picks the five security and compliance stories that change something for a company selling to enterprise buyers, and says what to do about each. This one was in issue 9.

Get the Brief every Tuesday

Before you go

Want the rest of this by email?

If this was useful, I send a few short notes on security posture. Unsubscribe in one click, and replies reach me directly.

From Jacob Masse, principal of traztech: the files by email, then a few short notes over the next month. No spam, unsubscribe in one click.

Want a second opinion on where you stand?

We run SOC 2, ISO 27001 and the rest of the compliance stack for startups and SMEs, and the security testing that sits behind it. The first call is free, and we will tell you if you are not ready to start yet.

Book a free call

Track record

Who is actually doing the work

5
Published CVEs, including a CVSS 9.1
Zero
Exceptions on a SOC 2 Type II built from nothing in-house

Published vulnerability research

Five published CVEs. CVE-2024-45163 (CVSS 9.1) is a flaw in the Mirai botnet itself, which gave defenders a way to shut down attacker infrastructure. CVE-2026-42626 takes HP ENVY 5000 printers offline from any unauthenticated device on the same network.

A SOC 2 Type II built from nothing

At Humera, a venture-backed US security company, Jacob built the compliance programme in-house from nothing: no report, no policies, no documented controls. It ended in a Type II attestation with zero exceptions.