A story we hear too often
The week the enterprise deal waited on a token nobody remembered issuing
the co-founder and CTO of a 28-person AI startup
Nadia’s company is 28 people in a West Loop warehouse, a product that reads contracts for insurers, and a first enterprise deal that has been ‘in procurement’ for nine weeks. The security questionnaire is done. The Type I is scheduled. The customer’s CISO has one more question.
On a Monday the CISO forwards an advisory: a third-party chat integration used by hundreds of SaaS companies has had its OAuth tokens stolen, and attackers are pulling customer data out of every CRM the tokens touch. The CISO asks whether Nadia’s company uses it. It does. A marketing hire added it eleven months ago.
In the version that stalls the deal for a quarter, nobody knows what the token could reach, the CRM holds the customer’s contact data from the pilot, the answer to the CISO is ‘we are looking into it,’ and the evidence for the Type I now has an exception in it.
In Nadia’s version, every integration and token was in the inventory the assessment built, with its scope next to it. The engineer on watch revokes the token in twenty minutes, pulls the CRM access logs and finds nothing left. Nadia sends the CISO a one-page account by Monday afternoon. The deal closes the following week; the CISO tells procurement the response was the reason.
The CISO asks whether Nadia’s company uses it. It does. A marketing hire added it eleven months ago.
What changes the ending
- An inventory of every integration, token and vendor with its scope, reviewed quarterly (CIS Controls 2 and 15, Software Inventory and Service Provider Management)
- Access logs on the CRM, the cloud and the code pipeline that can answer ‘what did it reach’ in an hour (CIS Control 8, Audit Log Management)
- A named engineer with authority to revoke and a response plan that produces a customer-ready account the same day (CIS Control 17, Incident Response Management)