CaseStudy
RealBranding Agency
Managing a large portfolio of web domains centrally
CaseStudy
Managing a large portfolio of web domains centrally
Website Agency & Branding
The RealBranding agency has over 20 years of web development experience serving hundreds of household brands and even a Cathedral.
While the agency was focused on improving on the overall customer branding, as the agency grew, the company found itself battling with more and more cybersecurity threats. The net effect was to hamper growth, and increase the support burden. There were times the agency had to solely focus on the problem web domains, effectively ceasing work on new creative projects, which generated the majority of its revenues.
The team has lots of experience in design and web marketing, but doesn’t have a dedicated cybersecurity professional. Instead it would rely on its devops teams to try and find the root causes of each attack, and hadn’t adopted cybersecurity standards. Managing Director Michael Taite said:
“Every week at least one of our clients would develop a problem with a website. We were constantly putting out fires. As we grew the client base, this just made the problem exponentially worse and was a real barrier to growth.”
The company initially looked to harden its infrastructure and develop a comprehensive reference build. However, as the installed base of sites grew over time, nearly every prior build had different custom elements, and sometimes different webstacks, cloud providers and services, in line with the customer requirements.
Inevitably, staff turnover exacerbated the legacy code issue. Although the company had documentation standards in place for each new build, the rapid pace of new client onboarding meant that sometimes the documentation was not prioritised.
RealBranding did not have any formal threat detection process in place.
It meant they were often blindsided by the incoming threats, and sometimes from a phone call from their clients.
Although the company monitored all its servers and had comprehensive uptime checking, out of business hours coverage, it didn’t assess service degradation, slow performance, cyber exploits or data egress as it simply didn’t have the tools to manage and control its diverse environment. The company was often blindsided by new threats.