Skip to main content
WarnHack
WarnHack
Free resource

SSH access risk checklist

Twelve yes/no checks security leads and founders should be able to answer about production SSH. No signup required to score — email is optional for a follow-up pack.

Live score

0/12 (0%)

High access risk

Check every statement that is true for your team today. Unchecked items are your backlog.

Priority gaps (12)

  • We do not use shared private keys across multiple people for production access Attribution and offboarding break; key sprawl is almost guaranteed
  • We can list every human who can reach production servers today (name + path) Access reviews and incident response will fail under pressure
  • Leavers lose production SSH access the same day (verified, not assumed) Standing access after exit is a classic breach and audit finding
  • Engineers get role-scoped access — not “everyone has the prod key” Blast radius of a laptop compromise is the entire fleet
  • Break-glass / emergency access is documented and rare — not the daily path Emergency paths become permanent backdoors

Email me a follow-up pack

Optional: get a short recap of common fixes (keys, bastion, session audit) and Terminal tips. Score at submit: 0/12.

Related: use cases · Terminal · Teleport vs StrongDM