A sysadmin, a mail administrator and a security officer who never go on holiday.
A small company does not need three full-time specialists. It needs working servers, mail that arrives and access only for those entitled to it. We hand this work to autonomous agents, and a person steps in when something unusual happens.
System administrator
- Watches servers, disks, certificates and domains, and warns before something runs out.
- Installs updates in an agreed window.
- Checks that a backup exists and that it can be restored.
- Creates and disables accounts on request.
Mail administrator
- Keeps SPF, DKIM and DMARC in order.
- Reads DMARC reports and notices when someone else sends mail in your name.
- Watches the domain's reputation and the blocklists.
- Traces a “the email never arrived” complaint to its exact cause.
Security specialist
- Reviews sign-in logs: new countries, night-time sign-ins, password guessing.
- Finds forgotten accounts and excess rights.
- Notices rules that forward mail outside, a common trace of a break-in.
- Keeps a list of vulnerabilities and updates ordered by urgency.
Limits.
The agent acts within a list of permitted operations. Restarting a service is on it. Deleting data, changing administrator rights or opening a port to the outside goes through a person.
What the manager gets
One summary a week. What happened, what the agent did on its own, what is waiting for your decision.
A case from practice · the client is not named
A month of someone else's presence on a mail server
It began with a program mining cryptocurrency on a small company's mail server. It was found the same day, and the owner closed the server's outgoing connections. Mail kept working, and a stranger stayed for almost another month.
We found what had been left.
Seven spare entrances planted over three weeks; one of them left no trace in the logs. And an attempt to open a control channel from the server to the outside, which failed because outgoing connections were closed.
We kept the evidence and removed the backdoors.
First came copies of everything found, with a note of what appeared and when. Then removal and a system update. A day later the stranger came back and left a new backdoor: the way in was still open.
We found the way in.
No description of known vulnerabilities mentioned it; the path was rebuilt from the sequence of events in the logs. The server was running commands slipped to it through the mail service. The vulnerable services were switched off and the attackers' addresses blocked.
We built the server again.
After weeks of someone else's access a clean-up only contains the damage and guarantees nothing. Mail now runs on a new server, with daily backups and with outgoing connections limited to what is needed.
This case grew into an agent that guards the mail server
Everything that was missing then is now done by an agent, every day and without reminders. A person steps in when a decision is needed.
- Updates. Every day the agent compares the installed components with the fixes that have been released. It also checks that the system's automatic updates are switched on and working.
- New attacks on this set of software. The agent reads security bulletins and vulnerability databases for the programs the server is built from, and follows their new releases. It also takes in signals from organisations that scan the internet and tell owners about infected hosts.
- Internal control. The agent compares the server with what it was yesterday: files and settings, scheduled jobs, open entry points, accounts. The reference for the comparison is kept off the server, and the server is regularly checked from the outside as well.
- Alerts. An alert goes to an address read every day; the channel counts as working only once a person has received a test message. In that case the warnings went for five days to a mailbox nobody opened.
- Backups. A backup is made every day, and the agent checks it itself: that it exists, that it is intact, that everything is in it. About backups it writes only when one fails.
There is no absolute protection. The agent is there so that a break-in is noticed the same day and the message about it reaches a person.
Where to start
With an inventory. The agent maps what you have: servers, domains, mailboxes, accounts. Often it is the first such map the company has ever had.