logo
hamburger-menu-icon
Back to Projects

Blockchain Engineering Organization

Security Roadmap for a Blockchain Org

A blockchain engineering organization's GitHub setup had grown to nearly 1,900 repositories with no consistent governance or security tooling. Ollon assessed the setup across five areas and built a prioritized security roadmap sequenced to avoid disrupting active pipelines. The organization now has a clear plan to reach enterprise security standards while keeping its open source contributions intact.

A blockchain engineering organization's GitHub organization had grown to nearly 1,900 repositories with no consistent governance in place. Access was managed through direct user permissions rather than teams, security tooling was unevenly applied, and there were no shared standards for repository configuration or dependency management. External collaborators on public repositories added further complexity, as they would not fall under a centralized identity solution.

Ollon assessed the organization's GitHub setup across five areas: access controls, repository configuration, security tooling, third party integrations, and reporting. The work produced a prioritized plan addressing identity management, security tooling, repository configuration, and third party app access. Recommendations were sequenced carefully to avoid disrupting active pipelines given the scale of the organization.

The organization came out of the engagement with a clear plan to bring their GitHub organization up to enterprise standards while keeping community contributions to their open source projects intact. The plan covers immediate actions using features already available, with a path toward full GitHub Advanced Security coverage as licensing expands.

GitHub, CodeQL, Dependabot, Google SSO, SCIM, Falcon SIEM, Crowdstrike, AWS

Our Expertise in Action

Identity and Access Management (IAM)

A blockchain engineering organization with roughly 1,900 repositories had grown without a single sign on solution, leaving access managed through scattered direct permissions instead of teams. Ollon assessed the organization's identity setup and built a roadmap for moving to Google SSO with SCIM provisioning, alongside a framework for governing external collaborators on public repositories who fall outside that identity system. Ollon's plan gives the organization a path to centralized, auditable access control while still supporting the open source contributors who sit outside its corporate identity system.

Cybersecurity assessment and incident response

Security tooling had been applied unevenly across nearly 1,900 repositories, with features like CodeQL, secret scanning, and push protection missing from many of them. Ollon audited that tooling and built a phased enablement plan, separating what could be turned on immediately using free features for public repositories from what required GitHub Advanced Security licensing for private ones. Ollon's assessment also recommended routing GitHub security alerts into the organization's existing Falcon SIEM and Crowdstrike tooling, consolidating detection and response into the security team's existing workflow.

Dependency management and security remediation

With no standardized process for managing dependencies, this organization also had no clear view into which third party tools connected to its GitHub organization actually needed the access they had been granted. Ollon designed a two track dependency management strategy using Dependabot, auto merging updates on development branches while requiring manual review before changes reach production. Ollon's assessment also audited the organization's connected GitHub Apps and found that 30 of 42 held write access, far more than most of those integrations require. Carrying out Ollon's least privilege remediation plan cuts that number down to only the apps whose function depends on write access.

GitHub

Governing nearly 1,900 repositories without consistent standards meant new projects inherited no baseline for security or configuration. Ollon designed public and private repository templates with required files and branch protection rulesets, laid out retention and archival policies backed by automated cleanup scripts, mapped a path to GitHub Enterprise Cloud, and proposed a three tier governance framework for GitHub Copilot. Once adopted, new repositories inherit a consistent baseline, with a defined path for scaling that standard as the organization adopts Enterprise Cloud and AI assisted development.

Blockchain and cryptocurrency

This organization builds one of the industry's major layer one blockchains and maintains a public GitHub footprint far larger than the typical enterprise. Ollon's assessment had to account for the scale and openness a blockchain project requires, applying enterprise grade security controls to the private, production facing side while preserving the public visibility that lets outside researchers inspect the protocol's code. The result is a governance model that tightens production infrastructure the way any enterprise would, while keeping the transparency blockchain projects depend on for community trust intact.