
Key takeaways
- Prioritise securing administrative access to all critical software assets immediately upon vendor exit.
- Insist on comprehensive documentation, including architecture diagrams and deployment procedures, as part of the handover.
- Conduct a thorough security audit post-handover to identify any vulnerabilities or backdoors.
- Understand the legal implications of intellectual property and licensing in your original development contract.
Why Securing Your Assets Matters Now
When a development project stalls or a supplier relationship concludes, the immediate priority is protecting your organisation's investment. This isn't just about code; it encompasses domains, cloud infrastructure, and critical data. Delay in securing these assets can lead to significant operational disruption, data breaches, or even a complete loss of access to your essential systems. Your ability to continue business operations or engage a new team hinges on this.
In the UK, the legal landscape for digital assets is clear. Your contract should stipulate intellectual property rights and data ownership. However, practical control often lags legal ownership. Ensuring you have administrative access to all platforms is the first step towards mitigating risks. Without this, even legally owned assets remain inaccessible and unusable, costing your business time and money in recovery efforts.
- List all domains, subdomains, and DNS configurations.
- Identify all cloud accounts (AWS, Azure, GCP, etc.) and associated services.
- Catalogue all code repositories (GitHub, GitLab, Bitbucket).
- Document all third-party service accounts and API keys.
The Immediate Triage: What to Secure First
Our experience with distressed projects shows that the initial focus must be on administrative access. On a recent UK retail build we took over, the outgoing agency held primary administrative keys for the client's AWS environment and domain registrar. We had to guide the client through a critical sequence: first, change all passwords, then revoke former supplier access, and finally, transfer ownership. This sequence prevents malicious or accidental interference.
Start by identifying the 'keys to the kingdom'. This includes root access to cloud providers, primary domain registrar accounts, and the top-level owner of code repositories. These are often distinct from regular user accounts. Once secured, systematically revoke all access for the outgoing supplier. This should happen before any formal knowledge transfer begins, ensuring their continued access is controlled and limited.
- Change root passwords for cloud accounts and domain registrars.
- Revoke all former supplier user accounts and API keys.
- Enable multi-factor authentication (MFA) on all critical accounts.
- Confirm administrative ownership of all code repositories.
Comprehensive Documentation and Data Handover
Beyond access, you need a complete and accurate record of the system. This includes technical documentation, architectural diagrams, deployment pipelines, and environment configurations. A client came to us mid-project with a half-built SaaS product where the previous team had provided only fragmented documentation. Reconstructing the build environment added weeks to the project timeline and significantly increased costs. Comprehensive documentation is your institutional memory.
Demand a structured handover of all project documentation. This is not just a 'nice to have'; it's critical for future maintenance, security, and development. Ensure it details dependencies, external integrations, and any bespoke configurations. This documentation should be stored in a location controlled by your organisation, ideally version-controlled alongside the code itself for consistency.
- Obtain up-to-date architectural diagrams and service maps.
- Request a complete list of all third-party licences and their terms.
- Secure database backups and data schemas.
- Demand any existing security audit reports or penetration test results.
Legal and Compliance Considerations in the UK
UK businesses must consider specific regulations during a software asset handover. Your original contract should detail intellectual property (IP) assignment. Ensure all code, designs, and unique assets are legally yours, as per the Copyright, Designs and Patents Act 1988. If not clearly assigned, you could face future disputes over ownership, hindering your ability to further develop or sell the product.
Data protection is another major concern. Under UK GDPR, your organisation remains the data controller, even if a third party processed data. Ensure all data held by the former supplier is either securely returned or verifiably deleted, with a certificate of destruction. This protects you from breaches and potential enforcement action by the Information Commissioner's Office (ICO). Also, verify compliance with any sector-specific regulations like PCI DSS for payments or NHS DTAC for healthcare.
- Review your contract for IP clauses and ownership assignment.
- Verify data return or secure destruction under UK GDPR.
- Assess compliance with industry-specific regulations (e.g., FCA, PCI DSS).
- Ensure all necessary software licences are transferred or re-acquired.
The Cost of a Poor Handover and Trade-offs
The financial impact of an incomplete or contested handover can be substantial. Costs include extended project delays, the expense of a forensic code audit to understand an undocumented system, and potential legal fees if IP or data ownership is disputed. We once saw a client pay an additional £30,000 just to regain access to their own cloud environment after a former contractor became unresponsive. This is money that could have been invested in new features.
While a clean handover is ideal, achieving it can sometimes mean accepting imperfect documentation or a delayed transfer if the alternative is a protracted legal battle. Prioritise securing core operational assets over exhaustive, non-critical documentation in urgent situations. The trade-off is often between speed of recovery and completeness of information. It's about pragmatic risk mitigation.
- Increased development costs due to undocumented systems.
- Legal fees for IP or data ownership disputes.
- Operational downtime and reputational damage from system access issues.
- Delays in product launch or feature delivery.
Next Steps to Secure Your Future
Taking decisive action to regain software control is paramount for any UK business facing a vendor exit or project rescue. Once primary access is secured and documentation gathered, consider a post-handover security audit to identify any lingering vulnerabilities or unintended access points. This proactive step helps establish a clean baseline for your internal team or new development partner.
Techsleight Labs understands the complexities of these transitions. We provide expert guidance, offering a confidential project health check with a written verdict on whether to fix, restart, or stop your project. Our senior engineers, available with onshore (UK) and offshore delivery options, can help you quickly assess inherited systems, secure your assets, and plan a clear path forward.
FAQ
How do I get my domain back from a former developer?
Contact your domain registrar directly with proof of ownership, such as company registration details or original purchase records. They can help transfer administrative control to your organisation, often requiring a formal request and identity verification.
What is the first thing to do when changing software suppliers?
Immediately secure all administrative access to your cloud accounts, domain registrar, and code repositories. Change passwords, enable MFA, and revoke the former supplier's access before any other steps are taken to prevent unauthorised activity.
Who owns software intellectual property in the UK?
In the UK, the ownership of software intellectual property generally rests with the creator, unless a contract explicitly assigns it to another party. Your development agreement should clearly state that all IP created belongs to your business.
Do I need to audit code from a previous agency?
Yes, a code audit is highly recommended. It identifies quality issues, security vulnerabilities (e.g., Cyber Essentials compliance gaps), and technical debt, providing a clear picture of the inherited system's state and informing future development efforts.
How long does a software handover take?
A basic handover of access can be completed within days, but a comprehensive transfer including full documentation, data migration, and knowledge transfer can take weeks or even months, depending on the project's complexity and supplier cooperation.
Ready to build in the UK?
Talk to a senior software team.
Share your roadmap, current stack, and timeline. We will help you choose the right developer, team, or managed project model.
Techsleight Labs is a trading name of Krapton IT Consultancy.

