We can never be sure about that. One’s threat model has to assume that Mallory can find a way in. Backdoor’s are not super common, but there will always be 0-days. Security operations need to be setup with this in mind. Design your infra for defence-in-depth. Logging and access control is very important. Log everything that happens in your systems. Don’t use long-lived credentials. Don’t give people more access than they need. Audit users’ privileges, remove privileges that are no longer required. Try to make your logs tamper-proof. (Perhaps keep copies of the logs offline?)