How to manage vendor, IT provider and contractor access to your systems
The 2013 Target breach, which exposed about 40 million payment cards, began with a login that belonged to a small heating and refrigeration contractor and was meant only for billing.[1] This guide explains how to manage the outside people who can reach your systems, from your IT provider to the software vendor who dials in for support, so a stranger with their password cannot walk through your office.
Why vendor access is a favorite way in
A small office rarely runs its own IT. An outside company, often called a managed service provider or MSP, handles computers, backups and email. The practice management or tax software vendor connects in to fix problems. A contractor manages the website, the phones or the security cameras. Each one needs some access, and each one is a door.
Criminals know that one IT provider may hold the keys to dozens of small businesses. In May 2022, cybersecurity agencies from the US, UK, Australia, Canada and New Zealand, including CISA, the FBI and the NSA, issued a joint advisory warning that attackers target managed service providers to reach their customers, and listing what customers should do about it.[2] That advisory is the backbone of this guide.
Cases: the billing login that reached the registers, and others
In the fall of 2013, a Pennsylvania refrigeration and HVAC contractor had an online connection to Target for electronic billing, contracts and project management.[3] According to a later analysis by Senate Commerce Committee staff, malware delivered by email to the contractor is believed to be how its Target login was stolen. In mid-November, the intruders used that login to get inside Target's network, and within about two weeks they had card-stealing software on most of the chain's checkout terminals.[1]
The Senate staff found weak spots at nearly every stage: two-factor login was rarely required for lower-level contractors, and the network was not divided tightly enough to stop someone who came in on the vendor side from reaching payment systems.[1] A login meant for sending invoices should have led to a billing portal and nothing else. The full story is in our case file on the Target HVAC vendor.
The pattern keeps repeating. At Australian health insurer Medibank, an IT worker employed by a contractor had work passwords synced to his home computer, where malware stole them. Medibank's remote access accepted a username and password alone, and data on 9.7 million customers was taken.[4] See the Medibank contractor login.
At a New York credit union, a request to the outside IT firm to disable a fired employee's remote access was never carried out, and she used it 2 days later.[5] That story is in our credit union case file. And at Uber in 2022, the intruder got in through the account of an external contractor; see the Uber case.
The Federal Trade Commission has drawn the same lessons from its own enforcement cases. Its guide for businesses points to a restaurant chain that did not adequately limit third-party access to its network, and a medical transcription company that did not require its own service providers to take reasonable security precautions.[6]
Step 1: know every outside login
Start with a list. For every vendor, contractor, IT provider and software company, write down:
- Who they are and who your contact is. With a phone number you collected at the start, not from a later email.
- How they get in. A remote support tool, a VPN account, an admin account in your email system, a vendor portal, or a shared password.
- What they can reach. Everything, or just one system.
- When access should end. The contract end date, or "only during a scheduled support session."
Anything you cannot explain gets switched off. An account nobody remembers creating is exactly the kind of door criminals look for.
Step 2: give each vendor the smallest key that works
The joint advisory tells customers to restrict provider accounts to only the systems they manage, not to put them in internal administrator groups, and to audit them to confirm each one is still needed.[2] In plain terms:
- One account per vendor, never shared. Each outside company gets its own named account, so you can see who did what and close it on its own.
- Only the systems they support. The phone vendor does not need your file server. The website designer does not need your email admin console.
- Remote support only when invited. Where the tool allows, require someone in your office to approve each session, or turn the vendor's access on for the appointment and off afterward.
- Separate the sensitive stuff. Ask your IT provider to put card terminals, and ideally client records systems, on a separate network from guest Wi-Fi, cameras and anything a vendor touches.
Step 3: require MFA on every vendor login
The same advisory says to enforce multi-factor authentication on all provider accounts that reach your environment, and to write that requirement into the contract.[2] Target's contractor login and Medibank's remote access were both far easier to abuse because a password was enough.[1][4] Ask your IT provider to show you, not just tell you, that its remote support tool and its admin accounts in your systems require a second login step. Our MFA guide explains which kind to ask for.
Step 4: put it in the contract, and close the door at the end
A short security section in each vendor agreement does a lot of work. The advisory recommends contracts that spell out who is responsible for which security tasks, and that require the provider to notify you of confirmed or suspected security events.[2] The FTC similarly recommends contract terms requiring service providers to take reasonable security precautions.[6] For a small office, ask for:
- MFA on all access to your systems.
- Named individual accounts, no shared logins.
- Prompt notice of any security incident that could affect you, with a set number of days.
- Removal of all access when the contract ends, confirmed in writing.
- A description of how they verify callers before resetting passwords for your staff. Our help desk guide explains why.
- Backups you can reach without them. The advisory recommends backups kept in isolated locations.[2]
Finally, close the door when they leave. The advisory calls disabling provider accounts at the end of a contract a commonly overlooked step.[2] When you change IT providers, the old one's remote tool may still be installed on every computer. Ask the new provider to find and remove it, change every admin password, and confirm in writing. Then review your vendor list every quarter alongside your staff list.
Your vendor access checklist
- A written list of every outside login. Who, how, what they can reach and when it ends.
- One named account per vendor. No shared passwords with outside companies.
- Least access. Each vendor reaches only the systems it supports.
- MFA on every vendor account and remote tool. Shown to you, not promised.
- Remote sessions approved from inside the office. Where the tool supports it.
- Sensitive systems separated. Card terminals and records on their own network.
- Contract terms for security, notice and offboarding. In writing.
- Quarterly review. Anything unexplained or expired is switched off.
Common questions
We are too small to demand contract changes. What can we do?
You can still ask questions and choose. Ask each provider in writing whether they use MFA on their access to your systems, whether their technicians have individual accounts, and how they would tell you about an incident. The answers are useful whatever they are, and a provider who cannot answer is telling you something.
Is it safe to let a vendor connect remotely at all?
Usually yes, with limits. Remote support saves time and money. The risk comes from access that is always on, shared, protected by a password alone, or broader than it needs to be. Fix those four things and remote support becomes a controlled appointment rather than an open door.
How do I know if my old IT provider still has access?
Ask your current provider to check every computer for remote support tools you no longer use, list every admin account in your email and cloud systems, and remove anything that belongs to the old provider. Then change the passwords on any accounts the old provider knew.
Put it in writing
The free Heist Control Checklist walks through the controls behind every case on this site in about ten minutes. For ready-made policies, the Policy Pack has five editable templates, and the Insider Threat Kit covers risks from inside your own team.
- Employee offboarding checklist: how to cut off a former employee's access the same day
- How to stop fake invoices, changed bank details and fake-boss payment requests
- How to verify callers before password resets, and protect your phone number from SIM swaps
- How a small business keeps software and devices patched, and why default passwords must go
- Backups that survive ransomware: offline copies, tested restores and a one-page plan
- Which two-step login actually stops phishing, and how a small office rolls it out
- Cases behind these controls
General guidance, not legal advice. Check requirements specific to your industry with a qualified adviser.
- U.S. Senate Committee on Commerce, Science, and Transportation: A "Kill Chain" Analysis of the 2013 Target Data Breach (Majority Staff Report, March 26, 2014)
- CISA, FBI, NSA, NCSC-UK and partners: Protecting Against Cyber Threats to Managed Service Providers and their Customers (AA22-131A)
- Krebs on Security: Target Hackers Broke in Via HVAC Company
- BleepingComputer: Scathing report on Medibank cyberattack highlights unenforced MFA
- The Register: Fired credit union employee deletes 21GB of data
- FTC: Start with Security: A Guide for Business