Guide · Vendor access

How to manage vendor, IT provider and contractor access to your systems

Published 2026-09-29 · 6 min read

The 2013 Target breach, which exposed about 40 million payment cards, began with a login that belonged to a small heating and refrigeration contractor and was meant only for billing.[1] This guide explains how to manage the outside people who can reach your systems, from your IT provider to the software vendor who dials in for support, so a stranger with their password cannot walk through your office.

Why vendor access is a favorite way in

A small office rarely runs its own IT. An outside company, often called a managed service provider or MSP, handles computers, backups and email. The practice management or tax software vendor connects in to fix problems. A contractor manages the website, the phones or the security cameras. Each one needs some access, and each one is a door.

Criminals know that one IT provider may hold the keys to dozens of small businesses. In May 2022, cybersecurity agencies from the US, UK, Australia, Canada and New Zealand, including CISA, the FBI and the NSA, issued a joint advisory warning that attackers target managed service providers to reach their customers, and listing what customers should do about it.[2] That advisory is the backbone of this guide.

Cases: the billing login that reached the registers, and others

In the fall of 2013, a Pennsylvania refrigeration and HVAC contractor had an online connection to Target for electronic billing, contracts and project management.[3] According to a later analysis by Senate Commerce Committee staff, malware delivered by email to the contractor is believed to be how its Target login was stolen. In mid-November, the intruders used that login to get inside Target's network, and within about two weeks they had card-stealing software on most of the chain's checkout terminals.[1]

The Senate staff found weak spots at nearly every stage: two-factor login was rarely required for lower-level contractors, and the network was not divided tightly enough to stop someone who came in on the vendor side from reaching payment systems.[1] A login meant for sending invoices should have led to a billing portal and nothing else. The full story is in our case file on the Target HVAC vendor.

The pattern keeps repeating. At Australian health insurer Medibank, an IT worker employed by a contractor had work passwords synced to his home computer, where malware stole them. Medibank's remote access accepted a username and password alone, and data on 9.7 million customers was taken.[4] See the Medibank contractor login.

At a New York credit union, a request to the outside IT firm to disable a fired employee's remote access was never carried out, and she used it 2 days later.[5] That story is in our credit union case file. And at Uber in 2022, the intruder got in through the account of an external contractor; see the Uber case.

The Federal Trade Commission has drawn the same lessons from its own enforcement cases. Its guide for businesses points to a restaurant chain that did not adequately limit third-party access to its network, and a medical transcription company that did not require its own service providers to take reasonable security precautions.[6]

Step 1: know every outside login

Start with a list. For every vendor, contractor, IT provider and software company, write down:

Anything you cannot explain gets switched off. An account nobody remembers creating is exactly the kind of door criminals look for.

Step 2: give each vendor the smallest key that works

The joint advisory tells customers to restrict provider accounts to only the systems they manage, not to put them in internal administrator groups, and to audit them to confirm each one is still needed.[2] In plain terms:

Step 3: require MFA on every vendor login

The same advisory says to enforce multi-factor authentication on all provider accounts that reach your environment, and to write that requirement into the contract.[2] Target's contractor login and Medibank's remote access were both far easier to abuse because a password was enough.[1][4] Ask your IT provider to show you, not just tell you, that its remote support tool and its admin accounts in your systems require a second login step. Our MFA guide explains which kind to ask for.

Step 4: put it in the contract, and close the door at the end

A short security section in each vendor agreement does a lot of work. The advisory recommends contracts that spell out who is responsible for which security tasks, and that require the provider to notify you of confirmed or suspected security events.[2] The FTC similarly recommends contract terms requiring service providers to take reasonable security precautions.[6] For a small office, ask for:

Finally, close the door when they leave. The advisory calls disabling provider accounts at the end of a contract a commonly overlooked step.[2] When you change IT providers, the old one's remote tool may still be installed on every computer. Ask the new provider to find and remove it, change every admin password, and confirm in writing. Then review your vendor list every quarter alongside your staff list.

Your vendor access checklist

Common questions

We are too small to demand contract changes. What can we do?

You can still ask questions and choose. Ask each provider in writing whether they use MFA on their access to your systems, whether their technicians have individual accounts, and how they would tell you about an incident. The answers are useful whatever they are, and a provider who cannot answer is telling you something.

Is it safe to let a vendor connect remotely at all?

Usually yes, with limits. Remote support saves time and money. The risk comes from access that is always on, shared, protected by a password alone, or broader than it needs to be. Fix those four things and remote support becomes a controlled appointment rather than an open door.

How do I know if my old IT provider still has access?

Ask your current provider to check every computer for remote support tools you no longer use, list every admin account in your email and cloud systems, and remove anything that belongs to the old provider. Then change the passwords on any accounts the old provider knew.

Close the same gap

Put it in writing

The free Heist Control Checklist walks through the controls behind every case on this site in about ten minutes. For ready-made policies, the Policy Pack has five editable templates, and the Insider Threat Kit covers risks from inside your own team.

More guides

General guidance, not legal advice. Check requirements specific to your industry with a qualified adviser.

Sources
  1. U.S. Senate Committee on Commerce, Science, and Transportation: A "Kill Chain" Analysis of the 2013 Target Data Breach (Majority Staff Report, March 26, 2014)
  2. CISA, FBI, NSA, NCSC-UK and partners: Protecting Against Cyber Threats to Managed Service Providers and their Customers (AA22-131A)
  3. Krebs on Security: Target Hackers Broke in Via HVAC Company
  4. BleepingComputer: Scathing report on Medibank cyberattack highlights unenforced MFA
  5. The Register: Fired credit union employee deletes 21GB of data
  6. FTC: Start with Security: A Guide for Business