Contractors, Third Parties and Supply Chain Insiders
- kind
- Reference
- domain
- Supply chain
- stage
- Programme design
- read
- 3 min
- assumes
- No prior programme in place
People with insider access who are outside your HR processes, your training, and usually your departure workflow.
An insider is anyone with legitimate access. That includes contractors, managed service providers, outsourced support, agency staff and partner organisations — none of whom appear in your HR system.
Why they are harder
Outside employment processes. No onboarding, no training, no exit interview, and no notification when they leave the supplier.
Access granted for a project and rarely removed. Project ends, account persists. This is the single most common finding in any access review.
Dual loyalty. A consultant working for three clients has legitimate context from all of them. That is what you are paying for, and it is also a risk you accept.
Different security posture. Their controls are not yours. Data reaching their environment is protected to their standard.
Frequently privileged. Managed service providers hold administrative access across systems, and they sit outside every control designed for employees.
The controls that matter
A named internal sponsor for every third-party account. Someone accountable for whether it should still exist. Without this, nobody owns the decision to remove access.
Hard expiry by default. Every third-party account time-bound, renewed deliberately rather than persisting by inertia. Expiry is easier to enforce than revocation because nobody has to decide to take something away.
Distinguishable identity. Third-party accounts marked as such in every system and every log. If you cannot filter for them, you cannot review them.
Contractual departure notification. Written into the agreement: the supplier tells you when their staff leave or move off your account. Nobody does this voluntarily.
Scoped access, genuinely. The default for contractors is broad access because narrowing it takes effort. Scope at onboarding, when there is a reason to think about it.
What the contract should cover
Data handling and location. Whether subcontractors are permitted and whether they are disclosed. Notification obligations on personnel change and on incidents. Return or destruction of data at termination, with evidence. Your right to audit. Background checking to a stated standard.
And the practical one nobody includes: a named person, with contact details, responsible for access administration on their side, updated when they change.
The offboarding gap
The most common serious exposure in this area.
An employee leaving triggers a process. A contractor leaving triggers nothing, because you do not know it happened.
Periodic confirmation is the workable substitute: quarterly, ask each supplier to confirm which of their people still require access. It is a five-minute email and it finds accounts every time.
Expiry does the rest. Time-bounded access fails safe.
Where the data actually goes
The exposure is frequently not the individual but the flow.
Data sent to a supplier for processing sits in their environment, on their staff's devices, subject to their controls, and possibly with their subcontractors. Your monitoring sees the transfer and nothing afterwards.
Map this. Which suppliers hold which categories of your data, and where. It belongs in the inventory alongside your internal systems, and it is usually absent.
Proportionality
You cannot monitor another organisation's staff and generally should not try. What you can do:
Restrict what they can reach. Time-bound it. Log their activity in your systems. Require notification. Verify periodically. Have a defined process for removing access quickly when the relationship ends.
That is achievable, defensible, and covers most of the realistic exposure — which is not a contractor deliberately stealing, but an account that outlived its purpose by three years.