September 26, 2026
Your Vendors Have the Keys. Do You Know Which Doors They Open?
Ask most mid-sized organizations how many outside parties can log into their systems and you get a confident number. Ask them to list those…
By Chuksawunor
2 min read
Ask most mid-sized organizations how many outside parties can log into their systems and you get a confident number. Ask them to list those parties, the accounts they use, and when each account was last reviewed, and the confidence usually fades.
Third-party access is one of the softest parts of the modern perimeter. It is also one of the easiest to fix, once you look at it directly.
How vendor access sprawls
It rarely starts badly. The EMR vendor needs remote access for support. The HVAC contractor needs to reach the building management system. The accounting firm needs a login to the finance share. The MSP needs admin rights everywhere.
Each decision is reasonable on its own. Five years later you have remote access tools nobody remembers installing, shared vendor accounts with passwords that never change, and admin rights held by a company whose own security you have never assessed.
Why attackers love it
An attacker does not need to break your front door if a vendor's key already fits the lock. Compromising one service provider can give access to every customer that provider supports. Remote support tools, in particular, are built to give an outsider full control of a machine. That is exactly what an attacker wants.
Five questions to ask this month
1. Who has access, and how? Build a simple list: vendor, purpose, accounts, access method, systems reached, and internal owner. If a vendor has no internal owner, that is your first finding.
2. Is every vendor account tied to a named person? Shared accounts like "vendor_support" make it impossible to know who did what. Ask vendors to use individual accounts, and require MFA on all of them.
3. Is access always on, or on request? Most vendors need access occasionally, not permanently. Access that is switched on for a support window and switched off afterwards dramatically reduces your exposure.
4. Can you see what vendors do? If a vendor account logs in at 3 a.m. from an unusual location, would anyone notice? Vendor sessions should be logged and monitored like any other privileged activity.
5. What does the contract say? Your agreements should cover security expectations, breach notification to you, and your right to ask for evidence. For regulated organizations, this is increasingly an expectation from regulators and insurers, not a nice-to-have.
Start small, finish the list
You do not need a vendor risk platform to begin. A spreadsheet, an hour with each department head, and a review of your remote access tools will surface most of the risk. Remove what is no longer needed, put MFA on what remains, and make someone responsible for each relationship.
Then repeat it every quarter. Vendor access drifts, and the review is what keeps it honest.
At GuardsArm we help regulated organizations across Canada and the US map third-party access, tighten controls, and monitor privileged sessions around the clock. A virtual CISO engagement is a practical way to get the vendor inventory done, or you can book a free risk review.
Tony Chuks Awunor is Founder and CEO of GuardsArm Inc., a Calgary-based managed security provider for regulated organizations across Canada and the US.