166 terms · 75/46/45
Threat № 063 · class: trust

Contractor Abuse

Contractor access abuse arises when a consultant, a contractor, an external firm or a temporarily engaged person uses access more widely or for longer than the work requires. The access is often granted legitimately, but afterwards it is not monitored, not narrowed and not withdrawn in time.

Term

description · examples · notes

Contractor access abuse arises when a consultant, a contractor, an external firm or a temporarily engaged person uses access more widely or for longer than the work requires. The access is often granted legitimately, but afterwards it is not monitored, not narrowed and not withdrawn in time.

Description

External associates can hold access to code, production systems, client data, the VPN, support tools or documentation. Unlike employees they are often outside the same regime of training, oversight, HR process and discipline. When the contract ends, the account sometimes stays open.

The risk is not only deliberate theft. A private laptop with no protection is enough, or keeping data for the next project, or sharing an account inside the supplier's own firm, or access nobody holds in any record any more. The external associate becomes a blind spot in the network of trust.

Examples

  • An external developer copies the project's source code and uses it later on another engagement.
  • A consultant keeps VPN access for months after the contract has ended.
  • A supplier firm shares one support account among several of its own employees, without the client's knowledge.

Notes

  • Access for external associates has to have an expiry date.
  • A plumber does not get a key to the house for coming once a month to fix a tap.
Composite
Wikipedia

Techniques

carried out with 2

Techniques used to carry it out. Select one to open its page.

Defenses

countered by 4