There are obvious and non-obvious vendors, third parties, and contractors that have access to your data or your corporate network. The obvious ones are organizations that provide IT or technology services to you. Naturally, these individuals would have access to your data, because you’ve granted it!
On the flip side, there are plenty of organizations whose access to your corporate network or data is less obvious, or even hidden. These companies likely provide a business service to your organization, which may include law firms, accounting firms, benefits, or PR agencies. Those firms may have access to your sensitive information, and you may be completely unaware. This can be for many reasons. Consider these common situations:
- You’ve contracted a business service and have given them more network access than you realized.
- You’ve sent something out to them, like an email or USB, that may have contained sensitive trade information or personally identifiable information (PII).
- You’ve brought them onsite and have unknowingly allowed them to amass sensitive data on you through simple conversations or onsite visits.
You may not consider these circumstances very important in regards to cyber security—but you should! If you’re providing “hidden” vendors with unprecedented levels of access to your corporate infrastructure, they can do major damage.
Consider These Scenarios
Let’s imagine that your company has just moved into two floors of a brand new office building. Every day, there are hundreds (or thousands) of people coming in and out of the doors. Some of those people you will know, and others you will not. Now let’s say the owners of the office building contract a third party HVAC service, and they give that service provider access to monitor the building facilities remotely. Sounds like business as usual, right?