Think about the last outside person who needed access to something in your business. A contractor building a report. An agency posting to your accounts. A vendor’s technician who needed into a system to fix something. You created an account, shared a folder, or added them as a guest, and everybody moved on.
Now the harder question. Is that access still working right now? For most businesses the honest answer is yes, and nobody has thought about it since. This is not a dramatic problem. It is quiet accumulation nobody owns, and it is one of the easier items on the security list to fix, because the fix is a habit, not a purchase.
The Accounts You Forgot You Created
Every business we look at has some version of this list. It is always longer than the owner expects.
- The contractor from a finished project. The website launched two years ago. The developer account that built it never got turned off, and it may still hold administrator rights.
- The vendor support account. Created during setup so the software company could help. It usually has broad permissions, no expiration, and nobody at your company knows who at their company can use it.
- Guest access to shared files. A folder shared with an outside team for a bid or one time project. The project ended. The share did not.
- Old integrations and connected apps. A tool somebody tried in 2021 that still holds permission to read your email or customer records long after anyone stopped using it.
- The shared login “for the vendor.” One username and password that three people at another company use. When one leaves, nobody tells you, because nobody thinks to.
CISA names third parties as an insider threat category, describing them as “contractors or vendors who are not formal members of an organization, but who have been granted some level of access to facilities, systems, networks, or people.” That is exactly this population. They are not adversaries. They are people you invited in and then stopped tracking.
Why it matters is simple. An account nobody watches is an account nobody notices being misused. A 2023 joint advisory from NSA and CISA listed improper separation of user and administrator privilege among the ten most common misconfigurations, called the slow accumulation of unnecessary permissions “privilege creep,” and told organizations to reduce, restrict, audit, and monitor administrative accounts. Forgotten outside accounts are privilege creep in its purest form. The stakes are not theoretical: in its 2025 Internet Crime Report, the FBI’s Internet Crime Complaint Center recorded 24,768 business email compromise complaints and more than $3 billion in reported losses, a category built on reaching accounts that should not have been reachable.
Set the Expiration When You Create the Account
Here is the change that fixes most of this, and it takes ten extra seconds. Every outside account gets an end date the moment it is created. Not later. Not on a cleanup list. At creation, when you know what the project is and roughly how long it runs. Most business identity platforms and file sharing services support expiration dates on guest accounts and shared links, in the settings near where you invite the person or generate the share.
This works because it inverts the default. Today access continues forever unless someone remembers to stop it, and nobody remembers. With an expiration date, access ends unless someone extends it. If the contractor still needs in, they will tell you, and extending takes a minute. Nothing important gets lost, and everything unimportant disappears on schedule.
Two notes. Pick a date shorter than you think you need, because extending is easy and revoking never happens. When the platform does not support expiration, put the date in your calendar. A reminder is a poor substitute for automation and a great substitute for nothing.
The Quarterly Review That Takes an Hour
Expiration dates handle accounts you create from here forward. The review handles the ones already sitting there and catches whatever slips through.
Once a quarter, someone sits down with a list and asks one question about each entry: does this person or company still need this? Keep it boring and scheduled.
- Pull the lists. User accounts, guest and external accounts, active shared links, connected third party apps, and remote access tools. Your IT provider can produce this in an afternoon.
- Flag anything you do not recognize. Not knowing what an account is for is itself the finding. Do not skip it because it looks official.
- Check the last login date. An account unused for six months is either unnecessary or forgotten. Both mean it goes.
- Look at permission level, not just existence. Plenty of outside accounts legitimately exist but hold far more access than the job required. Trim rather than delete when the relationship is ongoing.
- Disable first, delete later. Disable it, wait thirty days, see if anyone complains. That removes the fear that makes people avoid cleanup entirely.
An hour a quarter is the whole commitment. Put it on the calendar like any recurring obligation, and assign it to a person rather than to “IT” generally.
Vendor Accounts Deserve Real Offboarding
Most businesses have a decent employee offboarding routine. Someone resigns and there is a checklist: email disabled, laptop returned, building access removed. Almost nobody applies that discipline to outside parties, even though the outsider often reaches more systems than the employee did.
Treat the end of a vendor relationship as an offboarding event with the same checklist. When you stop working with an agency, consultant, or software vendor, that triggers account removal, share revocation, and disconnecting any integration they set up. Do it at the end of the engagement, not at the next review.
Two more things while you are in there. Give every outside person a named account instead of a shared one, so you can remove one person without disrupting others and so your logs mean something. And require multifactor authentication on outside accounts, the highest value control you can apply to an account you do not manage. Our comparison of security keys, passkeys, and app based MFA covers the tradeoffs.
Put It in the Contract
Here is the piece almost everyone skips, and it costs nothing. You cannot see inside your vendor’s staffing, so make telling you their obligation.
Add language to vendor agreements and statements of work requiring the vendor to notify you within a defined period when any of their people with access to your systems changes roles or leaves. Require named individual accounts, not shared credentials. State that access ends when the engagement ends. Ask for written confirmation that access was removed at project close.
None of that is aggressive, and a professional vendor will not blink. If one pushes back, that tells you how they handle everyone else’s access too. Have your attorney review the wording, but do not let the absence of perfect language stop you from asking for the basics in an email today.
The Bottom Line
Access granted to outside people almost never expires on its own, because granting is urgent and removing is nobody’s job. The fix is not complicated: set an end date at creation, review the list quarterly, offboard vendors like employees, and let the contract put the notification burden where it belongs. That is a habit, not a project.
It pairs with knowing what tools and accounts exist at all, the problem we take apart in our post on shadow IT. You cannot expire access you do not know about.
If you want a straight answer about who currently has access to your systems, we can pull that list and walk through it with you. It is usually eye opening and rarely takes long. We work with small and mid-sized businesses across Denton County. Contact us today.
Sources:
Comments are closed