Control need · Third-party and supplier access

Your suppliers need access. They do not need a permanent doorway.

Maintenance contracts, support arrangements and integrations all arrive with a connection attached. Those connections outlive the projects that created them, and they are rarely reviewed with the same care as employee access. Control governs the relationship rather than trusting it.

  • Procurement and risk framing
  • Supply chain exposure
  • Leads to Blueprint CP-03
  • Time-bound by design
The connection state today

Standing access, granted once, reviewed rarely

Vendor connectionsPersistent
Access windowsUndefined
Credential ownershipHeld by the supplier
Record of activityPartial

Need → Control → Blueprint → Modules

Corridor of offline storage racks inside a Firevault bunker
01What is exposed

Your risk now includes everyone you have ever connected to.

A supplier relationship is a commercial arrangement with a technical consequence. This is what is exposed when that consequence is left ungoverned.

01

Their security posture, applied to you

A standing connection means their credential hygiene, patching and staff turnover become part of your risk position.

Inherited risk
02

Access that outlives the contract

Connections created for an implementation frequently remain live years after the supplier relationship changed or ended.

Orphaned access
03

Reach beyond the scope of work

Access granted for one system often carries network reach into others, because it was easier to grant broadly than precisely.

Excess privilege
04

The audit answer you cannot give

Asked which suppliers can reach which systems today, most organisations need days to answer, and the answer is rarely complete.

Governance gap
02Why the exposure exists

Access was granted to get work done, then nobody closed it.

Supplier access is created under delivery pressure and reviewed under audit pressure, which are two very different moments with two very different levels of scrutiny.

The honest position

Nobody wants to be the person who blocks the engineer at two in the morning.

Permanent access exists because the alternative has historically been friction. If opening a path takes a day of paperwork, teams will keep the path open permanently and tell themselves it is monitored. Control removes that trade-off by making the temporary path easy to open and automatic to close.

Control the path, protect the asset.
Reason 01

Temporary access has no expiry

Access granted for a project is almost never diarised for removal when the project ends.

Reason 02

Contracts do not describe connectivity

Commercial agreements cover liability and service levels, rarely the physical path or its lifetime.

Reason 03

Suppliers hold the credentials

When the supplier manages its own accounts, your leavers process no longer covers who can reach you.

Reason 04

Convenience beats process

If requesting access is slow, teams keep standing access rather than face the delay each time.

Reason 05

Support tooling reaches widely

Remote support platforms are built for reach, which is exactly what makes them attractive to attackers.

Reason 06

The register is out of date

Vendor access lists are compiled for audits and drift as soon as the audit finishes.

03Which path needs controlling

Govern the relationship, one path at a time.

Third-party risk becomes manageable the moment each relationship is expressed as a specific path with a specific lifetime.

The path or relationshipWho uses itHow it behaves todayWhat Control governs
Vendor remote supportEquipment and software suppliersStanding remote access, often unmonitoredOpened for an approved request, closed when the window ends
Managed service provider administrationOutsourced IT and security providersPersistent administrative reach across zonesScoped to the systems in the contract, time-bound per engagement
Integration and data exchangePartner platforms and applicationsAlways-on connection between estatesDefined route with checks on what moves and when
Contractor and project accessTemporary staff and implementation teamsGranted at kick-off, removed inconsistentlyExpires with the engagement without needing a manual step
How each window is requested, approved, brokered and recorded is Blueprint territory. What matters here is agreeing that these relationships should be paths with lifetimes rather than standing trust.
04What physical Control changes

The doorway exists only while the work does.

Control does not make supplier access harder to obtain. It makes supplier access impossible to leave open by accident.

Connection state today

Standing supplier access

The path exists permanently and is restrained by credentials, agreements and good intentions.

  • Access continues after the project, the contract or the individual
  • Your exposure follows the supplier's own security posture
  • Reviews happen at audit time rather than continuously
  • Activity records depend on the supplier's tooling
  • Removing access requires someone to remember to do it
Connection state with Control

Time-bound governed access

The path is created for an approved purpose, held open for a defined period and physically removed when that period ends.

  • No standing route from any supplier into the estate
  • Each window tied to a named person and a stated purpose
  • Closure is automatic rather than dependent on memory
  • A clear record of who reached what, and when
  • An answer to the supplier access question that takes minutes, not days
Supply chain risk is not abstract. It is a list of connections you can name.Connected when approved. Disconnected by default.
05The Control philosophy

Control the path, protect the asset.

Control applies the same discipline to relationships that it applies to networks: the connection is the thing being governed, and its resting state is closed.

01

Start with the path, not the tool

Every incident that spreads does so along a connection that was already there. Control begins by naming that connection in plain language, before anyone talks about products.

02

Make the default state disconnected

A path that exists only when it is needed cannot be used at three in the morning by someone who should not have it. Disconnection is the resting state, not the emergency response.

03

Open on approval, close on schedule

When work genuinely needs a connection, Control opens it for a named person, a stated purpose and a fixed period, then closes it again without anyone having to remember.

04

Prove it physically, not on paper

A policy says the path should be closed. Physical control shows that it is. That difference is what auditors, insurers and boards are actually asking about.

How this fits together

Your need sets the direction. Control sets the rule. The Blueprint sets the architecture.

NeedControlBlueprintModules and Firebreak
06Where this goes next

The Blueprint for this need is CP-03 Control Third-Party Access

The Blueprint turns the agreed relationships into a working access pattern, including how requests are checked, how windows are brokered and what the audit trail contains.

CP-03 · Lead layer FIRE+VAULT

Control Third-Party Access

Give third parties access without giving them a permanent doorway.

Modules the Blueprint leads with

Applied to time-bounded vendor and supplier access. The Blueprint page carries the architecture, the zone detail and the deployment sequence.

Why it is worth exploring

What you get from the Blueprint that this page does not cover

  • How a request is validated before any path is created
  • The brokered route that keeps suppliers away from the wider estate
  • How windows are scheduled, extended and revoked
  • The evidence produced for supplier assurance and regulatory review
  • How the pattern scales across dozens of supplier relationships
A different job

This page is about controlling the path a supplier uses. If your concern is protecting the data itself, that is a different job: Offline Secure Storage holds selected copies physically outside the connected environment.

Protect critical data from ransomware
Questions

What procurement and risk teams ask.

The practical questions that decide whether supplier access can be changed without damaging the relationship.

In practice, yes. Suppliers are increasingly uncomfortable holding permanent access to customer estates because it makes them a target. A defined window with a clear record protects both sides.
Need → Control → Blueprint

Name the relationships. Then design the doorway.

CP-03 Control Third-Party Access sets out the validation, brokering and evidence behind access that exists only when it should.