The connection belongs to the business
This is evergreen guidance, not a response to a new incident. Web agencies, hosting companies, software vendors and managed IT providers often need legitimate access to customer systems. The risk begins when that access is treated as the supplier's private arrangement rather than a business-controlled route into websites, cloud services, data or administrative tools.
The NCSC advises organisations to ensure that access provided to suppliers' people and systems is limited, controlled and monitored. It should be reviewed periodically, removed when no longer required and restricted on a least-privilege basis. The same guidance says connections to supplier systems should not introduce unmanaged vulnerabilities, and that security requirements should form part of normal contracting, including termination and service transfer.
[1]A trusted network is not a sufficient decision
A supplier account may sit behind a VPN, come from a familiar address or have existed for years. None of those facts proves that today's request is appropriate. CISA describes zero trust as making granular, least-privilege access decisions for each request while treating the network as potentially compromised. Its maturity model is written as a roadmap for US federal agencies, not a compliance standard for UK companies, but the access principle is broadly useful.
Applied practically, the decision should consider the named identity, the device or service making the request, the resource being requested and the current business need. A connection that reaches an entire network when the supplier maintains one application creates unnecessary scope. A shared administrator password also weakens accountability: the customer may be unable to tell which individual used it or remove one person's access without disrupting everyone else.
[1][2]What businesses should do
Start with one important website or cloud service. List every supplier account, API credential, support portal, remote-management agent, VPN route and allow-listed network associated with it. Record the supplier, a responsible person inside the business, the systems reachable, the intended purpose and the date access should be reviewed. If nobody can explain an entry, do not assume that age makes it safe; investigate it through the service owner and supplier.
Replace shared human accounts with named identities where the platform permits, require suitably strong authentication and grant the smallest role that supports the contracted task. Separate supplier administration from ordinary user access and from unrelated systems. For occasional work, enable access for an agreed window rather than leaving it permanently available. Service and API credentials need the same ownership, scope and lifecycle discipline even though no person types them into a login page.
Make important use visible. Keep authentication and administrator audit records, alert on unexpected privileged activity and agree how the supplier reports an incident that could affect the service. Test the offboarding route before relying on it: the business should know who can disable the account, revoke credentials and remove connectivity without waiting for the person who originally configured them.
Finally, connect the technical register to procurement and contract changes. The NCSC recommends proportionate minimum requirements, periodic review and clear arrangements for returning or deleting information and assets when a contract ends. A renewal, staff change, completed project or provider exit should therefore trigger an access review, not merely an invoice update.
- Give every supplier route an internal owner and review date.
- Use named identities and the least privilege needed for the task.
- Time-limit occasional access and remove it when work ends.
- Monitor privileged use and retain an attributable audit trail.
- Test how accounts, credentials and connections will be revoked.
The Beekeeper view
Suppliers are not the problem; invisible and indefinite trust is. A competent provider still changes staff, tools and subcontractors, while the customer's systems and contracts evolve around them. Access that was proportionate last year can become excessive without anyone making a fresh decision.
Treat every third-party route like a key issued for a specific job. Label it, limit what it opens, record its use and decide when it comes back. The expiry date is not bureaucracy. It is the point at which temporary trust stops quietly becoming permanent infrastructure.
[1][2]Primary sources
- Supply chain security guidance: II. Establish control — National Cyber Security Centre, 28 January 2018
- Zero Trust Maturity Model — Cybersecurity and Infrastructure Security Agency, 11 April 2023
Beekeeper field notes summarise primary advisories for a UK business audience. Always follow the affected vendor’s current instructions for your exact product and version.