Supplier Access Review
IT providers, software vendors, accountants, marketing agencies and contractors often hold access to business systems long after the work that justified it has finished. A supplier access review lists who can reach your systems, confirms whether they still need to, and checks that the access which remains is protected and logged.
Attackers increasingly reach businesses through their suppliers, because one compromised provider account can open doors into many customers at once. You cannot control a supplier's security, but you can control what their accounts can reach in your systems.
Step 1: List everyone with access
Go wider than the obvious IT provider. Include anyone who can sign in to, administer or remotely connect to something your business relies upon:
- Managed IT provider or IT contractor
- Website developer or hosting company
- Accountant or bookkeeper (accounting software, payroll, banking)
- Marketing agency (website, social media, email platform, analytics)
- Software vendors with remote-support access
- Telephone and printer/copier suppliers
- CCTV, alarm and door-access maintainers
- Former contractors and freelancers
Step 2: Record what each supplier can reach
For each supplier, record the systems they can access, the level of access (user or administrator), the business reason, who approved it and when it was last used.
| Supplier | System | Access Level | Still Needed? | Last Used |
|---|---|---|---|---|
Step 3: Remove what is no longer needed
- Accounts for suppliers you no longer work with have been disabled or removed.
- Access granted for a one-off project has been removed now the project is finished.
- Administrator rights have been reduced to user rights where administration is no longer required.
- Shared passwords known to former suppliers have been changed.
- Remote-access tools installed by previous providers have been uninstalled.
The most dangerous account is the one nobody remembers: a former supplier's administrator login that still works. Removal, not monitoring, is the fix.
Step 4: Protect the access that remains
- Each supplier uses named accounts for their staff, not one shared login.
- Multi-factor authentication is enforced on all supplier accounts.
- Access follows least privilege — enough to do the job and no more.
- Administrative access is time-limited or activated on request where the system supports it.
- Supplier accounts are clearly identifiable (named or tagged as external).
Step 5: Log and document
- Sign-in and administrative activity by supplier accounts is logged.
- Remote-management and remote-support tools in use are documented.
- Contracts state how the supplier protects their access to your systems.
- Contracts require the supplier to tell you about a security incident on their side.
- You know how access will be handed over or removed if you change supplier.
Step 6: Repeat on a schedule
- The review is repeated at least twice a year.
- It is triggered immediately when a supplier relationship ends.
- It is triggered when a supplier reports a security incident.
- One named person owns the review and its follow-up actions.
Goes hand in hand with resilience
Supplier access is one part of the wider resilience picture — incident notification, backups and continuity are covered in our Cyber Resilience Readiness Guide.
Plain-English Takeaway
Suppliers accumulate access; businesses rarely take it back. List who can reach your systems, remove what is no longer needed, protect what remains with named accounts and MFA, and repeat the review on a schedule.
Downloadable guide
Download the Supplier Access Review Checklist
A one-page printable checklist and access register template for reviewing third-party access to your systems.
Download PDFFree download. No email address required.
Related Knowledge Centre resources
Cyber Resilience Readiness Guide
Review your critical systems, IT suppliers, incident response, backups and business-continuity arrangements.
View guideEmployee Leaver Checklist
Close accounts, recover devices and remove access when someone leaves.
Coming SoonCyber Essentials Readiness Checklist
Work through the key controls to review before applying for Cyber Essentials.
View guideDMARC: Three Questions to Ask Your IT Provider
Check whether your business email domain is protected against spoofing and impersonation.
Coming Soon