Recently, a few clients have asked us about our security concernswhen allowing non-employees, e.g., contractors, access to sensitive internal data.
If you haven’t already read our blog post on why we callyour staff users (who hasn’t?), please do. In it, I make the case thatwe call your computer-using staff users because they are users of yournetwork and data. You could have employees who don’t use computers andcontractors who do; their employment status – whether they are employeesor contractors – is not germane to discussions about to whom a business allowsaccess to its data.
We can extend the same logic to the question of giving contractorsaccess to your data.
When business owners think about their employees, they thinkabout staff to whom they’ve issued a computer. Because this device entered theorg as a new-in-box device and all the desired security settings are enforced,we can be confident that this computer is secure. However, any device’ssecurity is up for debate and is context-dependent, so let’s call these manageddevices – devices that the business controls.
A business might enforce computer security settings that mitigate:
- Data leakage by preventing users from copyingfiles to flash drives or emailing sensitive data
- Unauthorized access by enforcing strongcomputer passwords and two-factor authentication
- Software vulnerabilities by enforcing aggressiveoperating system and third-party software updates
- Malware propagation and users’ ability toundo security measures.
These are all great security measures that every businessshould adopt. But if you’re allowing anyone to access your sensitive companydata – files, email, etc., with a computer on which these settings are not enforced– an unmanaged computer, e.g., a contractor’s personal laptop, then you have ahuge blind spot.
Let’s consider the worst-case scenario: the contractor’slaptop has keylogging malware, no security software, its disk is not encrypted,and no password at the login screen, so if it falls out of their control,whoever finds it can log in to your company’s email and file-sharing accounts andsiphon all of your data. Bad all around. Not only are you breached, but your insurerwill deny your cybersecurity claim because the controls you told your insureryou were using were, in fact, not in use.
But perhaps the contractor promises that they have anti-malwaresoftware, a 48-character password, and a 10-second lock screen time-out ontheir computer. That’s great! But since it’s their computer - not yours, youcan’t guarantee that any of this will be present tomorrow; the contractor isfree to reduce the security controls on their computer at any time.
So, here’s what I’m getting at: you must always “assume breach”. That is, you must always assume that every computer outside of your business’s control is not only not secured, but actively breached, and then work backward.
How would you react if someone you trust asked you to givethem access to your data on a laptop they brought back from North Korea? Denyingtheir request wouldn’t be judging the character of the person, but the contentsof their laptop.
If you want to ensure that your contractors’ personalcomputers aren’t a security blind spot, you must stop thinking about the employmentstatus of the person and start thinking about the security postureof their devices.
This might be a hard pill to swallow, but if you care about the sanctity of your crown jewels, you must issue managed laptops to your contractors,and better still, restrict access to your resources to those managed devices.
“But Nate, we just can’t afford to buy every contractor a newlaptop!”
I hear you – it’s a business decision that only a businessowner can weigh, and I’ll stay out of the finance side of your business, butthere are inexpensive solutions, including:
1. Buying used laptops that we erase and set uplike new computers, thereby bringing them into compliance with your security requirements.
2. Creating Windows virtual machines in MicrosoftAzure that your contractors can remote into and work from there.
That said, no two businesses have identical security needsor finances, but every business should be aware of its cybersecurity blindspots.