Employees, contractors, and data security

IT Security
Nate Work
3
min

Employees, contractors, and data security

Share on:
Nate Work
on
August 10, 2026

Recently, a few clients have asked us about our security concerns when allowing non-employees, e.g., contractors, access to sensitive internal data.

If you haven’t already read our blog post on why we call your staff users (who hasn’t?), please do. In it, I make the case that we call your computer-using staff users because they are users of your network and data. You could have employees who don’t use computers and contractors who do; their employment status – whether they are employees or contractors – is not germane to discussions about to whom a business allows access to its data.

We can extend the same logic to the question of giving contractors access to your data.

When business owners think about their employees, they think about staff to whom they’ve issued a computer. Because this device entered the org as a new-in-box device and all the desired security settings are enforced,we can be confident that this computer is secure. However, any device’s security is up for debate and is context-dependent, so let’s call these managed devices – devices that the business controls.

A business might enforce computer security settings that mitigate:

-             Data leakage by preventing users from copying files to flash drives or emailing sensitive data

-             Unauthorized access by enforcing strong computer passwords and two-factor authentication

-             Software vulnerabilities by enforcing aggressive operating system and third-party software updates

-             Malware propagation and users’ ability to undo security measures.

These are all great security measures that every business should adopt. But if you’re allowing anyone to access your sensitive company data – files, email, etc., with a computer on which these settings are not enforced– an unmanaged computer, e.g., a contractor’s personal laptop, then you have a huge blind spot.

Let’s consider the worst-case scenario: the contractor’s laptop has keylogging malware, no security software, its disk is not encrypted,and no password at the login screen, so if it falls out of their control,whoever finds it can log in to your company’s email and file-sharing accounts and siphon all of your data. Bad all around. Not only are you breached, but your insurer will deny your cybersecurity claim because the controls you told your insurer you were using were, in fact, not in use.

But perhaps the contractor promises that they have anti-malware software, a 48-character password, and a 10-second lock screen time-out on their computer. That’s great! But since it’s their computer - not yours, you can’t guarantee that any of this will be present tomorrow; the contractor is free to reduce the security controls on their computer at any time.

So, here’s what I’m getting at: you must always “assume breach”. That is, you must always assume that every computer outside of your business’s control is not only not secured, but actively breached, and then work backward.

How would you react if someone you trust asked you to give them access to your data on a laptop they brought back from North Korea? Denying their request wouldn’t be judging the character of the person, but the contents of their laptop.

If you want to ensure that your contractors’ personal computers aren’t a security blind spot, you must stop thinking about the employment status of the person and start thinking about the security posture of their devices.

This might be a hard pill to swallow, but if you care about the sanctity of your crown jewels, you must issue managed laptops to your contractors,and better still, restrict access to your resources to those managed devices.

“But Nate, we just can’t afford to buy every contractor a new laptop!”

I hear you – it’s a business decision that only a business owner can weigh, and I’ll stay out of the finance side of your business, butthere are inexpensive solutions, including:

1.       Buying used laptops that we erase and set up like new computers, thereby bringing them into compliance with your security requirements.

2.       Creating Windows virtual machines in Microsoft Azure that your contractors can remote into and work from there.

That said, no two businesses have identical security needsor finances, but every business should be aware of its cybersecurity blind spots.

‍

Share on:
Contractors vs. Employees vis-à-vis network security
arrow button

Featured Articles

See all articles
See all articles