Join our Newsletter — 33% off our NHI Course

What happens when vendors can access internal systems without session recording or timely deprovisioning?

When session recording and deprovisioning are weak, teams lose the ability to reconstruct incidents quickly and may leave dormant access in place long after it is needed. That increases the chance of unauthorized changes, makes root cause analysis slower, and can extend exposure if a vendor account is abused. The result is higher operational risk and much weaker evidence for investigations.

Why vendor access becomes dangerous without recording and deprovisioning

When a vendor can reach internal systems without a durable session record, you lose the ability to prove what happened, by whom, and in what order. If deprovisioning is also slow, access can outlive the business need and turn into standing exposure. That combination weakens oversight, slows investigations, and creates a clear path for abuse if the vendor account is compromised.

Without session evidence, teams often end up arguing from assumptions instead of logs. Without timely removal, access reviews become stale, and the organisation may continue to trust a vendor relationship that no longer exists in practice.

What failure modes show up first

The earliest failure is usually not a dramatic breach, but a gap in accountability. A vendor may make a configuration change, pull data, or create a new path into the environment and leave little more than system state behind. If access is not promptly removed, dormant credentials can later be used for unauthorised activity long after the original project ended.

This is especially problematic when vendors use privileged accounts, shared accounts, or remote admin paths. Those patterns reduce attribution and make it harder to separate legitimate work from suspicious activity. In practice, the environment becomes easier to modify and harder to reconstruct.

What good control looks like in practice

Strong control combines three things: session recording, timely access removal, and clear ownership of the vendor relationship. Session recording should preserve enough detail to reconstruct commands, changes, and timestamps, while deprovisioning should be tied to contract end dates, ticket closure, or access expiration rather than informal reminders.

For vendors with elevated access, that usually means recorded sessions for privileged activity, narrowly scoped entitlements, and a defined process for revoking access as soon as the work is complete. If the business cannot explain why access remains open, it should be treated as an exception, not the default.

Risk and Threat Considerations

Vendor access without recording and timely deprovisioning creates both accountability risk and abuse risk. The control gap is attractive because it can hide changes, delay detection, and leave a ready-made foothold if vendor credentials are stolen or reused.

Failure mechanism: An attacker or careless insider uses an active vendor account to enter internal systems, performs actions that are not fully recorded, and then relies on delayed deprovisioning to retain access after the work should have ended.

Impact: The organisation may be unable to reconstruct the activity, prove scope, or attribute responsibility quickly, which increases dwell time, complicates containment, and can turn a short-lived access need into persistent exposure.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

OWASP Non-Human Identity Top 10 and MITRE ATT&CK address the attack surface, NIST SP 800-53 Rev 5 and CIS Controls v8 set the technical controls, and ISO/IEC 27001:2022 defines the regulatory obligations.

Framework Control / Reference Relevance
OWASP Non-Human Identity Top 10 NHI-01 — Improper Offboarding Delayed vendor removal leaves access active after work ends.
NHI-02 — Secret Leakage Unrecorded vendor sessions increase the chance of exposed credentials or tokens.
NHI-05 — Overprivileged NHI Vendor accounts often retain excessive access beyond the task scope.
Recommendation — Revoke vendor access immediately when the business need ends. Protect vendor credentials and track any secret exposure. Reduce vendor entitlements to the minimum required privilege.
NIST SP 800-53 Rev 5 AU-12 — Audit Record Generation Session recording depends on generating usable audit evidence.
AC-2 — Account Management Timely deprovisioning is an account lifecycle control.
AC-6 — Least Privilege Vendor access should be constrained to the minimum needed for the task.
Recommendation — Generate audit records for privileged vendor activity. Disable vendor accounts as soon as access is no longer needed. Limit vendor permissions to the smallest viable access set.
CIS Controls v8 CIS-5 — Account Management Vendor access lifecycle and removal are core account-management safeguards.
CIS-8 — Audit Log Management Session recording supports investigation and accountability for vendor actions.
Recommendation — Inventory and remove vendor accounts when access is no longer required. Ensure vendor activity is logged and retained for review.
ISO/IEC 27001:2022 A.5.15 — Access control Vendor access must be granted, reviewed, and removed under access control rules.
Recommendation — Apply controlled access approval and revocation for vendors.
MITRE ATT&CK T1078 — Valid Accounts Compromised vendor accounts are a common abuse path for internal access.
Recommendation — Monitor and rapidly disable valid accounts that no longer need access.

Practitioner Guidance

What to verify: Confirm that every privileged vendor path is either recorded or explicitly exceptioned with compensating controls, and that deprovisioning is tied to an objective trigger such as contract expiry, ticket closure, or access expiry.

Common mistake: Treating vendor access as temporary by intention rather than temporary by enforcement. If the process depends on people remembering to remove access, the control is already weak.

What good looks like: You can answer four questions quickly for any vendor session: who connected, when they connected, what they changed, and when their access was removed.

Practitioner takeaway: The key judgement is not whether vendor access is needed, but whether it remains attributable, reviewable, and revocable for the full time it exists.