TL;DR: Third-party access often remains open after contracts end, and SecurityScorecard argues that offboarding failures create breach risk because teams lose ownership, visibility, and revocation discipline at the point when access should disappear. NHIMG sees this as an identity lifecycle problem, not an administrative cleanup task.
NHIMG editorial — based on content published by SecurityScorecard: Vendor offboarding is the stage most teams skip
By the numbers:
- More than 35.5% of breaches now involve a third party.
- 41.4% of ransomware attacks now carry a third-party nexus.
Questions worth separating out
Q: What breaks when vendor offboarding is not verified?
A: Orphaned access survives.
Q: Why do former vendor credentials increase breach risk after a contract ends?
A: Because the credential still represents trust even when the relationship has ended.
Q: What are the signs that employee offboarding is failing in practice?
A: Common warning signs include still-active sessions after termination, lingering logins on SaaS platforms, missed shared credentials, and unexpected file downloads or configuration changes.
Practitioner guidance
- Build a formal vendor exit workflow Define offboarding as a security-controlled process with named owners across procurement, legal, finance, IT, and security.
- Verify revocation across every identity path Do not rely on a single deprovisioning action.
- Require evidence of data return or deletion For higher-risk vendors, collect written certification that customer data has been securely deleted or returned, and retain that evidence with the termination record and contract artefacts.
What's in the full article
SecurityScorecard's full article covers the operational detail this post intentionally leaves for the source:
- A step-by-step vendor offboarding workflow that maps tasks to procurement, legal, finance, security, and IT.
- The specific access types that must be revoked, including SSO, VPN, API keys, service accounts, physical access, and backup access.
- How continuous monitoring and Internet Intelligence data can confirm whether a former vendor still has an external footprint.
- Contract and evidence considerations for data deletion, retention clauses, and final audit trails.
👉 Read SecurityScorecard's analysis of vendor offboarding and lingering third-party access →
Vendor offboarding: is your third-party access actually closed?
Explore further
Vendor offboarding is an identity lifecycle control, not a procurement afterthought. The business may view termination as contract closure, but the security reality is that identities, secrets, and integrations outlive paperwork. When ownership disperses across teams, the lifecycle breaks at the exact point where revocation discipline matters most. The right frame is not "how do we close the file" but "how do we prove every vendor credential is gone." Practitioner conclusion: offboarding must sit inside IAM and third-party risk governance, not beside it.
A question worth separating out:
Q: How should security teams prove a vendor is truly offboarded?
A: They should require a closed-loop process that confirms access removal, data deletion or return, and post-exit discovery checks. The practical test is whether the vendor can still reach anything after termination. If the answer is not proven with logs, tickets, and system evidence, the exit is not complete.
👉 Read our full editorial: Vendor offboarding gaps are leaving third-party access open