Per Verizon's 2026 report on data breaches, breaches involving a vendor or partner grew 60% in a single year and now account for 48% of the total recorded worldwide — nearly half. This is not usually a vendor breaking in on its own: in most cases, it is the door the company itself left open for the vendor, used by someone else instead.
Every business has vendors with network access, and that's normal: the management system's support team logs in remotely to close a ticket, the accounting firm receives a full data export every month, the camera or monitoring company leaves a device plugged into the same network as everyone's computers. None of these accesses is a mistake by itself — the mistake is not knowing, today, how many there are, what each one reaches, and since when that password hasn't changed.
For the person who approves the IT budget, this is the most common blind spot: a company can have antivirus, a firewall and a trained team, and still have a key to its own network sitting with another company — no contract stating what it can reach, no time limit on that access, no log of when it was last used.
Who holds a key without you noticing
The list is usually longer than it looks once someone actually counts: the management system or ERP, with direct remote access to the server for support; the accounting firm, which receives full exports of the financial database; the camera or monitoring company, with a device plugged into the same network as the computers; the payroll provider; and, often, the previous IT provider, whose credentials nobody remembered to disable once the contract ended.
Per the European Union Agency for Cybersecurity's Threat Landscape 2025, 10.6% of the threat categories mapped in the period arrived through indirect paths — attacks that exploit a company's vendors and other dependencies rather than targeting it directly. It's a smaller share than phishing or malware, but it's growing because it's an easier route: instead of attacking a company with organized defenses, the attacker targets the weaker-defended vendor and walks in through the door that vendor left open.
A 2026 Sophos survey of IT teams across 17 countries points the same way: the most common entry point in a ransomware attack was an internet-exposed system or application (38% of cases), ahead of a user's device (30%) and network equipment (21%). Remote-support tools, system admin panels, and open connections kept for vendors fall exactly into that category — infrastructure built to make it easier for outsiders to work also makes it easier for the wrong outsider to get in.
The problem isn't the number of vendors. It's the lack of a simple inventory: who has access, to what, since when, and whether that access still makes sense today.
Why trust doesn't replace control
The common approach to vendors is to trust them and never review it again. The management system's password has been the same since it was installed. Remote access stays open all year, not just during the ticket. Nobody wrote down, in a contract, what that vendor can and can't reach inside the network.
Much of the confusion comes from a mistaken idea: if the problem happened on the vendor's side, it's the vendor's problem. Data protection law doesn't see it that way. Per guidance from Brazil's National Data Protection Authority, whoever processes data on a company's behalf — the so-called processor — is only required to notify the hiring company without undue delay once it discovers an incident. The legal duty to notify the affected people and the authority itself, within a three-business-day window, falls on whoever hired the service. The vendor makes the mistake; the bill and the deadline land on the company that owns the data.
That changes the question worth asking. It isn't "is this vendor trustworthy" — it probably is. It's "if something goes wrong on their end, can my company prove what they had access to and when that access stopped." Without that record, responding to an incident turns into reconstructing memory under pressure, racing against a legal deadline that has already started ticking.
What has to be in place
Working safely with vendors doesn't depend on distrusting them. It depends on mechanisms that work the same way no matter who is on the other side of the screen.
Access with a set time limit, not a standing one. The vendor gets in during the service call and the door closes on its own afterward — it doesn't stay open waiting for the next ticket, months later.
One individual login per vendor, never a shared generic password. Each company accessing the network has its own credential, which can be changed or turned off without touching anyone else's.
A second confirmation step beyond the password, for outsiders too. The same rule that applies to an employee applies to a vendor — the password alone is never enough.
A log of who entered, when and where. This isn't about distrust: it's what lets a company prove, after an incident, what actually happened, instead of reconstructing it from memory.
Every vendor reaching only what it needs. The camera company doesn't wander into the finance network; the accounting firm doesn't reach the sales team's file server.
A periodic review of who still has access. The provider whose contract ended two years ago and whose password was never turned off is the easiest door to find — and nobody looks for it until it's too late.
This is how Skills IT works: vendor access with a set time limit, individual logins, and a log of who entered and where, reviewed before it turns into something forgotten.
What changes when access is controlled
The payoff shows up first under pressure. When a vendor reports an incident — and that happens even with a reputable vendor — a company with an inventory and a log knows within minutes what that access reached and can cut it off right away. A company without that control spends days figuring out whether the problem reached it at all.
The second payoff is for whoever makes the budget call: with a set time limit and scope defined per vendor, every contract renewal already comes with the right question — is this access still needed, the way it stands? — instead of renewing an untouched access out of habit.
There's also a direct legal payoff. When an audit, a larger client or the authority itself asks who had access to a given piece of data, the answer already exists in a report instead of depending on someone's memory. That shortens the time between the question and the answer — and, if something has already gone wrong, it also shortens the time until the company can act, instead of spending the first few days just understanding its own environment.
None of this promises zero incidents. What changes is the size of the damage when a vendor — yours or another company's, further down the same chain — turns out to be the weak link.
Three questions to bring to the next meeting
Before signing the next vendor contract, it's worth asking what already exists today:
- How many vendors have access to our network right now, and does anyone have that list written down? If the answer is "not sure," the list is probably longer than anyone's memory.
- Is any of that access standing, open all year, instead of only during the service call? Every standing access is a door left up even when nobody is using it.
- If a vendor reported an incident today, how long would it take to know what it could reach on our network? If the answer isn't minutes, that's the first thing to fix before the next contract.





