Verizon's 2025 Data Breach Investigations Report — which analyzed more than 22,000 security incidents across 139 countries — found an alarming number: third-party involvement in data breaches doubled, from 15% to 30% in a single year. Vendors, contractors, consultants and partners now show up in one out of every three confirmed breaches.

The problem isn't new in theory. Companies have known for years that third-party access is a risk. What changed is the scale. Tens of thousands of consultants, agencies, integrators and partners access critical systems every day — and most still log in with a shared password, no exit date, no way to know who else is using that account, and no trail of where the access came from.

In May 2024, a company called Snowflake discovered that 165 of its customers had been breached. Not because of a software flaw. Because of stolen employee credentials — passwords captured by malware on the customers' own personal devices. How? Because nobody required two-factor authentication. How did nobody notice the access happening? Because there was no audit trail. And how long had the credentials been circulating? Some hackers used stolen passwords 4 years old, never rotated.

The vendor who signs in and never leaves

When an outside consultant arrives to run a 3-month project, what usually happens?

The company sets up an account for them — corporate email, VPN, database access, access to the shared project folder. The consultant logs in with their own password, or the password gets shared ("here's the team's password"). The project ends. Nobody deactivates the account. The person leaves the company and the account stays. As the company grows, so does the number of these accounts — the 3-month engagement turns into a 3-year one (the same consultant, renewed), the integrator does semiannual maintenance, the technology partner keeps permanent access for support.

SecurityScorecard's 2025 report found that 35.5% of breaches originate from third-party vectors. When those breaches start with a stolen credential, the problem is twofold: the company doesn't know the access is happening, and the hacker uses the credential as if they were a real employee.

The Snowflake case has a specific detail that applies to consulting, agencies and software-as-a-service alike: the 165 affected customers were not using two-factor authentication. Stealing the password was enough. And it wasn't just any password — it was the credential of an employee at the customer's own company, captured months or years earlier by spyware. The hacker didn't even need to look out of place logging in: they came in with a real employee's identity, as if they were that person.

The cost backs up the urgency. According to IBM's Cost of a Data Breach Report 2025, breaches that start with a vendor or supply-chain compromise cost organizations an average of $4.91 million — the second most expensive attack vector in the study, behind only phishing. That's not an abstract number: it's the kind of bill that shows up months later, once nobody remembers that a third party's access was still open.

The same pattern repeats at Brazilian and Latin American companies that outsource payroll, IT support or parts of accounting. It's common for an outsourced accounting firm to get access to the financial system for month-end close and keep that same login active months later, with no pending task to justify it. Nobody decides to leave the access open out of bad faith — at some point, nobody simply decides to close it.

Why the obvious restrictions don't work

Why the obvious restrictions don't work

"Let's create a policy banning password sharing" — the company sets it, announces it, repeats it in meetings. Three months later, a new integration project comes in, the integrator needs to access the production database to debug something urgent, and the manager hands over the password of a user who already has access. The policy exists. Reality is different.

"Let's force a password change every 90 days" — the company rolls it out. The problem: the consultant who uses that account weekly is fine with it; the one who logs in once a year forgets the password and requests a reset; nobody knows how many people actually have that password.

The third issue: without an audit trail, nobody knows what the third party actually looked at. What did the consultant see? How long were they inside the system? What reports did they run? If there's an investigation after an incident, that information is gone.

A recent study puts a number on the scale of the problem: Imprivata's 2025 research found that 47% of organizations experienced a data breach or cyberattack in the past 12 months involving third-party network access — nearly half, not an isolated minority. The same study explains why manual review doesn't keep up: IT and security teams spend an average of 134 hours a week analyzing and investigating the security of that access, roughly the equivalent of three full-time people just checking a spreadsheet of who still has an active password. Even with that effort, most companies surveyed don't have a complete inventory of who can access what.

What has to be in place

Personal identity for every third party. Never a shared login. Every person — employee or contractor — accesses the system with their own identity, never shared with anyone else. If someone's credential leaks, deactivating that one account blocks the access — without affecting anyone else using the system. Auditing becomes possible: when someone spends an unusual amount of time inside the system, you know exactly who it was.

Access scoped to the project and the role. The consultant implementing system X doesn't need to see HR databases or sales reports. If a tool has 50 features, they get the 3 they actually need — not the whole tool just because it's easier to hand over.

Defined validity, with automatic expiration. Third-party access lasts as long as the project does, no longer. An integrator hired for 3 months gets 3 months of access — after 90 days, the credential expires automatically, with nobody needing to remember to deactivate the account. If the project runs longer, the manager renews it; if it ends, the access is history.

Prior approval based on risk. Someone on the team has to authorize that specific third party for that specific access to that specific system. Creating a third-party account isn't an automatic IT task — it's a documented decision made by whoever owns that project.

A complete audit trail. Who accessed what, when, for how long, and which data they viewed. Not in a generic monthly report — in a log you can query whenever you need to.

That is how Skyller was designed: every person has their own identity, access matched to their role, and approval and logging recorded automatically — producing the audit trail most integrations lack.

The payoff is threefold

The payoff is threefold

Security is the obvious win. A stolen credential becomes useless the moment the access window expires. Without shared logins, one stolen password only affects one person. With a complete audit trail, you find out in days — not months — that something odd happened.

But there's a gain that usually settles the internal debate: compliance. Data protection regulations such as Brazil's LGPD require that sensitive data be accessible only to those with a genuine need to know. Any regulator will ask: who has access? For how long? Is there an audit trail? If the answer is "shared passwords, and we don't know," a fine is just a matter of time. With personal identity, defined validity and a full trail, the answer is ready.

The third gain is operational. When a new consultant joins, you don't lose 2 days manually setting up accounts or waiting for them to receive 4 different emails. With automatic provisioning, they're in the system within minutes, already holding the access they need — and already carrying an exit date.

That recovered time matters more than it sounds. If teams spend an average of 134 hours a week manually reviewing third-party access — per the same Imprivata research — automating validity and permissions frees up part of those hours for decisions that actually require human judgment, not for checking a spreadsheet of who still has an active password.

Three questions for your next meeting

  1. If a consultant is let go today, how many tools can they still log into tomorrow? If the answer depends on someone remembering to revoke access, the risk is already there. With an expiration date, you don't depend on memory.

  2. When a third party accesses sensitive data, can you say, days later, exactly what they looked at and for how long? If there's no audit trail, the answer is no. Without a trail, there's no compliance.

  3. How many third-party accounts do you have active right now without knowing exactly why? Most companies don't know. That's the number that should worry you.

Try Skyller for free