IT Staffing

IT Contractor Onboarding and Offboarding: The Security Checklist

By Tech Ents Team  ยท  December 20, 2024

Share: LinkedIn ๐• / Twitter

The Scope of the Risk

A 2024 survey by CyberArk found that 63% of organisations had experienced a security incident caused by a third-party contractor in the previous 12 months. The most common causes: orphaned accounts after contract end, overly broad access granted during the engagement, and shared credentials that were never rotated after contractor departure.

Onboarding: Least Privilege from Day One

Contractor access should follow the principle of least privilege rigorously โ€” more rigorously than for permanent employees, because the organisational relationship and trust baseline are different.

Onboarding checklist:

During the Engagement

Review contractor access quarterly or on any scope change. Contractors whose project scope has changed often retain access from their previous assignment โ€” clean this up proactively. Log and alert on contractor access to sensitive systems.

Offboarding: The Critical Window

Contractor offboarding is high-risk because it is less emotionally charged than permanent employee departures โ€” it can feel routine and be given less attention. But a contractor with active access who has moved on to a competitor represents the same risk as any other departing employee.

Offboarding checklist:

Automation is the Answer

Manual offboarding fails because it depends on someone remembering to do it. Automate account expiry in Azure AD. Use ServiceNow or your ITSM platform to trigger an offboarding workflow when a contract end date is reached. Make the process systematic, not heroic.

# IT Staffing
← Older post
On-Prem vs Cloud: A Practical Decision Framework for 2025
Newer post →
PowerShell Automation for IT Administrators: From Scripts to Reliable Tooling
← Back to all posts