- Job title
- Sales Manager
- Sector
- Healthcare services
- Organization type
- chain store
- Joined
- Sep 2024
- Message
- 404
We work with an external firm for software development. They access via VPN. I can't tell who did what.
We work with an external firm for software development. They access via VPN. I can't tell who did what.
For external staff: VPN + MFA + Audit Logging are mandatory. Need a written SOP. Reports should be reviewed regularly. The contract should state the access termination date.
we're not the boss of the external team either... btw we enabled VPN + audit logging, i feel a bit safer now
edit: typed from phone, sorry for typos.
protocol: 1. vPN mandatory 2. mFA required 3. weekly audit log review 4. i mean end date specified in contract 5. revoke access afterwards
Thanks, this was very helpful. If 2FA is on, a stolen password alone is useless.
Security isn't absolute; it's about making attacks not worth the effort.
I felt relieved reading this answer, so it's not just me. The real issue isn't the number, but what it's based on.
Don't rely on a single measure; go layer by layer. If you post the result here, it will help others too.
I don't think this advice fits everyone. The harder it is to reverse a decision, the slower you should make it.
Just leaving this note, it might be useful.
My question might sound amateurish, sorry about that. Mistakes made on the external staff access side are usually reversible but expensive.
Doki · Brand identity · 2026
Im curious too. Any unwritten clause becomes a point of disagreement later, as both sides remember it differently.
Thanks for writing this, that's the right way. The harder it is to reverse a decision, the slower you should make it.
When we decide without measuring, we always end up in the same place.
I've been down this road, let me tell you. Everything goes well for the first three months; problems arise in the fourth.
If you have questions, write them; I'll answer as best I can.
If you're going this route, sort this out first. Solutions that work at a small scale collapse when you grow; I learned this late.
An automated scan report is not the same as a penetration test. That's all, sorry if I went on too long.
Ive been down this road, let me tell you. Most incidents start with a leaked password, not a vulnerability.
If I were you, I'd go this route.