forumNew topic

Freelancers and external staff access the system remotely, it's hard to control them, what are the risks?

HHasan K***Member
Job title
Sales Manager
Sector
Healthcare services
Organization type
chain store
Joined
Sep 2024
Message
404
#1

We work with an external firm for software development. They access via VPN. I can't tell who did what.

EEsra S***MemberCommunity member
Joined
Jan 2026
Message
367
Most Helpful#2

For external staff: VPN + MFA + Audit Logging are mandatory. Need a written SOP. Reports should be reviewed regularly. The contract should state the access termination date.

BBeyza B***MemberCommunity member
Joined
Jul 2025
Message
254
#3

we're not the boss of the external team either... btw we enabled VPN + audit logging, i feel a bit safer now

edit: typed from phone, sorry for typos.

HHüseyin Z***MemberCommunity member
Joined
Mar 2023
Message
76
#4

protocol: 1. vPN mandatory 2. mFA required 3. weekly audit log review 4. i mean end date specified in contract 5. revoke access afterwards

ZZafer A***Member
Job title
Secretary
Sector
Jewelry
Organization type
20-person company
Joined
Nov 2024
Message
142
#5

Enable audit trail on the Linux server (auditd). Log all commands so you can see who did what.

LLevent E***Member
Job title
Warehouse Manager
Sector
Healthcare services
Organization type
120-person company
Joined
Jul 2024
Message
108
#6

Don't miss this: Taking notes for two weeks yields better results than a six-month estimate.

BBurcu A***MemberCommunity member
Joined
May 2024
Message
146
#7

It's rare to find an explanation this clear.

PPolat E***Member
Job title
Technical service technician
Sector
Agriculture
Organization type
cooperative
Joined
Mar 2024
Message
273
#8

Thanks, this was very helpful. If 2FA is on, a stolen password alone is useless.

Security isn't absolute; it's about making attacks not worth the effort.

MMetin K***Member
Job title
Export manager
Sector
Paper
Organization type
300-person organization
Joined
Nov 2023
Message
19
#9

I felt relieved reading this answer, so it's not just me. The real issue isn't the number, but what it's based on.

Don't rely on a single measure; go layer by layer. If you post the result here, it will help others too.

DDamla Ç***MemberCommunity member
Joined
Nov 2023
Message
199
#10

i went through the same thing.

GGürkan K***Member
Job title
Human Resources Specialist
Sector
Catering
Organization type
120-person company
Joined
Dec 2024
Message
157
#11

I don't think this advice fits everyone. The harder it is to reverse a decision, the slower you should make it.

Just leaving this note, it might be useful.

BBurak Can M***Veteran
Job title
Founder · e-commerce
Organization type
20-person company
Joined
Apr 2023
Message
212
#12

My question might sound amateurish, sorry about that. Mistakes made on the external staff access side are usually reversible but expensive.

AAleyna S***Member
Job title
Export manager
Sector
E-commerce
Organization type
medium-sized business
Joined
Aug 2024
Message
3
#13

I agree, and I'd like to emphasize that. Just because everyone does it doesn't mean it's right.

NNuri G***Member
Job title
Call center representative
Sector
Cosmetics
Organization type
boutique agency
Joined
May 2024
Message
177

Doki · Brand identity · 2026

#14

Im curious too. Any unwritten clause becomes a point of disagreement later, as both sides remember it differently.

LLeylaMember
Job title
Purchasing
Joined
Apr 2024
Message
86
#15

Thanks for writing this, that's the right way. The harder it is to reverse a decision, the slower you should make it.

When we decide without measuring, we always end up in the same place.

RRecep K***Member
Job title
Customer service representative
Sector
Leather
Organization type
family business
Joined
May 2024
Message
1
#16

Timely topic.

HHakan B***Expert
Job title
Human Resources Specialist
Sector
Plastic
Organization type
early-stage startup
Joined
Jan 2026
Message
409
#17

I was thinking the same thing. If you scold false alarms, nobody will report again.

VVolkan U***MemberCommunity member
Joined
Feb 2024
Message
56
#18

I've been down this road, let me tell you. Everything goes well for the first three months; problems arise in the fourth.

If you have questions, write them; I'll answer as best I can.

HHakan Y***Member
Job title
Production planning
Sector
Seafood
Organization type
20-person company
Joined
Sep 2022
Message
42
#19

If you're going this route, sort this out first. Solutions that work at a small scale collapse when you grow; I learned this late.

An automated scan report is not the same as a penetration test. That's all, sorry if I went on too long.

KKadriyeMember
Job title
Ceramics workshop
Joined
Jun 2024
Message
72
#20

Ive been down this road, let me tell you. Most incidents start with a leaked password, not a vulnerability.

If I were you, I'd go this route.

Reply