CIO Brief: Contractors Need the Same Security as Employees
Retrospective: this article looks back at events from September 2022, written in 2026 with the benefit of hindsight.
The short version: In 2022, Uber was breached through a contractor whose password had been stolen and who eventually approved one of many login prompts. Contractors often have similar access to employees but weaker oversight.
Why contractors deserve equal security
Contractors, consultants and temporary staff often:
- Use their own devices, which may be infected with password-stealing malware.
- Are exempt from some security policies "to keep things simple."
- Keep access after their engagement ends.
Attackers know contractor accounts are easier targets.
The business impact
- Full breach starting from a contractor account.
- Access lingering after projects end.
- Unclear accountability when contractors work through third-party firms.
Questions to ask your team
- Do contractors have the same MFA and device requirements as employees?
- Can contractors access company data from personal, unmanaged devices?
- How quickly is contractor access removed when engagements end?
- Do we review contractor access regularly?
What good looks like
The same or stricter sign-in protection for contractors, limited access on unmanaged devices, access with automatic expiration dates, and quarterly reviews.
The decision
Ask for the number of active contractor and guest accounts and how many haven't been used in 90 days. It's a simple metric with an immediate cleanup opportunity.
- Uber Breached via MFA Fatigue (Sept 2022): A Contractor, a Push Storm and Hardcoded Admin Secrets Incident Teardowns
- How to Write Conditional Access Policies for Contractors and Guests How-To & Hardening
- Detecting MFA Push Bombing: Entra Sign-In Logs and Sentinel KQL Detection & Response