CIO Brief: IoT and SaaS Admin Access — The Overlooked Privilege
Retrospective: this article looks back at events from March 2021, written in 2026 with the benefit of hindsight.
The short version: In 2021, hackers accessed about 150,000 security cameras — in hospitals, schools and factories — by finding a single "super admin" password at the camera company, Verkada. Your vendors' internal access to your data and devices is part of your risk.
Why vendor admin access matters
Many SaaS and IoT platforms let vendor staff access customer environments for support. That's convenient — until a vendor admin account is compromised. Then one stolen credential reaches every customer.
The business impact
- Privacy and safety exposure from cameras, access control and building systems.
- Data exposure from any SaaS platform with broad vendor access.
- Regulatory consequences — the FTC later penalized Verkada over its security failures.
Questions to ask your team and vendors
- Can vendor employees access our data or devices without our approval?
- Is that access logged, and can we see the logs?
- How do vendors protect their own admin accounts?
- Are our security cameras, door systems and other IoT platforms managed with the same rigor as our IT systems?
What good looks like
Vendor access only with your approval, time-limited and logged; vendors able to demonstrate strong protection of privileged accounts; IoT platforms included in security reviews.
The decision
Add "how do your employees access our data?" to every SaaS and IoT vendor review. The answer tells you a great deal about your real exposure.
- Verkada Camera Breach (Mar 2021): A Super Admin Credential Left Exposed Incident Teardowns
- How to Find and Vault Hardcoded Credentials Across Cloud Services How-To & Hardening
- Detecting Exposed Super Admin Credentials: Sentinel and GuardDuty Detections Detection & Response