Privileged vendors deserve privileged controls

A supplier with administrative access should be treated like an administrator, because that is what they are.

Brokered access rather than standing credentials, per-person identity rather than a shared account, time-bound sessions, recording. All of which is normal for internal administrators and rarely applied to external ones, despite the external ones being harder to monitor and easier to compromise.

More on Third-party risk