Resource
How We Protect Our Own Access to Your Environment
Your IT provider has administrative access to nearly everything you run. That makes the provider's own security part of yours. Before you ask how a provider will secure your environment, ask how it secures its own access to it.
Why this matters
An IT provider manages many businesses through the same set of tools and accounts. That's what makes managed IT efficient, and it's also what makes a provider a target. The remote management tools IT providers use have been used by attackers to reach many client businesses at once. A provider whose own access is weak isn't one weak link. It's a weak link attached to every client it serves.
How we do it
- MFA on everything. Every account our team uses, including the tools we use to reach client environments, requires multi-factor authentication. No exceptions.
- We never subcontract our help desk. Every call and support request is handled by 3rd Element staff, not a third-party or white-label help desk. The only outside party with any access is our security monitoring partner, and its role is limited to detecting and responding to threats.
- Access only from our own devices. Our team works only from company-managed devices. Getting into our management tools takes both an authorized user and an authorized device, so a stolen password on its own gets nowhere.
- When someone leaves, their access leaves with them. Their device is removed and their access is shut off, so there's no path back into our controls. Because access requires both the user and the device, taking either away closes the door.
- A CJIS cleared team. Every member of our staff is CJIS cleared.
Questions to ask any IT provider
- Is MFA required on every account your team uses to reach our systems, including your remote management tools?
- Who actually answers our calls: your own staff, or a subcontracted or white-label help desk?
- Can your technicians reach our environment from personal devices?
- What happens to a technician's access on the day they leave?
- Are your staff background checked?
- If your company were compromised, what stops an attacker from reaching us?
A provider that takes this seriously can answer every one of these specifically. If the answers are vague, that tells you something too.
Common questions
Questions leadership usually asks first.
Continue reading
Related work and reading.
Standards and Security Baseline
The written baseline used across every supported environment.
Read more: Standards and Security BaselineCybersecurity Services
Security built into how IT is managed every day.
Read more: Cybersecurity ServicesIT Provider Vetting Checklist
The questions to ask before signing with an IT provider.
Read more: IT Provider Vetting ChecklistWhat Happens When Your MSP Gets Acquired
What to check when ownership and support begin to change.
Read more: What Happens When Your MSP Gets AcquiredNext step
Get a clearer view of your IT environment.
Want to ask us these questions directly? Schedule an IT Environment Review.
