IT Vendor Staff Vetting: 4 Questions Every CEO Should Ask Before Handing Over Access
You evaluate contracts, check references, maybe request a sample report. But almost no vendor evaluation ever reaches the most uncomfortable question: who, exactly, is the person sitting inside your network right now – and what do you actually know about them? The technician with administrative access to your file servers, your email system, and your backup infrastructure is a risk surface that most IT vendor evaluations never examine. It should be the first thing you examine.
- Why the Technician Is Your Real Attack Surface
- Question 1: What Does Your Pre-Hire Screening Actually Cover?
- Question 2: How Are Technical Credentials Verified and Kept Current?
- Question 3: How Do You Control and Monitor What Your Own Staff Can Access?
- Question 4: What Happens When a Technician Leaves Your Firm?
- Red Flags That Should End the Conversation
- What a Good Answer Looks Like
- How to Use This in a Real Vendor Decision
Why IT Vendor Staff Vetting Starts With the Technician – Your Real Attack Surface
Most IT vendor conversations orbit around technology: what tools they use, how fast they respond, whether they have a security operations function. These are real considerations. But the technology stack your IT firm uses is only as trustworthy as the people operating it.
Consider what administrative access actually means. A technician with full administrative rights to your environment can read your files, access your email, modify your backup schedules, create new user accounts, and in many cases exfiltrate data without triggering an obvious alert. That is not a flaw in the arrangement – it is a requirement of the job. Someone has to hold those keys.
The question is not whether your IT firm’s staff have that access. They have to. The question is what your vendor has done to make sure the people holding those keys are the right people – properly trained, properly supervised, and properly removed when they leave.
According to the Cybersecurity and Infrastructure Security Agency (CISA), insider threats – including negligent employees and malicious insiders at vendors and contractors – represent one of the most underreported categories of security incidents. The risk is not theoretical. It is statistically consistent, and it lives inside the trust relationship you have already established with your IT provider.
Here are the four questions worth asking before you sign another contract – or before you decide whether to stay with the one you have.
Question 1: What Does Your Pre-Hire Screening Actually Cover?

Start here. Every reputable IT firm will tell you they run background checks. The follow-up is what separates real programs from checkbox compliance.
A meaningful answer includes specifics: criminal history at the county, state, and federal level; identity verification; employment history confirmation; reference checks that actually happened; and for roles involving financial system access or sensitive regulated data, a credit history review. Some firms also run sex offender registry checks for staff who visit client sites.
What you are listening for is process, not policy. “We run background checks” is a policy statement. A process answer sounds like: “Every offer is contingent on a completed background check through [a named provider], we re-screen annually, and any felony conviction is an automatic disqualifying event.” The difference between those two answers is the difference between a written policy that sits in a folder and an operating standard that actually governs hiring decisions.
Ask a follow-up: “What would disqualify a candidate?” A firm with a real program answers without hesitation. A firm running checkbox compliance gives you something vague about reviewing things “on a case-by-case basis.”
Red flag: any answer where background checks happen but the criteria are never defined or applied consistently. Rigorous IT vendor staff vetting at the hiring stage is the foundation everything else rests on.
Question 2: How Are Technical Credentials Verified and Kept Current?
This question has two parts, and both matter.
The first is verification. When a technician claims a certification – a security credential, a vendor-specific qualification, a compliance-related designation – does your IT firm actually verify it? Credential fraud in technical fields is more common than most hiring managers want to admit. A legitimate firm confirms that certifications are real and currently active, not expired copies of something earned five years ago.
The second is currency. Technology changes. Threats evolve. A certification earned in 2019 with no continuing education behind it represents a snapshot of knowledge that may no longer apply to your environment. Ask your IT vendor whether staff are required to maintain continuing education, whether certifications have expiration dates and what happens when they lapse, and whether the firm has a documented training plan and budget for technical staff.
You are not auditing their curriculum. You are checking whether staff development is a managed process or an afterthought. A firm that cannot tell you how they keep their technicians current is a firm whose technicians may be working from outdated mental models when something goes wrong in your environment.
Strong IT firms tie training to specific roles and to the technologies those staff are responsible for managing. If a technician holds administrative access to a cloud platform, they should hold a current credential or documented training record for that platform – not a general IT certification from years ago. This is one of the most overlooked dimensions of serious IT vendor staff vetting.
Question 3: How Do You Control and Monitor What Your Own Staff Can Access?
This is the most technically specific question on the list, and the one most vendors will be least prepared for. That gap in preparation is itself informative.
What you want to understand is whether your IT firm applies the same security discipline to their own internal environment that they claim to apply to yours. Specifically, you are asking about privileged access management – granting elevated permissions only when needed, logging what happens during those sessions, and revoking access automatically when a session ends.
A mature firm will tell you that technicians do not hold standing administrative access to client environments around the clock. Elevated permissions are granted for specific tasks, then removed. Every action taken with those permissions is logged and reviewable. No technician has access to a client environment they are not actively assigned to support.
Ask whether the firm conducts internal access reviews – periodic audits of who has access to what, and whether that access still fits the technician’s current role. People change roles. People get moved to different client accounts. Without regular access reviews, permissions accumulate and create exposure.
Ask specifically: “If I wanted to see a log of what actions your technicians have taken inside my environment over the last 30 days, could you produce that?” A firm with proper logging says yes without hesitation. That capability matters enormously when something goes wrong.
For a detailed picture of what access controls should look like in practice, the NIST Cybersecurity Framework covers access management under its Protect function – a useful benchmark for what your vendor should be meeting.
Question 4: What Happens When a Technician Leaves Your Firm?
Staff turnover at IT firms is real. When technicians move on, their access needs to move with them – out the door, immediately.
This question is about offboarding rigor. When a technician leaves your IT vendor, what is the documented process for removing their access? How quickly does it happen? Who owns the confirmation? And critically: does the process cover access to client environments, or only internal company systems?
This is not hypothetical. A technician who leaves an IT firm may retain access to client environments for days or weeks if the offboarding process is manual, informal, or inconsistently applied. That window is a real exposure, and it is exactly what sound IT vendor staff vetting protocols are designed to close.
A firm with a mature offboarding process can walk you through it step by step: on the day of separation, all accounts are disabled, client environment access is revoked, and a confirmation review happens within a defined window – typically 24 hours. Some firms automate parts of this process to remove human error from the equation entirely.
Ask a pointed follow-up: “Has a technician ever left your firm and retained client environment access longer than 24 hours – and if so, what did you learn from that?” A firm that has genuinely examined this question gives you a direct answer. A firm that has not will get uncomfortable, and that discomfort is data.
Red Flags That Should End the Conversation
Some answers are not just unsatisfying – they signal a fundamental lack of internal security maturity. Watch for these:
- Inability to name the background check provider or describe screening criteria in specific terms
- Certifications listed on a website that cannot be verified or that turn out to be expired
- No documented process for granting or revoking technician access to client environments
- No ability to produce access logs or session records for work done inside your environment
- Vague or defensive answers to the offboarding question
- A posture of mild offense at being asked – any firm that treats these questions as an insult rather than reasonable due diligence is not a firm you want holding your administrative keys
Any one of these signals should prompt deeper scrutiny. Multiple signals together indicate that IT vendor staff vetting is not a functioning discipline at that firm – regardless of what their sales materials claim.
What a Good Answer Looks Like
A firm that takes internal staff risk seriously answers these questions without hesitation and with specificity. They have named processes, named providers, and documented standards. They can show you evidence – a sample access log, a training record format, a written offboarding checklist – rather than describing policies that may exist only on paper.
The strongest firms hold themselves to roughly the same scrutiny they apply to your environment. If your managed IT provider is genuinely security-conscious, their internal posture reflects that. They have thought about insider risk. They have built controls around it. They can explain those controls to a non-technical CEO in plain language, without getting defensive.
Firms that have earned independent security audits – not self-attested compliance, but third-party verification against a recognized standard – have demonstrated that their internal controls are real enough to withstand external scrutiny. That is a meaningful differentiator in a category where most vendors are evaluated only on what they say, not what they can prove.
If you want to understand how a rigorous vendor security program connects to a broader cybersecurity strategy for your business, that context matters when you are comparing providers and weighing the depth of their internal controls.
How to Use This in a Real Vendor Decision
Bring these four questions into every vendor evaluation and every annual business review with your current IT firm. They are not gotcha questions – they are reasonable due diligence for a relationship that involves handing someone administrative access to your most sensitive business systems.
The goal is not to catch a vendor in a lie. It is to understand whether the firm you are trusting with your infrastructure has done the internal work that matches the external trust you have placed in them. The firms that have done that work will welcome the questions. The firms that have not will show you exactly why you asked.
If your current IT vendor cannot give you clear, specific, evidence-backed answers to these four questions, that is not a reason for panic – it is a reason for a serious conversation, and possibly a reason to start a more deliberate evaluation of your options. The standard exists. The firms that meet it are not hard to distinguish from the ones that do not, once you know what to ask.
If you want a second opinion on where your current vendor stands – or want to understand what rigorous internal controls actually look like in practice – Book a Free Strategy Call. It’s a 20-minute conversation with our team. No pressure, no obligation.
Want a Walkthrough of Your Own Setup?
Twenty minutes on the phone with our team gets you specific recommendations you can use immediately — whether you hire us or not. No pitch, no pressure, just an honest read on where your business stands.