Privileged Access Management: 6 Questions Every CEO Should Ask Their IT Firm
Most CEOs evaluate an IT firm on response times, pricing structure, and service catalog. Almost none of them ask about privileged access management — and that is exactly where the largest, most undisclosed security gap in most IT vendor relationships quietly lives. This discipline governs who holds administrative-level credentials to your systems, how those credentials are stored, and what happens when personnel change. Someone at your IT firm almost certainly holds admin-level access to your systems, your servers, your cloud environment, and possibly your email. Do you know who that person is? Do you know whether those credentials are logged, rotated, or revoked when that person leaves? If the answers aren’t immediately clear, this post is worth your time.
- What Is Privileged Access Management — and Why It Matters to You
- Question 1: Who Specifically Holds Administrative Credentials to My Systems?
- Question 2: How Are Those Credentials Stored and Protected?
- Question 3: Is Every Use of Administrative Access Logged?
- Question 4: What Happens to Credentials When a Technician Leaves?
- Question 5: Do You Use the Principle of Least Privilege?
- Question 6: Have Your Internal Access Controls Ever Been Independently Audited?
- Red Flags to Watch For
- What Good Looks Like
- How to Use This in a Real Vendor Conversation
What Is Privileged Access Management — and Why It Matters to You
When your IT firm manages your environment, some of their technicians operate with elevated permissions — often called “admin” or “administrator” access. These are accounts that can install software, create or delete users, access file systems, and reconfigure security settings. In the wrong hands, a single privileged account can unlock everything. The discipline of controlling those accounts — keeping them monitored and auditable at all times — is what separates a responsible IT partner from a liability.
This is not theoretical. The Cybersecurity and Infrastructure Security Agency (CISA) consistently identifies compromised privileged credentials as one of the most common entry points in serious cyber incidents. The risk isn’t always an outside attacker. Sometimes it’s a technician who still has access after leaving. Sometimes it’s a credential that was never rotated after a vendor employee resigned. Sometimes it’s a shared admin password that a dozen people know and nobody audits.
Your IT firm has more access to your business than almost anyone else you work with. You should understand exactly how they control that access — before you sign a contract, not after an incident.
Question 1: Who Specifically Holds Administrative Credentials to My Systems?

This sounds simple. It rarely is. Many IT firms use shared administrator accounts — one login that multiple technicians use interchangeably. When you ask this question, you’re not just asking for a headcount. You’re asking whether access is individual and traceable, or collective and opaque.
The answer you want: “Each technician has their own named account with individual credentials. We do not use shared admin accounts.” That means if something goes wrong, there is an audit trail pointing to a specific person and a specific action.
The answer that should concern you: “Our team has access” or “whoever is on-call can get in.” Those answers describe a model where accountability is diffuse and traceability is nearly impossible. Push further: can you give me a list of named individuals with admin rights to my environment right now? A firm with mature access controls will produce that list without hesitation.
Question 2: How Are Those Credentials Stored and Protected?
Administrative credentials — the usernames, passwords, certificates, and keys that grant elevated access — need to be stored securely. Many IT firms keep these in a shared spreadsheet, a notes app, or a basic password manager with no access controls. That is a problem.
A mature IT firm uses a dedicated credential vault — a purpose-built system that encrypts credentials, controls who can retrieve them, and logs every retrieval. Think of it as a safe with a combination that rotates automatically and records who opened it and when. This is one of the core technical requirements of any sound privileged access management program.
When you ask this question, listen for specifics. “We use a credential vault” or “we use a privileged access management platform” are good signs. “We use a password manager” might be adequate or completely insufficient — ask whether it tracks who accessed which credentials and when. Vague answers here are a meaningful red flag.
Question 3: Is Every Use of Administrative Access Logged?
Logging is the difference between knowing what happened and guessing. If a technician makes a change to your systems — intentionally or by accident, legitimately or not — you should be able to reconstruct exactly what they did and when.
This question has two parts. First: is privileged access itself logged — meaning, do you record every time someone uses an admin account? Second: are the actions taken during that session logged — meaning, do you record what they actually did once they were in?
A well-run firm will say yes to both. They will also be able to tell you where those logs are stored, how long they’re retained, and whether they live somewhere the technician themselves cannot alter or delete. Logs stored only on the system being administered are not reliable — a bad actor can simply delete them. Complete, tamper-resistant logging is a cornerstone of any credible access control program.
Question 4: What Happens to Credentials When a Technician Leaves?
This is the question most CEOs never think to ask — and it may be the most important one on this list. Staff turnover is normal at every company, including IT firms. What matters is what happens to access rights when someone walks out the door.
A firm without a formal offboarding process will typically revoke the departing technician’s personal login and stop there. But if that technician also knew a shared admin password, had a personal copy of a credential, or set up their own access path during their tenure, none of that gets cleaned up in a standard offboarding. This is one of the most common failures in managing privileged access.
The answer you want: “When a technician leaves, we have a documented offboarding process that includes revoking all individual access, rotating any credentials they had knowledge of, and auditing for any access paths they may have created.” That process should happen the same day the person leaves — not days later.
Ask whether this process is documented and whether it has ever been tested or reviewed by someone outside the IT operations team itself.
Question 5: Do You Use the Principle of Least Privilege?
The principle of least privilege is straightforward: every person and every system should have only the minimum level of access required to do their specific job — nothing more. It is one of the most fundamental concepts in information security, referenced throughout NIST’s security guidance for exactly this reason.
In practice, this means a help desk technician handling password resets should not have the same access as a senior engineer configuring firewalls. Access to your financial systems should be restricted to technicians with a legitimate reason to work there. Access is scoped, not blanket.
Many IT firms — especially smaller ones — grant broad administrative rights to all technicians because it removes friction when someone needs to jump on a ticket. But it also means every person at that firm, including the most junior hire who started last week, can access everything you have. Least privilege is not optional in a sound access management framework. It is the foundation.
Ask how they structure access tiers and whether they can show you which technicians have which levels of access to your specific environment.
Question 6: Have Your Internal Access Controls Ever Been Independently Audited?
An IT firm can tell you anything about how they manage privileged access. What matters is whether any of it has been verified by someone with no stake in the outcome.
Independent audits of an IT provider’s internal security controls are rare — most IT firms have never undergone one. But they exist, and they are the highest form of credibility a firm can offer on this topic. Ask whether the firm has been audited against any recognized security framework and, if so, ask to see the evidence.
At Xact IT, we hold the GTIA Cybersecurity Trustmark, which requires an annual independent audit by Versprite — a CREST-accredited assessor — against the CIS Critical Security Controls at IG2 with supplementary ISO 27001 controls. That audit covers our internal practices, including how we manage admin access across all client environments. It is one of the reasons we can credibly claim zero client breaches across every engagement since 2004. That is not luck. It is the direct result of operating with controls that get tested by people who are paid to find gaps — not to say everything looks fine.
Most IT firms cannot point to anything equivalent. That gap matters.
Red Flags to Watch For
These are the answers — and behaviors — that should make you slow down or walk away entirely:
- The person you’re speaking with doesn’t know the answers and has to “check with the team.”
- They use shared admin accounts across multiple technicians with no individual attribution.
- Credentials are stored in a basic shared password manager with no access logging.
- There is no documented offboarding process for departing technicians, or the process exists only informally.
- All technicians have the same level of access regardless of role or client environment.
- The firm has never undergone any independent audit of their internal security controls.
- They react defensively to these questions rather than engaging them directly — a firm with strong access controls welcomes this conversation.
What Good Looks Like
A well-run IT firm — one that takes the governance of admin credentials seriously — will have clear, documented answers to every question above before you finish asking. They will name the specific platform they use to vault credentials, describe how their access tiers are structured, walk you through their offboarding checklist, and point to evidence that their internal practices have been independently verified.
They will not be defensive. They will be precise. The firms that have built these controls know the value of them — they’ve invested in building them, and they’re glad to discuss it because almost no one else in their competitive set can say the same.
This is also a reliable signal about the kind of partner they will be overall. A firm that manages its own internal access carelessly is almost certainly managing yours the same way. A firm with rigorous internal controls is showing you how they will approach your environment: deliberately, with accountability at every step.
For more on how we approach cybersecurity as a practice — not just a feature — visit our cybersecurity services page. You can also explore our broader managed IT services to see how access controls fit into every engagement we run.
How to Use This in a Real Vendor Conversation
You do not need to be a technical expert to have this conversation. These six questions are written in plain language specifically because the answers should be explainable in plain language. If a vendor responds with jargon, deflection, or a promise to “get back to you,” treat that as data.
Bring this list to your next vendor review, your next contract renewal, or your next meeting with an IT firm you’re evaluating. Ask the questions in order. Watch how the person across from you responds — not just what they say, but how confidently and specifically they say it. A firm that has done the work will answer without hesitation. A firm that hasn’t will show you that, too.
Responsible privileged access management is not a bonus feature or an advanced concept reserved for large enterprises. It is the baseline of responsible IT service delivery. Any firm managing your systems should demonstrate it clearly, specifically, and without prompting. Now you know the questions to ask.
If you want to see how Xact IT answers every one of these questions — with documentation to back it up — Book a Free Cybersecurity Strategy Call. Twenty minutes. No pressure. Just answers.
Let’s Talk About Your IT Strategy
If anything in this post raised a question about your own environment, the fastest path to an answer is a 20-minute strategy call. We’ll look at your specific situation and tell you what we’d actually do about it.