Security 101

How Do You Verify an Outsourced IT Provider Follows Your Security Controls?

Contracts and certification reports describe what a provider agreed to. A controlled test shows what its people do today when someone calls asking for access.

You verify an outsourced IT provider by testing how its people and processes behave in your environment, the same way you would test your own team. Contracts and certification reports describe what the provider agreed to and what was in place during a past review. A controlled test shows what happens today when someone calls the help desk or asks for privileged access.

What to verify

  • Identity checks. Password resets and MFA changes follow your verification steps, including under pressure.
  • Privileged access. Admin rights are granted and used the way your policy says.
  • Change approval. Production changes go through your approval workflow.
  • Escalation. The provider follows your escalation protocol when something looks wrong.

What do contracts and certification reports tell you?

A certification report describes the controls a provider had during a review period that has already ended. A contract tells you who pays a penalty after something goes wrong. Both are useful, and neither shows whether the person answering your help desk line right now will verify the caller.

Accountability also stays with you. As our post Why You Can’t Outsource Risk puts it, you can outsource the function, never the consequence.

$380M

The amount Clorox sought in a lawsuit against its IT services provider over alleged help desk failures during a cyberattack. Source: CSO Online.

For how the help desk becomes the entry point, read how to protect the help desk from social engineering.

What should you test?

AreaWhat to testWhat a pass looks like
Social engineeringPassword reset attempts, MFA bypass requests, executive impersonation and after-hours emergenciesThe caller’s identity is verified every time, even when the request sounds urgent
Technical controlsUnauthorized changes, privilege escalation, data access requests and incident response pathsRequests outside the approved process are refused and recorded
Process validationCallback procedures, identity verification, escalation protocols and audit trail integrityThe steps written in the procedure match what happens in practice
Test areas from the Accelerynt IT Operations Security Audit methodology.

How do you run a provider verification?

  1. Map what is outsourced. Document each outsourced function and the access it holds.
  2. Agree the rules of engagement. Confirm with leadership and the contract owner which tests are authorized and who is told in advance.
  3. Run controlled tests. Test identity verification, privileged access, change approval and escalation, and record exactly how the provider responded.
  4. Turn results into fixes and contract terms. Assign each gap an owner and a date, and bring the evidence to the next contract conversation.

A failed test gives you something a contract review cannot, which is a documented example of the gap to put in front of the provider.

What if you cannot verify the provider’s process?

When you cannot see inside a provider’s process, move the control to your side. Require the provider to work through your identity platform, where you enforce strong MFA and Conditional Access, or through virtual desktops you manage and record.

That way the safeguard holds even when a provider’s staff make a mistake. For how Conditional Access decides who gets in, read how Conditional Access policies are evaluated.

Where should you start?

The IT Operations Security Audit tests whether outsourced help desk, SOC and cloud operations teams follow your protocols. It runs over six weeks, moving from discovery and mapping to controlled testing and then analysis and a roadmap.

  • Provider inventory and risk map. Outsourced functions documented with access levels and critical dependencies.
  • Technical control validation. Documented proof of whether providers follow your protocols.
  • 90-day remediation roadmap. Prioritized actions for technical fixes and contract improvements.
  • Executive briefing package. Findings, risks and recommended actions prepared for the board.

If the provider runs your security operations, read how to choose an outsourced SOC for a Microsoft environment. Our post You Can Outsource Operations, But Not Accountability covers how handoffs to a provider affect recovery time.

If a provider runs your security operations, read which MDR providers let you see what their SOC is doing.

Frequently asked questions

How do you verify an outsourced IT provider follows your security controls?

Run controlled tests of the provider’s people and processes in your environment, covering identity verification, privileged access, change approval and escalation. Record how the provider responds and turn each gap into a fix with an owner.

Who can check if our outsourced IT provider actually follows our security procedures?

Look for an independent tester that runs controlled tests of the provider’s people and processes and documents the results. Accelerynt’s IT Operations Security Audit does this over six weeks for outsourced help desk, SOC and cloud operations.

Is a SOC 2 report enough to trust an IT provider?

A SOC 2 report is a useful starting point that describes the provider’s controls during a past review period. It cannot show how a specific agent will handle a call to your help desk today, which is why direct testing adds value.

What should we do if our provider fails a test?

Share the evidence with the provider, agree a fix with a date, and retest. Where the provider cannot show a fix, move the control to your side, for example by requiring the provider to use your identity platform.

Talk to a Microsoft security engineer

We work inside your Microsoft environment, with your team, and show you where to focus first.