Skip to content
The Cyber Security Place

Their staff, your access, nobody's joiner-leaver process

Event dated 22 April 2026 · Published 2 September 2026 · 3 sources

Among April 2026's reported incidents, Adobe was said to have been reached through an outsourcing contractor in India. The structure matters more than the specific case, because it recurs. Contractor staff hold the client's access to do the client's work, while sitting outside the client's directory, outside its policies, and outside its joiner-mover-leaver process. When somebody at the supplier changes role or resigns, the event that should trigger removal happens in an organisation that does not run the removal — and the organisation that does run it never hears about the event.

Insider risk is normally framed around employment. Somebody joins, is granted access, changes role, and eventually leaves, at which point a process removes what they had. The process is imperfect, but it exists, it is owned, and it is triggered by an event the organisation can see.

Outsourced work breaks the chain at the trigger. The client grants access to named individuals at a supplier. Those individuals are managed by somebody else, and the events that should end their access — reassignment, resignation, dismissal — are events in the supplier's records that reach the client, at best, in a monthly report.

Neither party owns the gap

The supplier knows when its people leave and does not control the client's systems. The client controls the systems and does not know when the supplier's people leave. Each has exactly half of what removing an account requires, which is why the accounts stay.

That is not negligence on either side. It is a division of information created by the contract, and it persists precisely because nobody is failing at their own job. The gap belongs to the arrangement rather than to a person, which is also why nobody is assigned to close it.

Shared accounts make it worse

The common shortcut is a small number of accounts used by a rotating group of contractor staff, because provisioning individuals through a client's process takes days and the work does not wait. It is efficient and it removes attribution entirely: the log records a service account, and which of eleven people used it that Tuesday is a question the client cannot answer at all.

Where those accounts exist, the joiner-leaver problem stops mattering, because there was never a leaver event to miss. The credential simply outlives everybody.

What is actually enforceable

Two things, and both belong in the contract rather than in a control. Named individual accounts, never shared — which the supplier will resist on grounds of cost, and which is the only way attribution survives. And an obligation to notify the client within a stated number of hours when any named person stops working on the account, with the client revoking on that notice rather than on a review cycle.

Where neither is achievable, the honest fallback is time. Access that expires on a fixed date and must be renewed converts a permanent unknown into a bounded one, and it works without anybody at the supplier remembering to tell you anything.