Small business cyber safety

A Supplier Needs Access: How Much Should You Give Them?

When an accountant, web developer, MSP or contractor needs access, the safest answer is rarely “everything” and rarely “nothing”. It is the smallest workable access for the shortest sensible time.

Small businesses often grow by trusting capable outside help. An accountant may need access to payroll or invoicing. A web developer may need the website host, domain settings or analytics. An IT provider may need administrator access to Microsoft 365, backups or endpoint tools. The risk begins when temporary help quietly becomes broad permanent access.

Cyber.gov.au’s small business guidance recommends the principle of least privilege: people should have the bare minimum permissions they need to do their work. That is a practical business rule, not enterprise jargon. If a supplier only needs one system, do not hand over the owner login to five.

The short answer

Give suppliers the least access that will let them finish the job, record what they can reach, set an end point for that access and review it when the work changes. A named account, the right role and an expiry date are usually safer than a shared owner password that nobody remembers to change later.

Sort supplier access by consequence, not convenience

Not all access is equal. The first useful step is to separate routine work from high-consequence control.

  • Low consequence: viewing analytics, updating page copy, checking a booking export or preparing a report.
  • Medium consequence: changing website content, updating customer records, processing invoices or managing a shared mailbox.
  • High consequence: administrator access to Microsoft 365 or Google Workspace, domain registrar control, DNS, backups, payment systems, user creation, password resets or privacy-sensitive customer data exports.

If the task sits in the high-consequence group, slow the decision down. Cyber.gov.au’s guidance on engaging managed service providers says you should clearly identify which systems each provider can access and how, and keep that record up to date. That same discipline helps even when the supplier is a solo contractor or long-term trusted helper.

Do not start by sharing the owner login

Shared credentials feel easy because they avoid role setup, user invites and permissions decisions. They also remove accountability. If several people use the same powerful login, it becomes much harder to know who changed what, who still has access and which recovery methods are still connected to the account.

Cyber.gov.au’s managed-service-provider guidance says organisations should provide the least privileged account required to do the job. It also recommends named privileged access for a limited duration where stronger access is necessary. In a small business, that can look like:

  • a named Microsoft 365 admin account added only for the migration weekend;
  • a website editor role instead of full hosting access for content changes;
  • a finance-platform user who can process invoices but not change every business setting; or
  • a separate supplier login instead of handing over the owner mailbox password.

If the platform cannot support separate users or roles, treat that system as higher risk and add a stronger review routine around it.

Write down the boundary before the work starts

Many access problems are really scope problems. Before a supplier starts, write a short private note covering:

  1. which systems they need;
  2. what actions they are allowed to perform;
  3. whether customer or staff personal information is involved;
  4. who inside the business approves changes; and
  5. when the access should end or be reviewed.

Cyber.gov.au’s supply-chain guidance says organisations should map dependencies and manage access to their network while reviewing permissions. For a microbusiness, the same idea can be kept simple: know which outside party touches which part of the business, and do not leave that knowledge in one person’s head.

A practical access decision for common suppliers

  • Accountant or bookkeeper: start with the accounting platform, payroll or document folder they actually use. They usually do not need your domain registrar, website hosting or everyday email account.
  • Web developer: give website, hosting or DNS access only if the task truly needs it. A content update should not automatically include registrar control.
  • Managed service provider: document exactly which systems they administer, how they connect and who in your business can approve stronger access.
  • Short-term contractor: prefer invited user access, project folders and expiry dates instead of reusing a long-standing team login.

When customer data is involved, convenience is not the only question

If the work includes customer or staff personal information, privacy obligations may also matter. OAIC guidance says access to personal information should be on a need-to-know basis, because limiting access helps protect the information from unauthorised access, use or disclosure.

That does not mean every supplier relationship is forbidden. It means you should ask narrower questions: does this person need the whole database, or only one export? Do they need ongoing access, or one supervised task? Are you collecting or disclosing more information than the job requires?

The Privacy Act does not apply to every small business in the same way, and turnover alone is not the whole test. If privacy obligations are part of the decision, check which organisations are covered and get advice for your circumstances. Even where a legal requirement is unclear, the need-to-know principle is still good risk management.

What to ask before you approve stronger access

Cyber.gov.au’s supplier and MSP guidance is useful because it turns vague trust into practical questions. Before approving stronger supplier access, ask:

  • Which exact system or account do you need to do the job?
  • Can this be done with a lower-permission role?
  • Can we use a named account rather than a shared password?
  • How long do you need this access?
  • Will you be able to see customer, staff or payment information?
  • How will we know what changed?
  • Who inside the business will remove or reduce this access afterward?

Business.gov.au’s cyber security checklist also says staff should only be given access to the systems they need. Extend that rule to suppliers and contractors. Outside help should not be the exception that breaks your basic access discipline.

A same-day access removal checklist

  1. List every system the supplier can still reach.
  2. Disable or remove named accounts that are no longer needed.
  3. Remove delegated mailbox, folder or admin roles.
  4. Review MFA methods, recovery addresses and phone numbers attached to those accounts.
  5. Rotate shared secrets that had to be used because the platform was limited.
  6. Check whether API keys, app passwords, remote-support tools or saved browser profiles were left behind.
  7. Update the private access record so the next person is not guessing.

This is especially important when a project finishes suddenly or a trusted relationship changes under pressure.

What can safely wait

You do not need a perfect access-governance program before making a useful improvement. Start by replacing the broadest shared supplier access with one named account or one reduced role. Then add expiry dates and a simple record of who can reach what.

The biggest gain usually comes from removing unnecessary power, not from buying another security product. Least privilege, documented boundaries and timely access removal are realistic controls for a small business without an internal IT department.

Sources and further reading

Frequently asked questions

What if the supplier says they need full admin because it is faster?

Ask whether the task can be completed with a narrower role first. If broader access is genuinely required, limit it to a named account, a clear scope and a review point instead of leaving permanent blanket access behind.

What if the platform only supports one powerful login?

Treat that as a risk to manage, not a reason to stop caring. Keep the access period short, review recovery settings and connected apps, change the secret when the work ends and plan a move to a platform that supports individual roles when practical.

Related articles

Browse all cyber safety articles