Access doesn't disappear in the cloud - It just gets harder to see
What happened
SecurityBrief reports that third‑party access in cloud and hybrid environments remains hard to see and rarely maps neatly to organisational responsibilities. The article notes Australian critical‑infrastructure rules (CIRMP) now explicitly list third‑party access as a hazard, increasing compliance pressure on operators. Buyers should watch for demands from regulators for a current access register and test revocation processes for legacy contractor accounts
Why the category manager should care
Treat third‑party access as a contract and operational deliverable, not an IT tickbox; buyers must be able to produce a current answer to 'who can access what' on demand
Key facts
- CIRMP rules cite third‑party access as a named hazard and are in force
- Third‑party access spans on‑prem, OT and cloud environments