By Donato Poveda
Published 2026-08-20
9 Min Read
Security Operations
0:00 / 0:00

A services contract closes at the end of March. The work is finished, the final invoice clears, & every file that should be closed gets closed by the person responsible for closing it. In August the badge issued under that contract still opens a side door, & the account issued with it still authenticates.

Nothing failed. There was no moment at which a failure was available to be made.

That opening is a composite. I built it to show a shape, & it is not a report of any incident or any engagement.

The shape is not mine, though. It has been audited & published three times over, by three federal Inspectors General.

A contractor badge on a lanyard resting on a closed archive folder for a completed services contract, the folder's period of performance dates visible on the label, an otherwise cleared desk in cool office light

Two Calendars That Never Meet

An employee's access runs on human resources events. Somebody is hired, moves, or leaves, & each arrives in the identity system as a record with a date on it. Imperfect, but a system, & it fires.

A third party's access runs on something else. It begins with an award & is supposed to end with a period of performance, a term written into a document that lives with procurement & with legal. That document was never connected to the directory. The contract has an end date. The credential has no idea what it is.

In May 2023 the Department of Transportation's Inspector General published an audit that did the obvious thing: it started from contracts whose performance period had ended & went looking for the credentials issued under them. Of the 1,184 contractor employee badges analyzed, 294 of them, 25 percent, had not been collected or deactivated. In one case the auditors describe, a support contract ended in April 2021 & the badge issued under it was not collected or deactivated until February 2022, 325 days later.

Bound that figure. The population was one department's non-FAA service contracts over $250,000 that ended across fiscal years 2020 & 2021, sampled statistically at 64 contracts. It measures the real thing, & it is not a rate for American business.

The reflex answer to a number like that is an offboarding checklist. A checklist assumes somebody is told.

The Department of Homeland Security's Inspector General found, in a December 2022 audit, exactly where that assumption breaks. Policy required a card be revoked within 18 hours of security officials receiving notice of a separation. Nothing specified when the notice had to be sent. The clock was well designed, & it started on an event nobody was required to generate.

There are four places the notice reliably does not come from, & only three rest on a documented finding rather than on my own read. The tiers underneath the contract you actually signed, where the requirement to push credential obligations down to subcontractors is written into NIST's supply chain guidance & measured by nobody, anywhere. The account issued to a company rather than to a person. The credential that was never in the directory to begin with: badges, gate remotes, alarm codes, lockbox codes, because IT cannot revoke what IT was never asked to issue.

And the fourth is the engagement that goes quiet rather than ending. Nobody sends a notice about a contract that is technically open & simply has no work left in it. That one is my own judgment after twenty years of this work, & there is no source behind it.

The Join Is Not in Anybody's Job

The same audit sets out who owned each piece of the contractor badge lifecycle. Five roles: a security office that issued & deactivated the cards, a contracting officer's representative responsible for the security clauses & for collecting the cards afterward, & three others. The report annotates three of the five as collateral duties, & the representative's role as usually one too.

Nobody in that table owned the join. The Inspector General said so in structural language rather than accusatory language: the department did not always promptly collect & deactivate contractor badges because it had not established clear accountability over the process.

The same audit is sharper still on one point. Of the 64 contracts sampled, 27 of them, valued together at $161.1 million, did not carry all the required badge related security clauses, including the one obliging the contractor to notify the contracting officer when access was no longer necessary. Nobody failed to send that notice. The notice was never wired.

The plainest statement of the problem came from the General Services Administration's Inspector General in March 2016. Officials reported that cards went uncollected because they were too busy, were unaware of the requirement, did not know how to collect them, or did not know which contractor employees were on which contract.

The two registers did not agree either. GSA's system of record showed over 92,000 active contractor employees; officials told the Inspector General that figure was inaccurate & speculated the real number was nearer 50,000. That estimate is theirs, not the auditors'. Neither review found the join automated anywhere. What both found was people doing it by hand. At GSA, eight of eleven regional credentialing offices ran ad hoc monitoring of their own devising. At Homeland Security, officials compared a two week old payroll report against the identity system to work out who had actually left. Where the join happens at all, it happens as somebody's workaround.

Every measured example above is a federal badge, & that is not an artifact of where I looked. Federal agencies have Inspectors General who audit them & publish what they find. Commercial contract security has no equivalent public record: a contractor who kept a badge is handled by taking the badge back & saying nothing. So when somebody quotes you a percentage of private sector contractor badges still live after contract end, ask where it came from. No public figure exists to draw it from, & that absence is part of the same problem.

The contract ended. The credential did not. In between there was no system whose job it was to notice.

When the Actor Is a Company

It is easy to file this under housekeeping. The Transportation audit opens with the reason not to.

In 2014 a contractor employee transferred from a control center facility in Illinois to one in Hawaii. During the twelve days between assignments the badge was not collected, was not deactivated, & the access to the Illinois building was not removed. He went back in & deliberately set a fire. The equipment destroyed disrupted the national transportation system for weeks, & the Inspector General put the cost to the public at over $350 million. The report bounds the case in its own footnote: agency policy at the time did not address collection & deactivation for a situation of that kind. Nobody had been terminated. Nobody had resigned. The gap opened during a transfer.

The digital version has the cleaner record, & it belongs to the company that filed it. Home Depot's annual report for the fiscal year ended February 2015 recorded, in the company's own words, that its investigation to date had determined "the intruder used a vendor's user name and password to enter the perimeter of our network." After that, the intruder acquired elevated rights. A filed disclosure describing an investigation as it stood eleven years ago, quoted here for one thing: where the intruder came in.

A Senate Commerce Committee majority staff report read the 2013 Target breach the same way, & every hedge in it is the committee's. Writing in March 2014, the staff concluded on the public record as it then stood that Target had given network access to a Pennsylvania HVAC & refrigeration contractor. The staff also found that attackers had reportedly gained their first access by stealing that contractor's credentials. The report says on its own first page that it was assembled from media reports & expert analyses rather than a completed forensic examination. What survives the hedging is the nature of the access: remote access held for electronic billing, contract submission & project management. A business process connection, not a technical one.

The number everybody reaches for at this point is the wrong one. Verizon reports third party involvement in 48 percent of the confirmed breaches in the corpus behind its 2026 Data Breach Investigations Report, up from 30 percent the prior edition. Read the definition before spending the figure. The metric combines a vendor inside the software supply chain, a vendor hosting the organization's data, & a vendor with a connection into its environment. None of the three is a credential that outlived its contract. Verizon also states in its own methodology that it makes no claim the findings represent all breaches in all organizations; its collection is a sample of convenience. A real number about a different question. The one that belongs to this question is the Inspector General's 25 percent, because that audit measured the contract.

This is the part of it I have spent the most time inside. Twenty years in federal law enforcement & executive protection is twenty years of asking who, & a credential attributed to a company cannot answer. A Treasury Inspector General audit in February 2020 put the adversary's side of it plainly: attackers frequently exploit legitimate but inactive accounts to impersonate legitimate users, & terminated contractor & employee accounts have often been misused that way. That is the auditor's professional assertion inside its discussion of findings rather than a measured result.

The rest of the problem is structural. The records that would settle who was at the keyboard sit inside a company you do not control & cannot assess, which NIST states flatly about external services. Meanwhile the contract may already be closed, which is where this started.

Manufacturing the Missing Event

None of this is an offboarding failure, so an offboarding fix will not reach it. No event exists at all. The work is to manufacture one.

Five recommendations. They are mine, they are security practice rather than anybody's standard, & none of them makes anybody compliant with anything. Each matches control language NIST already publishes, which matters mainly because it means none of this is exotic.

One boundary runs under all five. Each is executed on records the reader already owns. Reconciling a contract register against an access directory is a comparison of two lists. It is never a test of whether a credential still works, & where a step needs records the vendor holds, the authority for that comes from the contract & stops there.

Two printed lists laid side by side on a table under a single desk lamp, one a contract register with end dates, one an access directory, several rows on the access list with no matching row on the contract list

Go back to the composite, because the uncomfortable part of it was never the badge.

It is that everybody in it did their job. Procurement closed the contract on the date the contract named. Facilities issued a badge to somebody authorized to hold one. IT provisioned an account somebody with authority had requested. Five departments, five correct outcomes, & one date only one of them ever saw.

The reconciliation that would have caught it is not technically hard. It is a comparison of two lists the organization already owns, & at least two federal departments have been performing it by hand, run by people with no mandate to run it.

At Scopos Strategies, that comparison is the assessment. We lay the contract register against the access directory & report what the comparison shows, independently of what the vendor reports & independently of what the internal owner reports. It is investigative work before it is anything else, & that is the background we bring to it.

Pull two lists this quarter, the contract register & the access directory, & put one question to them: what appears in one that does not appear in the other?

Sources

Back to Insights

This article was produced with AI assistance. The perspective and security expertise are the author's own.