Your Vendors Are Your Perimeter

— by

A few weeks ago I was setting up an MCP connection between Claude and HubSpot for a client, and the vendor required full admin rights just to get the connection going. That stuck with me. It’s becoming completely normal, and most people never stop to ask what that access actually means.

This week gave us a real example of why it matters. Ernst & Young is facing a proposed federal class action after attackers got into a third-party IT help desk platform used by EY’s tax practice. Attackers didn’t touch EY’s tax software or audit systems. They got into a help desk tool that happened to have client tax documents sitting in support ticket attachments.

The attackers were in that system for 26 days before anyone noticed. Investigators spent close to three months figuring out the scope before EY notified affected clients. No malware. No ransomware. No group even claimed credit. The whole thing ran on something security researchers call a trusted relationship attack. The attacker doesn’t need to break anything. They just need to find a connection everyone already approved and stopped watching closely.

This Pattern Isn’t New

Back in 2013, Target got hit through a refrigeration vendor’s login credentials, not their own network defenses. Okta had a version of this too, when their own customer support system got breached and attackers used what was inside to reach Okta’s actual customers. The EY case follows the same shape. A trusted third party gets compromised, and because that vendor had a certain level of access, client data walks out the door with it.

Why This Matters to You Directly

If you’re at a firm, you almost certainly have standing access to client systems. That makes you a trusted third party too, the same way EY’s vendor was one for them. And if your own firm uses contractors or outside providers, check your engagement letters, there’s probably a carve-out for exactly this, the same exposure runs the other direction. A vendor breach on your side can turn into a client liability question fast, the same way it just did for EY.

AI Is Turning Up the Volume

One of the best things about AI right now is how easily it connects to other systems. That’s genuinely valuable. It’s also why firms are hooking these tools into everything, often with more access than the task actually needs. I’ve seen someone get access to Claude and, within minutes, ask it to send mass invites for a marketing event, which meant granting full access through a Microsoft 365 connector just to get that one task done. I did something similar myself connecting HubSpot to Claude through MCP. The setup required heavy admin rights, and it was on me afterward to scale that back down to read-only. AI is a big reason firms are adding more of these connections, faster than most can track them.

Where to Start

Start by mapping your trust graph: every vendor, contractor, and tool that touches client data, and what level of access each one actually has. I went through this exercise recently at my own firm, and the number of tools had grown noticeably in just a few months, mostly because AI tools were being tested and added faster than anyone was tracking. Once you have the list, ask the boring but important question for each one: does it actually need this level of access, or did it just default to broad because that was easier to set up?

Data minimization matters here too. The advice you’ll read everywhere is to connect AI to everything for maximum benefit. It skips the part where someone has to manage that access afterward. Just because a connection is easy to set up doesn’t mean the scope you gave it was the right call.

Key Takeaways

  • Trusted relationship attacks target the connections you already approved, because approval means less ongoing scrutiny.
  • The EY breach ran through a routine internal tool, not a sophisticated exploit of EY’s core systems.
  • Your firm is a trusted vendor to your clients too. A breach on your end becomes their liability question.
  • Map your firm’s full trust graph: every vendor, contractor, and tool with access to client data, including AI connectors.
  • Treat AI connector permissions (MCP and similar) with the same scrutiny you’d apply to any contractor’s access.

Want the CPE credit? Take the full lesson on EverydayCPE and earn 0.2 CPE credits: [lesson link]

Today’s lesson


Leave a Reply

Discover more from EverydayCPE

Subscribe now to keep reading and get access to the full archive.

Continue reading