A virtual assistant or remote contractor should follow the same security standards as a full-time employee: verified identity, an individual account instead of a shared password, multi-factor authentication, least-privilege access, a managed and encrypted device, and a documented offboarding process.
The two biggest mistakes small businesses make are giving a contractor the ownerâs credentials because it is faster, and having no plan for revoking access when the relationship ends.
The worst cases are not imaginary. Persistent access can outlive the relationship. A contractorâs account can be used to redirect payments or copy client data. In documented cases, remote workers have used stolen identities, proxy infrastructure, and U.S.-based laptop farms to appear as though they were working from one location while actually operating somewhere else.
This is not an argument against virtual assistants, offshore contractors, or remote work. Hiring remote help is often an excellent business decision. The problem is giving someone permanent access to important systems without applying the controls you would use for any other employee.
Part One: Why This Matters
The day one problem
The familiar scene looks something like this:
You hire a capable VA. They are ready to work. You need help immediately.
By the second day, they have:
- The ownerâs email password
- Access to the accounting system
- A shared cloud drive
- The password manager
- A company card
- A personal Gmail or messaging account used for business
- Maybe even access to banking or payroll
It happened because creating a proper account felt slower than sending a password in a text message.
That is understandable. It is also dangerous.
The access was granted in minutes, but unwinding it later may take months because nobody wrote down what was shared. You may remember the major systems, but forget the old CRM, the forwarding rule, the shared spreadsheet, the vendor portal, the remote access tool, or the password vault entry.
Access you cannot enumerate is access you cannot revoke.
A backup can restore your files. It cannot tell you which systems your former assistant could access, which client files they downloaded, or which account receives your authentication codes.
Remote work changes the threat model, not the standards
An office provides some controls automatically. The device may belong to the company. The network is usually managed. Other people are nearby. Sensitive conversations are less likely to happen in a shared living room.
Remote work removes those assumptions.
A contractor may be using:
- An unmanaged personal computer
- A shared family laptop
- A home network with several devices
- A workspace shared with another employer
- Public Wi-Fi
- Personal email and cloud storage
- A device located in another country with different legal and regulatory considerations
None of this makes remote work unsafe. It means the controls have to carry the weight that physical proximity used to carry.
The principle is simple: same standards, different enforcement.
A contractor should not receive a lower security standard because they work from home, work through an agency, or live in another country. Their role may justify narrower access, but it does not justify weaker security.
The three realistic risk categories
1. Accidental exposure
This is the most common type of problem, and it is usually not malicious.
A VA may:
- Click a phishing link
- Reuse a password
- Work from a shared computer
- Download client files to a personal device
- Paste sensitive information into an unapproved AI tool
- Send a document to the wrong person
- Use personal email because the company system is inconvenient
Good people make mistakes. Security controls exist because good intentions are not a control.
2. Unauthorized use
Access can continue after the relationship ends. A contractor may share credentials with a teammate, keep a local copy of files, or leave a browser session active on an old computer.
Sometimes this is deliberate. Sometimes it happens because the contractor is trying to finish work or because the business never completed offboarding.
Either way, the result is the same: someone still has a path into your systems.
3. Deliberate infiltration
This is the rarest category and potentially the most damaging. Someone is hired specifically to obtain access, steal data, redirect money, or create a foothold for a later attack.
The important point is that the same basic controls help with all three categories. You do not need one security program for accidental exposure and another for sophisticated infiltration. You need individual accounts, MFA, limited access, managed devices, monitoring, and a real offboarding process.
Part Two: How to Secure a VA or Remote Staff Member

Before you hire: verify who will actually do the work
Start with the person, not just the agency or platform.
Use a live video interview with the individual who will perform the work. If an agency is involved, ask who will have access to your systems and whether that person can be changed without your approval.
As appropriate for the role and applicable law:
- Confirm the workerâs identity and claimed location
- Make sure documentation is consistent with the name used for payment and business communication
- Verify employment and education claims directly when they matter
- Ask who else they work for
- Ask whether they will use subcontractors
- Understand where company equipment will be shipped
- Review the agreementâs confidentiality and data-handling terms
- Check whether the work creates a compliance, export-control, privacy, or sanctions concern
Watch for red flags such as reluctance to appear on live video, inconsistent answers about location, payment accounts in another personâs name, frequent changes to addresses or payment platforms, or requests to use equipment you cannot manage or inspect.
These are not accusations. They are reasons to slow down and verify.
The FBI has specifically warned that remote IT worker schemes have used stolen identities, reused contact information, false websites, and U.S.-based facilitators. The FBI and IC3 January 2025 advisory recommends identity verification during interviewing, onboarding, and employment, along with monitoring for unusual logins and data movement.
Day one: provision access before work starts
Do these things before handing over business data.
-
Create a unique account
Never share the ownerâs login. Not for convenience, not for a temporary task, and not because the software makes delegated access annoying.
A shared password destroys accountability. The audit log can only show that somebody with the password did something.
-
Require MFA everywhere
Enable multi-factor authentication for email, cloud storage, accounting, payment platforms, password managers, and administrative consoles.
MFA is one of the highest-return security controls available to a small business.
-
Grant the minimum access required
A scheduling assistant does not need banking access. A bookkeeping contractor may need accounting access without needing email administration. Start narrow and expand access only when a real task requires it. The same principle applies on the device itself â see why end users should not have local admin access.
-
Assign an internal owner
Every external account should have an internal person responsible for it. The business owner does not have to perform every task, but someone inside the company must know what the contractor can access. When something does go wrong, that ownership is also what keeps an incident from becoming a crowd.
-
Use a managed device
Ideally, provide a company-managed laptop. If the contractor uses their own device, require full-disk encryption, automatic updates, screen locking, endpoint protection, and a private work environment.
A personal device shared with children, roommates, or another employer is not an adequate control for sensitive business data.
-
Give them a company identity
Use a company email address and approved collaboration tools rather than personal Gmail, WhatsApp, or an unmanaged cloud drive. Work communication should be traceable and revocable.
-
Document the access
Record the systems, permissions, dates, devices, and internal owner in one place. This list is what makes future access reviews and offboarding possible.
-
Put expectations in writing
The agreement should address client data, local storage, personal cloud drives, AI tools, subcontractors, incident reporting, confidentiality, and what happens when the relationship ends.
Ongoing controls: the part everyone skips
Access is not a one-time decision.
Review contractor access at least quarterly. Look for systems they no longer use, permissions that grew beyond the original role, dormant accounts, and tools nobody remembers approving.
Watch for:
- New email forwarding rules
- Unusual download activity
- Impossible travel or unexpected countries
- Logins at times inconsistent with the workerâs location
- New remote access software
- Repeated sign-ins from multiple locations
- Client files appearing in personal storage
Separate duties around money. The person who enters a vendor payment should not also be the person who approves it. Any change to banking information should be confirmed by phone using a number you already had, not the number in the email requesting the change.
Keep business information in business systems. Do not let client records live permanently in personal chat apps, personal email, or a personal cloud account.
You also need an AI policy. Can the VA paste client information into a personal chatbot? Can they use an AI transcription service? Which tools are approved? If you have not answered those questions, assume different people are making up their own answers.
At USTech.Ninja, this is the kind of access governance we handle for clients, including provisioning, MFA enforcement, device standards, access reviews, and documented offboarding. Our own contractors and virtual assistants are held to the same security standards as full-time employees.
Offboarding: where nearly every small business fails
When the relationship ends, access must be revoked deliberately and completely. Do not wait until the next day.
Your offboarding checklist should include:
- Disable sign-in immediately, ideally within the hour.
- Revoke active sessions and refresh tokens, not just the password.
- Remove access from email, cloud storage, shared drives, accounting, banking, CRM, project tools, VPN, remote access, password vaults, and admin consoles.
- Rotate any shared password the person knew.
- Remove email forwarding rules, delegations, calendar shares, and distribution-list memberships.
- Transfer ownership of documents, mailboxes, calendars, workflows, and files they created.
- Collect or wipe company devices.
- Deactivate company cards, phone numbers, and other issued identities.
- Review system logs to confirm the deprovisioning worked.
- Document what was done, when, and by whom.
An offboarding that is not verified is not an offboarding.

Part Three: What the Worst Case Looks Like
1. Access that outlives the relationship
A contractor leaves. You change one password. Nobody remembers the shared drive, accounting login, email rule, password vault entry, or browser session.
Months later, the former contractor, or someone who obtained access to their old device, still has a path in.
This is a serious process failure, not necessarily a sophisticated hack. Individual accounts and verified offboarding prevent it.
2. Fraudulent payment redirection
A contractor mailbox is compromised. An invoice is intercepted. Bank details are changed. Money is sent to the wrong account.
Recovery can be difficult, especially when the transfer is quickly moved through multiple accounts or across borders.
The strongest practical controls are separation of duties and out-of-band verification. A payment detail change should require a second person and a phone call to a known number.
3. Data and client exfiltration
Client lists, pricing, contracts, credentials, and files can be copied over time through legitimate access.
If everyone uses one shared account, you may not be able to prove who accessed what. You may not even know what was taken.
Unique accounts, audit logs, restricted downloads, approved storage, and periodic review give you visibility before the damage becomes permanent.
4. The fake remote hire
The FBI has documented schemes involving remote IT workers who use stolen or fabricated identities, proxy infrastructure, U.S.-based facilitators, and laptop farms. In these arrangements, company laptops may be hosted at a U.S. residence while being remotely controlled by a worker elsewhere.
The FBIâs July 2025 advisory describes identity obfuscation, remote access to U.S. company laptops, false addresses, payment-account changes, and the use of AI or face-swapping technology during video interviews.
The Department of Justice reported in June 2025 that coordinated law enforcement actions involved alleged fraudulent employment at more than 100 U.S. companies, laptop farms, stolen identities, data theft, and cryptocurrency theft. The DOJ also reported seizures of laptops, financial accounts, and fraudulent websites. The court documents describe allegations, and defendants are presumed innocent unless proven guilty.
This is a documented scheme, not a reason to distrust every remote worker. The practical defenses are ordinary security controls:
- Live identity verification with the actual worker
- Managed devices with real visibility
- Restricted remote access software
- Geographic and sign-in monitoring
- Least-privilege permissions
- Careful third-party staffing oversight
- Verified offboarding
5. Overlapping arrangements and confidentiality conflicts
A VA may work for several clients, including companies in the same industry. That is not automatically a problem. It does create confidentiality and conflict-of-interest questions.
A contractor should not be moving files between clients, reusing credentials, or using one clientâs personal information to perform work for another. Your agreement should define confidentiality, data separation, subcontracting, and approved tools.
What people actually do versus what they should do
| What people actually do | What they should do | What it prevents |
|---|---|---|
| Send the ownerâs password in a text message | Create an individual account with MFA | Shared-account abuse and weak audit trails |
| Give access quickly and figure out permissions later | Define the role first and grant least privilege | Access creep |
| Let the VA use a personal laptop with no controls | Use a managed device or enforce encryption, updates, screen lock, and endpoint protection | Malware and data exposure |
| Give the VA the company card or full banking access | Use limited financial roles and separate payment entry from approval | Payment fraud |
| Put sensitive files in a shared Drive folder with everyone included | Use role-based folders and approved business storage | Unnecessary client-data exposure |
| Let the VA paste client information into a personal chatbot | Define approved AI tools and prohibit unapproved data sharing | Data leakage through AI services |
| Never review access after onboarding | Conduct quarterly access reviews | Dormant accounts and permission creep |
| Change one password when the relationship ends | Revoke sessions, remove permissions, rotate known passwords, and verify logs | Persistent access |
| Keep the access list in someoneâs memory | Document systems, permissions, owners, and dates | Guesswork during an incident |
Which stage are you in?
Stage one: informal
The VA has the ownerâs password or a shared login. Access was granted by text message. Nothing is written down.
Offboarding will be guesswork.
Stage two: accounts exist, but access is broad
The contractor has an individual login and MFA, but their permissions are wider than their role requires. Device standards are unclear. Access reviews do not happen. Offboarding is a scramble.
Stage three: deliberate
Every worker has a unique account, MFA is enforced, access is scoped to the role, an internal owner is assigned, devices are managed, financial duties are separated, access is reviewed, and offboarding is documented and verified.
Stage three is achievable for a five-person business. This is not enterprise-only security. It is basic operational discipline applied consistently.
If you use automation or an MSP AI agent Hermes, recurring checks can surface new forwarding rules, unusual sign-ins, or access changes so a person only gets involved when a decision is needed.
Five actions to take this week
- Give every remote worker an individual account with MFA. Stop sharing the ownerâs login today.
- Write down every system each remote worker can access, and assign one internal person to own that list.
- Separate payment entry from payment approval, and confirm bank-detail changes by phone.
- Create the offboarding checklist before you need it, including session revocation and file ownership transfer.
- Conduct a live video interview with the person doing the work, and require a managed device with real visibility.
The right remote worker can make your business faster, more organized, and more profitable. Secure access helps you keep the benefits without turning one person into an invisible master key.
If you are about to hire your first remote team member, or you are not sure what the last one still has access to, schedule an introductory call with USTech.Ninja. We can review the access model with you and help build a practical process.
For a broader review of your technology and security exposure, see our cyber risk audit. If you need ongoing support, our Managed IT services Phoenix team can help put the controls in place and keep them current.





