Why Your Company’s Cleaning Service Could Be a Security Risk

    June 26, 202610 min read
    Why Your Company’s Cleaning Service Could Be a Security Risk

    Why Your Company’s Cleaning Service Could Be a Security Risk

    When Target announced in late 2013 that hackers had stolen 40 million credit card numbers, investigators scrambled to find the source of the breach. They expected to find a sophisticated cyber intrusion or a compromised executive’s laptop. Instead, they traced the attack back to an unexpected source: Fazio Mechanical Services, a small HVAC contractor. That heating and air conditioning company became the entry point for one of the largest retail data breaches in history, resulting in over $18 billion in losses.

    This case fundamentally changed how security professionals think about third-party risk. The cleaning crew mopping floors, the HVAC technician adjusting thermostats, and the catering staff setting up conference rooms all represent potential security vulnerabilities. For students entering the workforce, recent graduates starting their first jobs, and career changers moving into office environments, understanding these risks isn’t paranoia—it’s practical workplace awareness that can protect both careers and companies.

    The Hidden Access Most People Never Consider

    Service providers move through office buildings with remarkable freedom. Janitorial staff arrive after hours when most employees have left. HVAC contractors access mechanical rooms and building management systems. Catering teams enter conference rooms where sensitive documents might be visible. Maintenance workers carry keys that open doors throughout the facility.

    This physical access creates opportunities that most people never consider. A cleaning crew member with a master key can enter server rooms, executive offices, and secure storage areas. They can photograph documents left on desks, plug devices into network ports, or simply prop open doors that should remain locked. They don’t need technical skills to enable a breach—they just need access.

    The Target breach illustrates this perfectly. Attackers didn’t need to break through firewalls or defeat encryption. They stole credentials from an HVAC contractor who had network access to monitor temperature controls in Target stores. That seemingly innocuous access provided the foothold attackers needed to move laterally through Target’s network until they reached the payment card systems.

    Why Service Workers Become Targets

    Security researchers have identified a troubling pattern: attackers increasingly target low-wage workers in service roles because they represent the path of least resistance. These workers often receive minimal security training, work irregular hours with limited supervision, and may have access credentials that exceed what their job actually requires.

    Social engineering attacks against service workers exploit economic vulnerability and workplace power dynamics. An attacker might impersonate a manager and ask a janitor to unlock a door “because I forgot my badge.” They might offer a cleaning crew member money to plug a small device into a computer “to test the network.” They might befriend an HVAC technician and casually ask questions about building security systems.

    The janitorial industry faces particular scrutiny in security discussions. Cleaning staff typically work after hours, have keys to most areas, and often work for third-party contractors rather than directly for the company whose facilities they clean. Background checks vary widely among cleaning companies, with some performing minimal vetting to fill positions quickly. The International Sanitation and Maintenance Association notes that security awareness training for cleaning staff remains inconsistent across the industry.

    Real Breach Patterns from Service Provider Access

    The MGM Resorts breach in 2023 demonstrated another variation of this risk. Attackers used social engineering to compromise IT support staff at a third-party vendor, gaining access credentials that allowed them to move through MGM’s network. The attack resulted in an estimated $100 million in losses and exposed customer data across multiple properties.

    The SolarWinds incident of 2020, while technically a software supply chain attack, shares a fundamental principle with service provider breaches: attackers compromised a trusted third party to access their ultimate targets. SolarWinds provided software updates to thousands of organizations, including the Pentagon, Microsoft, and Cisco. When attackers inserted malicious code into those routine updates, they gained access to some of the most secure networks in the world.

    These incidents share common elements. First, attackers identified third parties with access to their real targets. Second, those third parties often had weaker security controls than the ultimate targets. Third, the access granted to third parties exceeded what strict security principles would recommend.

    Questions Every Employee Should Know to Ask

    Understanding supply chain security doesn’t require technical expertise. It requires asking the right questions about the service providers entering your workplace. These questions apply whether you’re an entry-level employee noticing something unusual, a team lead involved in vendor selection, or a manager responsible for facility operations.

    For cleaning services, fundamental questions include:

    • Does the company conduct background checks on all staff who will have building access
    • How does the company manage and track keys or access cards
    • What security training do cleaning staff receive before starting work
    • Can the company restrict specific staff members from entering sensitive areas like server rooms
    • How does the company respond when a staff member loses keys or access credentials

    For HVAC and maintenance contractors:

    • What level of network access does the company require to perform their services
    • Does the company use multi-factor authentication for any remote access to building systems
    • How does the company secure credentials used to access building management systems
    • Can the company provide references from similar clients regarding their security practices
    • What notifications does the company provide before sending technicians to your facility

    For IT support or managed service providers:

    • What specific systems and data will the provider need to access
    • How does the provider authenticate their staff when accessing your systems
    • What security certifications or compliance standards does the provider maintain
    • How does the provider monitor and audit access by their staff
    • What is the provider’s incident response plan if they experience a breach

    These questions shift the conversation from “can you do the work” to “can you do the work securely.” They signal that security matters to your organization and help identify vendors who take these concerns seriously.

    Red Flags That Warrant Immediate Attention

    Certain patterns suggest a service provider may create unacceptable security risks. Recognizing these red flags helps protect both the organization and your own career reputation.

    A service provider who dismisses security questions or suggests they’re unnecessary represents a significant concern. Security-conscious vendors expect these questions and have clear answers ready. Resistance to basic security inquiries often indicates the vendor hasn’t implemented appropriate controls.

    Vendors who refuse to limit access to only necessary areas create unnecessary risk. A cleaning company should understand why janitors don’t need access to server rooms. An HVAC contractor should accept that network access must be monitored and logged. Legitimate service providers recognize that access restrictions protect both their clients and themselves.

    Missing or inadequate background checks for staff who will have building access represents another serious red flag. While background check requirements vary by industry and location, service providers working in office environments should have some vetting process for staff members who receive keys or access credentials.

    Service providers who subcontract work without notification create chain-of-trust problems. If you’ve vetted Company A but they send workers from unvetted Company B, your security controls become meaningless. Clear contractual language should address subcontracting and require notification before any subcontractors enter your facility.

    Practical Steps for Different Career Stages

    For students and recent graduates entering the workforce, security awareness around service providers builds professional credibility. New employees who notice and appropriately report security concerns demonstrate valuable judgment. This might mean mentioning to a supervisor that cleaning staff were in the server room, or noting that a contractor asked unusual questions about network systems.

    Career changers entering office environments often bring fresh perspectives that longtime employees miss. Someone transitioning from retail might notice that vendor access protocols seem lax compared to inventory control procedures. Someone coming from healthcare might recognize that visitor management practices would never pass HIPAA scrutiny. These observations have real value when raised constructively.

    Early-career professionals participating in vendor selection conversations can ask security questions that more senior staff might overlook. Questions about background checks, access restrictions, and security training demonstrate thoughtfulness beyond your experience level. Even if you’re not the decision-maker, raising these concerns contributes to better outcomes.

    Entrepreneurs and small business owners face particular challenges with service provider security. Limited budgets might make expensive vendors prohibitive, but the cheapest option often comes with hidden security costs. Focusing questions on specific security practices rather than general certifications helps identify responsible vendors at various price points. A small cleaning company that conducts background checks and restricts access may be more secure than a large company that does neither.

    The Business Impact Beyond Security

    Understanding service provider risks delivers career benefits beyond preventing breaches. These concepts connect to fundamental business principles like contract management, vendor relationships, risk assessment, and operational controls. Demonstrating fluency with these topics during job interviews shows business acumen that employers value across roles.

    The financial impact of service provider breaches extends far beyond immediate losses. Target’s $18 billion in costs included not just credit card fraud but also legal settlements, regulatory fines, stock price decline, and brand damage. MGM’s $100 million loss included operational disruption across multiple properties. These numbers make service provider security a board-level concern, not just an IT issue.

    Supply chain security now appears in regulatory frameworks worldwide. The EU’s NIS2 Directive requires organizations to manage third-party risks. SEC cybersecurity rules demand disclosure of material breaches, including those originating from vendors. Understanding these requirements positions you to contribute to compliance discussions regardless of your specific role.

    Making Security Awareness Practical

    Service provider security doesn’t require becoming a security expert. It requires maintaining awareness of who has access to what, and whether that access is both necessary and monitored. This mindset applies equally whether you’re working in a small startup or a Fortune 500 corporation.

    The principle of least privilege applies to service providers just as it does to employees. Access should be limited to what’s necessary for the specific work being performed. Cleaning staff need keys to offices and conference rooms, but probably not to server rooms or executive suites. HVAC contractors need access to mechanical systems, but not necessarily full network access to building management interfaces.

    Trust but verify remains the operational standard for vendor relationships. This doesn’t mean assuming vendors are malicious—it means implementing controls that protect both parties. Background checks, access logs, security training, and clear contractual terms create accountability that serves everyone’s interests.

    The Target breach that started with an HVAC company taught security professionals a hard lesson about third-party risk. For students, recent graduates, and career changers, that same incident offers a different lesson: security isn’t just about firewalls and encryption. It’s about understanding how businesses work, who has access to what, and asking the questions that protect organizations from their most overlooked vulnerabilities. The cleaning service, the HVAC contractor, and the catering staff aren’t security threats by nature—but without appropriate controls, they represent risks that every employee should understand.

    Share this article

    Enjoyed this article?

    Subscribe to Professor Simon's weekly newsletter for practical insights, career guidance, and leadership lessons delivered every Friday.

    A confirmation email will be sent. If you don't receive it, please check your spam or junk folder.

    No spam. Unsubscribe anytime.

    Prefer to Listen?

    Listen to Professor Simon’s IT & Cybersecurity Podcast for practical conversations about cybersecurity careers, certifications, security leadership, and real-world lessons from the field.

    Listen on Spotify