Why offshore hires fail in month three
Almost nothing fails in week one. The failures cluster at month three, and by then the cause is months old.
Read articleInsights
· Guides
Every outsourcing arrangement involves giving someone access to something. Your inbox, your CRM, your customer records, sometimes your payment systems.
That is not a reason to avoid it. It is a reason to set it up properly — and most of what follows costs nothing and takes minutes.
Never share a password. Every system worth using supports separate user accounts. Sharing a login means you cannot tell who did what, and you cannot revoke one person without disrupting everyone.
Give the minimum that works. Someone scheduling social posts does not need billing access. Someone handling your inbox does not need admin rights. Start narrow; widen if the work genuinely requires it.
Use a password manager for anything shared. Where a system truly has no multi-user support, a password manager lets you grant and revoke access without the credential ever being readable in an email or a chat message.
Turn on two-factor authentication. On your accounts and theirs. It is the single highest-value control available and it is free.
This is the question most people forget, and the one that matters most.
When someone leaves the account — theirs or yours — who removes their access, how quickly, and how do you know it happened? A provider who has thought about this will answer immediately. A provider who has not will say something reassuring and vague.
Ask for it in writing, and ask for confirmation when it actually happens.
Not because you expect to enforce it, but because agreeing it in writing makes both sides think about it concretely. It should cover what counts as confidential, what happens to your data when the engagement ends, and whether anything can be subcontracted onward without telling you.
That last point is worth pressing on. If a provider can pass your work to someone you have never heard of, every control above is only as strong as an arrangement you cannot see.
GDPR if you hold data on anyone in the EU or UK — and you probably do, even if you do not sell there. ISO/IEC 27001 is the reference point for how an organisation manages information security. PCI DSS applies the moment card data is anywhere near the process.
You are not auditing anyone. You are checking whether these are familiar words or new ones.
Use systems that log activity, so you can answer “who changed this” without an argument. Review who has access to what every few months — access tends to accumulate quietly, and stale accounts are the ones that get compromised.
None of this is exotic. All of it is the difference between a considered arrangement and a hopeful one.
Our own practices are aligned to GDPR, ISO/IEC 27001 and PCI DSS, and you can read how we handle client data in full.
Keep reading
Almost nothing fails in week one. The failures cluster at month three, and by then the cause is months old.
Read article
Most businesses ask for full overlap and need about two hours. The difference costs money and narrows who will stay.
Read articleLet's talk
Tell us what's taking up your time. We'll show you exactly how a trained iFOVS team can take it off your plate — and what it costs.