skip to content

A contractor's personal laptop holds corporate access and you cannot mandate anything on it - what do you change?

level: principalimportance: nice to knowfreq 30%

answer

  1. you cannot change the device, so change something else
  2. what does the profile still contain worth selling
  3. unverifiable controls are not controls
  4. hardware-held keys have nothing to copy
  5. someone other than security owns the budget

basics

~20 s

Change what the device is allowed to hold, not the device: credentials that cannot be copied out of hardware, or a brokered session so the personal machine holds only a view. Where neither fits, price in a supplied managed device.

solid answer

~50 s

You have no authority over the endpoint, so every control class that assumes you do is unavailable - and mandating antivirus or signing an acceptable-use clause is a paper control you cannot verify and that does nothing against a single archiving pass. What you can change is the value of what a pass can copy. First class: authentication material that is hardware-bound and non-exportable, so the browser profile simply does not contain anything a buyer can present later. Second class: brokered access, where the corporate session lives on infrastructure you do run and the personal machine holds a rendered view rather than resident material. Third class: contractual and commercial - supply a managed device and price it into the engagement, or cut the identity's scope to what you can afford to lose. The principal judgment is which of those the business will actually pay for, and what you do when the contractor is a three-person firm that will walk rather than accept a loaner.

go deeper

for a junior

Understand that controls installed on a device only work where someone has the authority to install and check them, which is not the case on a person's own laptop.

for a middle

Be able to explain why hardware-bound authentication removes the value of a copied browser profile, while a stronger password or an anti-malware requirement does not.

for a senior

Rank the available classes by what each removes and state their limits honestly, including that partial migration leaves the unmigrated paths fully saleable.

for a principal

Own the parts a technical answer cannot reach: whose budget buys the devices, who is allowed to refuse them, when the contract can actually change, and how you record an accepted risk so the decision belongs to the business.

## Start from the constraint, not the control The constraint is unusually hard and you should say it out loud before proposing anything: the machine belongs to someone else, you cannot install on it, you cannot inspect it, you cannot verify any assurance its owner gives you, and you cannot rebuild it. Every endpoint control class you would normally reach for assumes ownership of the endpoint. They are all off the table, and pretending otherwise is the failure mode here. What remains is under your control on **your** side of the boundary: what a person can authenticate with, where the corporate session lives, and what that identity is allowed to reach. ## The paper-control trap The common wrong answer is a policy and a requirement: sign an acceptable-use clause, require anti-malware software, require the machine be kept up to date. It is attractive because it is cheap and it produces a document. It fails on three counts: - **unverifiable** - you have no way to know the state of a machine you cannot see, so the control's status is permanently unknown; - **irrelevant to the mechanism** - a single archiving pass over the user's own profile completes in minutes and needs no privilege the user does not already have; - **it transfers blame, not risk** - when the bundle surfaces, the clause tells you who to be annoyed with and nothing about what to do. ## Control class 1: make the copy worthless The technique cannot substitute for the thing it copies. If what a person authenticates with is a private key held in hardware that cannot be exported - the model specified by FIDO2 and WebAuthn - then the browser profile contains no artefact that means anything to a buyer, because possession of the authenticator, not possession of a copied file, is what the verifier checks. This is the strongest available class precisely because it removes the *product*, not the malware. Its limits are honest ones and you should name them: it protects what has been migrated to it and nothing else, and long-lived material sitting in the same profile for anything not yet migrated remains fully saleable. Partial migration buys partial protection. ## Control class 2: move the session off the device If the corporate work happens on infrastructure you run and the personal machine holds a rendered view, then the profile on that machine has nothing corporate in it to copy. This class is architectural rather than cryptographic, it costs real money and it degrades the working experience, which is why it tends to survive only where the work is narrow - one application, a defined set of tasks. ## Control class 3: change the commercial arrangement The honest third option is not technical at all. Supply a managed device and price it into the engagement; or accept the personal device and cut the identity's scope until the worst realistic bundle is something you can absorb - narrow entitlements, short-lived grants, no standing administrative reach, no access to bulk data. ## The judgment, which is the actual question Ranking the classes is the easy part. The principal-level content is everything around it: - **Who pays.** A loaner fleet, its shipping, its support and its replacement cycle land on someone's budget, and it is rarely security's. - **Who can refuse.** A large supplier may simply decline your hardware; a three-person firm may walk rather than absorb the overhead. The business owner of that relationship, not you, decides whether that is acceptable. - **Contract timing.** Terms can usually be changed only at renewal, so a decision today is often a decision that takes effect in a year, and you need an interim position. - **Consistency.** Applying this to one contractor because they were unlucky enough to be infected, while two hundred others carry the same arrangement, is theatre. Either the class of access changes or it does not. - **What you accept.** Sometimes the right answer is a documented acceptance with a narrowed scope and a renewal-date commitment, owned by the business, not a control you pretend to have. ## Answering it in a loop Name the constraint, dismiss the paper control and say why, rank the three classes by what they remove rather than what they add, then spend most of your answer on the ownership and money questions. An interviewer at this level is testing whether you can say *this is not mine to mandate, here is who decides and here is what I recommend they decide* - not whether you can list controls.

  • Why is requiring anti-malware software on a contractor's own laptop a weak answer?
    Because you cannot verify it, so its state is permanently unknown, and because it does not address the mechanism: one archiving pass over the user's own profile needs no elevated privilege and finishes in minutes. It produces a document rather than a change in what a copy is worth.
  • You migrate the contractor to hardware-bound authentication but the profile still holds saved passwords for three internal tools. What have you achieved?
    Partial protection only. The migrated path is no longer saleable, but the three unmigrated tools remain fully exposed and a buyer will simply use those. Migration protects what has moved to it, so the useful measure is coverage of the reachable surface, not whether the programme has started.
  • The business owner refuses a supplied laptop because the supplier will walk. What do you recommend?
    Narrow the identity until the worst plausible bundle is absorbable - reduced entitlements, no standing administrative reach, no bulk data - and record it as an accepted risk owned by that business owner with a review at contract renewal. The recommendation is theirs to accept; making that explicit is the point.

saying these in an interview costs you the question

  • Require antivirus and an acceptable-use policy
  • Mandate patching on a device you cannot inspect
  • Rotate the password and consider it handled
  • Treat this contractor differently from identical arrangements
  • Choose a control without naming who pays for it

context