Cybersecurity

The hidden risk of integrations: a checklist for third-party apps

The Hidden Risk of Integrations: A Checklist for Vetting Third-Party Apps (API Security)

A new app can save time by connecting to Microsoft 365, accounting software, customer records or cloud storage. That connection may also give the app access to business data and the ability to act on your behalf.

The risk is not a reason to avoid every integration. It is a reason to check what the app can reach, who is responsible for it and how you will remove it if something goes wrong.

Why integrations need a closer look

Most small businesses use outside software for payments, support, reporting and file sharing. Building every function in-house is rarely practical.

Problems arise when an app receives more access than it needs, keeps data in an unexpected location or becomes essential to a daily process without a recovery plan.

A weak or compromised integration could expose information, interrupt work or allow unauthorised changes. An outage at the provider could also stop an important business process even when no attack has occurred.

What to check before connecting an app

Confirm the business need

Write down what the app is meant to do and who owns the decision. If an existing approved tool already does the job, another connection may add risk without adding much value.

Review the access request

Read the permission screen before approving it. Does the app need to read every mailbox, edit all files or access every customer record?

Ask for the narrowest access that will let it do the job. Be especially careful with access requested for the whole organisation or with administrator approval.

Find out what data the provider receives

Ask what information the app collects, where it is stored, how long it is kept and whether other providers handle it. Check how the provider deletes your data when you close the account.

If the app will handle personal, financial or health information, get suitable privacy or legal advice before connecting it.

Check the provider's security evidence

Look for current, independent evidence that matches the service you plan to use. This may include a recognised security certification, an independent controls report or recent testing results.

Do not rely on a badge alone. Check its scope, date and whether it covers the actual product and data centre involved.

Check access and administrator controls

The app should support individual user accounts, multi-factor authentication and clear access levels. Avoid shared administrator logins. Ask how staff access is removed, how important settings are protected and whether the business can see who made a change.

Plan for incidents, outages and exit

Find out how the provider reports an incident and what support is available during an outage. Decide what staff will do if an important app is unavailable and keep a way to retrieve essential information where practical.

Check who owns the data, what the provider is responsible for and how you can export and delete information when the service ends. Larger or higher-risk arrangements may need contract, privacy or legal review.

Keep a list of connected apps and the person responsible for each one. Review access when staff leave or an app changes purpose, and remove connections that are no longer used. Closing a user account may not remove an organisation-wide connection, so check the main administration area as well.

Make app approval a business process

Staff should know who can approve a new connection and what information is required. A short, consistent check is better than discovering an unknown app after it has had access for months.

Before approving another app, ask JCPIT about an integration review. We will confirm the systems and access in scope before reviewing existing connections or helping you set an approval process.

Jake
Jake
JCPIT Support — Keeping IT Simple.
← Previous Article
Five practical rules for using generative AI at work
Next Article →
Make your website and documents more accessible