Compliance Scenario · Data & Technology Risk · Third-Party Access
The Rig Is Down, and the Penalty Clock Is Running. A Vendor Can Fix It Today — If I Get Them Onto Our Systems Now. Do I?
Keeping the rig turning is your job. Deciding who gets access to the company’s systems and data is not.
Quick Answer
Is it OK to give an unvetted vendor access to our systems to meet a deadline?
No — not on your own authority. Letting an unvetted third party onto company systems gives them access to proprietary data and operational controls, and that data may also be subject to where it’s legally allowed to live. The vetting and onboarding process exists for exactly this moment; skipping it “just this once” can create a security, contractual, and even regulatory exposure far larger than the delay you’re trying to avoid.
When the deadline is the pressure, that’s the moment to escalate — not to improvise. See more data & technology risk scenarios.
Pressure Type: Expedience
The fix is right there, the cost of waiting is real and visible, and the slow path feels like bureaucracy getting in the way of the work. Expediency doesn’t feel like cutting a corner — it feels like being the person who solves the problem. That’s exactly when a decision that isn’t yours starts to feel like one that is.
The Situation
Travis is the field operations lead on a remote rig site. Mid-job, the automated control system fails, and every day it’s down racks up a heavy penalty. A capable local IT vendor can patch it today — but they’re not vetted or onboarded, and corporate onboarding takes weeks. To get them working now, Travis would have to put them on the company network and grant access to the proprietary control software, with operational data flowing back to headquarters across a border.
There’s a shortcut: Travis can certify the vendor under a legacy entity name the company has “used before,” skipping the queue. Everyone back home wants the rig turning, and whoever makes that happen looks good. The penalty clock is loud. What does Travis do?
Three Ways People Respond
1. Get them on now under the legacy entity.
Certify them under the old name, skip the queue, save the day. Why it fails: giving an unvetted third party access to proprietary systems and data isn’t a field-level call — and certifying them under a name that doesn’t match reality adds a falsification problem on top. The downtime penalty is real, but the security, contractual, and data-residency exposure that Travis would create is far greater.
2. Let them in, but “keep an eye on them.”
Grant limited access and watch over their shoulder. Why it fails: the moment they’re on the network, access and data movement have already occurred — supervision doesn’t undo them. A verbal “be careful” isn’t a vetting process, a contract, or the authority to expose the company’s systems.
3. Escalate immediately and ask for an expedited exception.
Call it in now, document the downtime, and push hard for a fast-tracked vetting or an authorized alternative. Why it works: see below.
The Right Call
For Travis: Choice 3 — escalate now and force the exception.
Travis raises it immediately — to his manager, IT security, and whoever owns vendor approvals — lays out the cost of downtime, and pushes for expedited vetting or an authorized fix. The penalty is exactly the argument for moving fast through the right channel, not for going around it. If there’s no fast lane for emergencies like this, that gap is the real problem, and naming it is part of the job. Travis keeps the rig as his responsibility and puts the access decision where it belongs.
Why It’s Harder Than It Looks
The cost of waiting is right in front of you.
The penalty is a real number ticking up now; the security and legal exposure is abstract until it isn’t. Visible cost beats invisible risk in the moment — which is the whole trap.
“We’ve used their sister company” feels like vetting.
A familiar-sounding name makes the shortcut feel pre-approved. It isn’t — and certifying a vendor under an entity that isn’t really them turns a judgment call into a falsified record.
Everyone’s rooting for the fix.
The person who keeps the rig turning is the hero; the person who slows it down to escalate feels like the obstacle. The reward structure quietly pushes toward the shortcut.
“I’d never hand our systems over to some random vendor.”
You wouldn’t — not if it looked like that. But under a six-figure-a-day penalty, with a capable crew standing right there and a legacy name that makes it feel already approved, it doesn’t feel like “handing over our systems.” It feels like keeping the rig turning. The exposure is the access you grant, not the intention behind it.
Frequently Asked Questions
Is giving a vendor temporary access really a big deal?
Yes. Temporary access is still access — to proprietary systems, operational controls, and data that may be subject to where it can legally live. A short window is enough to create a lasting security, contractual, or regulatory exposure.
Who decides whether a vendor can get onto our systems?
The owners of vendor approval and IT security — through the vetting and onboarding process — are not individuals on site, however urgent it feels. Your role is to surface the need and the urgency, fast.
What should I do if following the process would mean missing a deadline?
Escalate immediately, document the cost of the delay, and ask for an expedited exception. If there’s no fast lane for genuine emergencies, that gap is exactly what to flag — the answer is to fix the process, not to bypass it.
How to Use This in Training
Run it in 10–15 minutes with field leads, site supervisors, operations, and anyone who can grant access under pressure. Read the situation, then ask the question that does the work: “What are you allowed to decide to keep the job moving — and what’s above your line?” Let the room draw the boundary, then make it explicit.
Close on the habit: when the deadline is the pressure, escalate fast through the right channel. Available as a manager-led Decision Brief™.
Where This Goes Next
This is the front-line version of a decision that lands much harder in the boardroom. The leadership version — where a fast field fix becomes a cross-border data-sovereignty crisis — is the Executive Decision Lab™ “The Connected Rig.”
More Data & Technology Risk Scenarios
Cluster Hub
Browse all Data & Technology Risk scenarios →
Teach the line before the clock is running
Run this scenario with your field and operations teams as a 15-minute Decision Brief™, or talk to us about data and third-party risk training.
© 2005–2026 Xcelus LLC. All rights reserved. Scenario is fictional and for training and discussion only; not legal advice.
© 2005–2026 Xcelus LLC. All rights reserved. This content is for training and discussion only and is not legal advice; consult qualified counsel about your organization’s specific obligations.