Vendor Risk Management: How to Vet the Companies That Hold Your Data

By J. Mesa

Your payroll provider holds your employees’ Social Security numbers. Your IT company holds an administrator password to every computer you own. Your billing service holds your customers’ records. You chose each vendor for price and service. An attacker chooses them for a different reason: one break-in at a vendor opens the door to every one of its clients.

What is vendor risk management?

Vendor risk management is the process of identifying which outside companies can reach your data or systems, checking how well they protect them, setting security terms in the contract, and reviewing them over time. You may also see it called third-party risk management.

Why do vendors matter to a small business?

Because you can outsource the work and still own the responsibility. When a vendor loses your customers’ data, the customers and the regulators come to you.

The record backs this up:

  • In 2013, attackers reached Target’s payment systems with credentials stolen from a heating and air conditioning contractor.
  • In 2021, criminals pushed ransomware through Kaseya’s remote management software to the clients of dozens of IT providers. Many victims were dental offices, accounting firms, and other small businesses.
  • In 2023, a flaw in the MOVEit file transfer tool exposed data from thousands of organizations, many of which had never heard of MOVEit. Their vendors used it.
  • In 2024, the attack on Change Healthcare froze billing for medical practices across the country for weeks.

Verizon’s 2025 Data Breach Investigations Report found a third party involved in 30 percent of breaches, double the share from the year before.

Which vendors should I worry about?

Sort your vendors by what they can touch.

  • High risk. Vendors that hold sensitive data or have administrator access to your systems: IT providers, cloud email and file storage, payroll and HR platforms, accounting and tax software, billing services, records systems, backup providers, and payment processors.
  • Medium risk. Vendors with limited data or limited access: marketing platforms with customer email lists, website developers, scheduling tools, phone systems.
  • Low risk. Vendors with no data and no access: office supplies, landscaping, the coffee service.

Spend your time on the high-risk group. A typical small business has 5 to 15 vendors in it.

How do I build a vendor inventory?

Open a spreadsheet and add a row for each vendor. Record:

  • Vendor name and what it does for you
  • The data it can reach
  • The system access it holds
  • The risk tier
  • The person at your business who owns the relationship
  • Contract start and renewal dates
  • Whether you have a security review and a signed agreement on file

To find the vendors you forgot, review a year of bank and credit card statements, the list of applications connected to your Microsoft 365 or Google Workspace account, and the software your staff signed up for without asking. That last group, called shadow IT, often holds more company data than anyone realized.

What should I ask a vendor about security?

For a high-risk vendor, ask these questions before you sign and again at renewal.

  1. Do you hold a current independent security report or certification, such as SOC 2 Type II or ISO 27001? May we see it?
  2. Do you require multi-factor authentication for your staff and offer it to us?
  3. Do you encrypt our data in transit and at rest?
  4. Who at your company can see our data, and how do you control that access?
  5. Where do you store our data, and which subcontractors can reach it?
  6. Have you had a breach in the last three years? What changed afterward?
  7. How quickly will you notify us of an incident involving our data?
  8. How often do you back up our data, and have you tested a restore?
  9. Do you carry cyber insurance?
  10. What happens to our data when the contract ends?

A vendor that refuses to answer, or answers with marketing copy, has told you something.

What is a SOC 2 report?

A SOC 2 report is an independent auditor’s examination of a service company’s controls for security, availability, confidentiality, processing integrity, and privacy. A Type I report describes the controls at one point in time. A Type II report tests whether the controls worked over a period, commonly 6 to 12 months. Ask for Type II.

Read three parts: the auditor’s opinion, the list of exceptions, and the section on what the vendor expects you to do. A SOC 2 report shows that an auditor looked. It does not guarantee the vendor will avoid a breach.

Small vendors often lack a SOC 2 report. In that case, rely on the questions above and on the contract.

What should the contract say?

Put the security terms in writing. Look for these clauses, or ask to add them:

  • A duty to protect your data with reasonable, specified safeguards
  • Breach notification within a set time, such as 72 hours
  • Limits on using your data for anything beyond the service
  • Disclosure of subcontractors, and the same duties passed down to them
  • Return or deletion of your data at termination, with written confirmation
  • A right to request security documentation each year
  • A cyber insurance requirement
  • Allocation of costs if the vendor’s failure causes a breach

A large vendor will not negotiate its standard terms with a ten-person business. Read them anyway. You need to know what you agreed to, and the terms may decide which vendor you choose.

Does compliance require vendor oversight?

Yes, in each of the major rules.

  • HIPAA requires a signed business associate agreement with every vendor that handles patient information.
  • The FTC Safeguards Rule requires you to select capable service providers, set security expectations by contract, and assess them on a schedule.
  • PCI DSS requires a list of the service providers that touch card data, written agreements, and a yearly check of their compliance status.
  • Cyber insurance applications ask how you manage vendors.

How do I limit the access a vendor has?

Assume that a vendor will suffer a breach at some point, and reduce what the attacker gains.

  • Give each vendor its own named account. No shared logins.
  • Grant the lowest level of access that lets the vendor do the job.
  • Require multi-factor authentication on every vendor account.
  • Turn remote access on when the vendor needs it and off when the work ends.
  • Send the vendor only the data it needs. A marketing firm does not need dates of birth.
  • Review the logs of what vendor accounts did.
  • Review connected third-party applications in your cloud accounts twice a year and remove the ones you do not use.

What about my IT provider?

Your managed service provider holds more access than any other vendor, so it deserves the hardest questions. Ask how it protects its own remote management tools, whether every technician uses multi-factor authentication, how it stores your passwords, whether it separates one client’s access from another’s, and what it will do for you during an incident. Ask for its incident response plan and proof of insurance. A good provider welcomes these questions.

What should I do when a vendor has a breach?

  1. Get the facts in writing: what data, which dates, how many of your records.
  2. Change the passwords and API keys tied to that vendor, and cut off its access until it confirms containment.
  3. Call your attorney and your cyber insurance carrier. You may have notification duties even though the vendor caused the event.
  4. Follow your incident response plan.
  5. Watch for phishing that uses the stolen data to target your staff and customers.
  6. Decide whether the vendor keeps your business.

How do I end a vendor relationship securely?

Offboard a vendor the way you offboard an employee. Disable its accounts and remote access tools. Change any shared passwords. Retrieve your data, then get written confirmation that the vendor deleted its copies. Remove its software from your systems. Update the inventory.

How often should I review vendors?

Review high-risk vendors once a year and at each contract renewal. Review any vendor right away when it has a breach, changes ownership, or changes what it does for you.

Your next step

List your top five vendors by the sensitivity of the data they hold. Send each one the ten questions above. Cerberus Cybersecurity builds vendor management policies and reviews third-party risk as part of our risk and compliance assessments. Contact us to start your inventory.