Think about every platform your business runs on. Your accounting software. Your CRM. Your payroll provider. Your IT management tools. Your cloud storage. Your HR system.
Now think about how many of those vendors have access to your data, your systems, or your employees' credentials — and ask yourself when you last checked whether they're actually secure.
For most small businesses, the honest answer is never. That matters, because attackers increasingly reach smaller targets not directly, but through the vendors those targets trust.
Why Vendor Risk Is Your Risk
The SolarWinds attack compromised thousands of organizations through a single trusted software update. The Kaseya attack hit MSPs and their clients through one vulnerability in a remote management tool. The MOVEit breach reached hundreds of companies that didn't know their file-transfer vendor was exposed.
Those are enterprise headlines, but the mechanism — compromise the vendor, use that access to reach its clients — applies to small businesses too. Your bookkeeper has access to your books. Your HR platform holds your entire employee roster. Your IT provider can touch every machine on your network.
You're responsible for the access you grant, even when it's someone else who gets breached. Regulators, clients, and cyber insurers will all ask what you did to vet the vendor — not just what the vendor did wrong.
Step 1: Know What You Have
You can't manage risk you haven't identified. Start with a vendor inventory: every platform, service, and partner with access to your systems or data. Include:
- SaaS platforms — CRM, accounting, HR, project management
- IT management tools — RMM, patching, endpoint protection
- Cloud infrastructure — storage, backup, hosting, DNS
- Professional service providers — accounting firm, payroll processor, outside counsel
- Communication platforms — email, video conferencing, phone system
- Anyone else holding credentials to your environment
Most businesses doing this for the first time are surprised by how many vendors they have — and how little they know about most of them.
Step 2: Tier Your Vendors by Risk
Not every vendor needs the same scrutiny. Tier them by what they can reach and what the damage would be if they were compromised.
Treat as critical
- Admin access to your systems
- Financial data
- Payroll and HR data
- Your IT provider
- Backup and recovery platform
Review annually
- CRM with client data
- Email and calendar
- Project management tools
- Cloud file storage
Baseline review
- Marketing and analytics tools
- Collaboration apps
- No system access
- No sensitive data
Step 3: Ask the Right Questions
For your high-risk vendors, you should be able to answer all five of these. If you can't, that's a conversation to have with the vendor — or a reason to look at alternatives.
Do they have a SOC 2 Type II report?
It means an independent auditor tested their controls over months, not on a single day. Not having one isn't automatically disqualifying, but you should know either way.
What's their breach notification commitment?
If they're breached and your data is involved, how fast are they required to tell you? Contractually — not "we'll let you know."
Which of their employees can see your data?
Can their support team access it? Who holds admin rights? Is that access logged and reviewed?
Do they enforce MFA internally?
A vendor that doesn't require MFA for its own staff has accounts that are easier to compromise — and those accounts can reach your data.
Who are their subprocessors?
Most SaaS platforms rely on other vendors for hosting and specific functions. Do you know who they are and what they can see?
Step 4: Tighten Access
However well you vet a vendor, least privilege still applies: vendors get only the access they need, only for as long as they need it.
- Give each vendor its own account instead of a shared admin login, so you can cut off one without affecting the others
- Review vendor accounts quarterly and remove any belonging to vendors you no longer use — more common than you'd think
- Require MFA on every vendor-accessible account where possible
- Document what each vendor can reach, so you know exactly what to lock down if one is breached
Step 5: Read the Contract for Security Terms
Your vendor agreements should address:
- Data ownership — your data is yours, not theirs
- Breach notification — timelines and method
- Right to audit — access to their security reports and certifications
- Data deletion — how and when your data is removed if you leave
- Subprocessor changes — notice when they add new parties with access to your data
Most vendor contracts are written in the vendor's favor. That doesn't mean you can't negotiate. For high-risk vendors, it's worth having counsel review the agreement.
A Practical Starting Point
If this feels like a lot, here's the one thing to do in the next 30 days: build the list. Write down every vendor with access to your systems. Tier them. For the top three to five, request their SOC 2 report and read their breach notification terms.
That's vendor risk management — not perfect, but meaningful. You don't need enterprise GRC software. You need a spreadsheet and a few focused hours.
Free Vendor Risk Review
We'll help you map which vendors can reach your systems and data, tier them by risk, and identify where your third-party exposure actually sits.
DM us "AUDIT" on LinkedIn or schedule a free consultation · (646) 791-2137