Module 12 min
Why Vendor Security Matters
TL;DR
You're only as secure as your weakest vendor.
Why Vendor Security Matters
When you hire a vendor, you're giving them access to your data or your systems.
If their security is weak, your security is weak.
Real Examples
- A cloud vendor gets hacked → your data is at risk
- A payment processor has weak security → customers' credit cards are at risk
- A software vendor ships vulnerable code → your systems are at risk
- An outsourced team doesn't protect data → your secrets leak
The Risk Chain
You ← Vendor 1 ← Vendor 2 ← Vendor 3 ← ...
Every vendor in your chain is a risk.
What You Can Control
You can't make vendors perfect. But you can:
- Screen them before signing
- Audit them (ask questions, request evidence)
- Contract them (include security requirements)
- Monitor them during the relationship
The Four Types of Vendor Risk
- Security Risk: Do they secure data? Protected infrastructure? Trained employees?
- Operational Risk: Can they deliver reliably? Do they have backups? Respond to incidents?
- Compliance Risk: Do they meet legal requirements (GDPR, HIPAA, PCI)? Are they audited?
- Financial Risk: Are they financially stable? Could they go out of business?
Your Role
- Procurement: Include security requirements in contracts
- Security: Assess vendor risk and recommend approval/rejection
- Business: Understand the risk you're taking on
- Legal: Ensure security requirements are enforceable
Knowledge check
Knowledge check 1
Why is vendor security your problem?