ForgeAwareness
0 of 6 complete0%
Module 12 min

Why Vendor Security Matters

TL;DR

You're only as secure as your weakest vendor.

Why Vendor Security Matters

When you hire a vendor, you're giving them access to your data or your systems.

If their security is weak, your security is weak.

Real Examples

  • A cloud vendor gets hacked → your data is at risk
  • A payment processor has weak security → customers' credit cards are at risk
  • A software vendor ships vulnerable code → your systems are at risk
  • An outsourced team doesn't protect data → your secrets leak

The Risk Chain

You ← Vendor 1 ← Vendor 2 ← Vendor 3 ← ...

Every vendor in your chain is a risk.

What You Can Control

You can't make vendors perfect. But you can:

  1. Screen them before signing
  2. Audit them (ask questions, request evidence)
  3. Contract them (include security requirements)
  4. Monitor them during the relationship

The Four Types of Vendor Risk

  1. Security Risk: Do they secure data? Protected infrastructure? Trained employees?
  2. Operational Risk: Can they deliver reliably? Do they have backups? Respond to incidents?
  3. Compliance Risk: Do they meet legal requirements (GDPR, HIPAA, PCI)? Are they audited?
  4. Financial Risk: Are they financially stable? Could they go out of business?

Your Role

  • Procurement: Include security requirements in contracts
  • Security: Assess vendor risk and recommend approval/rejection
  • Business: Understand the risk you're taking on
  • Legal: Ensure security requirements are enforceable

Knowledge check

Knowledge check 1

Why is vendor security your problem?