All articles

4-part series

Vendor & Third-Party Risk

A four-part series on the risk you inherit from everyone you do business with — how two real breaches began at a vendor rather than the victim, the five questions to ask before you sign with anyone, why outsourcing IT to an MSP does not outsource your security responsibility, and what a board should be asking about who has your data.

  1. 1

    Real-World Stories

    The Breach That Wasn't Yours

    You can lock down every system you own and still lose everything because of a vendor you trusted. Two real breaches show exactly how, and why the risk is bigger than most small organizations realize.

    7 min read
  2. 2

    Practical How-To

    The Five Questions to Ask Before You Sign With Any Vendor

    You do not need a formal vendor risk management program with scorecards and quarterly audits. You need five questions, asked consistently, before any vendor gets access to your data or your systems.

    6 min read
  3. 3

    Myths & Mistakes

    Your MSP Isn't Your Security Team

    Outsourcing your IT is a reasonable decision. Assuming it means someone else now owns your security risk is a different decision entirely, and most organizations make it without ever choosing to.

    7 min read
  4. 4

    Leadership Lens

    What Your Board Should Know About Who Has Your Data

    You do not need to read every vendor contract yourself to oversee this well. You need to ask who has your data, and recognize what a real answer sounds like versus a comfortable one.

    7 min read