Vendor & Third-Party Risk
Leadership LensPart 4 of 4

What Your Board Should Know About Who Has Your Data

You do not need to read every vendor contract yourself to oversee this well. You need to ask who has your data, and recognize what a real answer sounds like versus a comfortable one.

7 min read

This series opened with two breaches that hit hundreds of small businesses and nonprofits through vendors, not through anything those organizations did wrong on their own systems. It moved through the specific questions worth asking before signing any vendor, and the myth that outsourcing IT means outsourcing security responsibility. This final post is about who is actually accountable for all of it.

In most small organizations, the honest answer is nobody, specifically. Vendor decisions get made by whoever needs the tool fastest. Contracts get signed by whoever has signing authority, often without a second read for data or security terms. Nobody owns the full picture of which vendors hold what, because nobody was ever asked to.

"The question a board needs to answer is not 'is our vendor secure.' It is 'do we know which vendors matter most, and did anyone ever check.'"

You do not need to become a contracts expert or a security specialist to close this gap. You need to ask a small number of questions, consistently, and expect specific answers rather than reassurance. What follows are five that belong in your next leadership or board conversation.

1
Ask this first
How many vendors actually touch our sensitive data, and do we have a list?

This question sounds basic. In most small businesses and nonprofits, it is genuinely unanswered. Vendors accumulate over years, added by different staff for different projects, and no one has ever consolidated the list. A strong answer names a real, if imperfect, inventory: which platforms hold donor, client, financial, or employee data, and who at the organization manages each relationship.

A weak answer is "I'm not sure, IT would know" followed by IT not actually knowing either, because the list was never anyone's job to keep.

Why this question matters
You cannot evaluate risk in relationships you have not identified. This is the same inventory logic from the earlier "know what you are protecting" step in this blog's foundational series, applied to vendors instead of internal systems.
2
Ask this about our biggest exposure
If our most critical vendor were breached tomorrow, what would happen to us specifically?

This question forces a concrete answer instead of an abstract one. A strong response names the vendor, describes what data or access they hold, and gives a realistic picture of what your organization would need to do: who to notify, what regulatory obligations apply, and roughly what it would cost in time and reputation.

Both incidents that opened this series show what this looks like in practice. The nonprofits affected by the Blackbaud breach did not choose when or how their donors found out, the vendor's timeline and disclosure decisions drove that. Knowing in advance what your exposure would look like is the difference between a plan and a scramble.

Why this question matters
Third-party involvement in breaches is up sharply, now present in nearly half of all breaches tracked in Verizon's most recent Data Breach Investigations Report. This is no longer an edge case worth skipping in a risk conversation.
3
Ask this about contracts
What do our contracts actually say about breach notification, liability, and getting our data back?

This is a governance question, not a legal one. You are not asking leadership to interpret contract law. You are asking whether anyone has actually read these sections for your highest-risk vendors, as covered in the previous post's questions, and whether the answers are documented somewhere accessible.

A strong answer points to a specific review that happened, even an informal one. A weak answer assumes the standard terms are fine because nobody flagged a problem, which usually means nobody looked.

Why this question matters
Contracts negotiated once, years ago, by whoever was in the room at the time, often do not reflect what the organization would want today. A periodic review is a governance habit, not a one-time task.
4
Ask this about the MSP relationship specifically
What does our IT provider actually cover, and where does that coverage end?

Given how common the "our MSP handles security" assumption is, this deserves its own direct question at the leadership level. A strong answer describes the actual scope of the MSP relationship in plain terms: what they monitor, what they do not, and who is responsible for the gap.

A weak answer is a confident "they take care of all of that" from someone who has not actually read the contract. This is precisely the myth addressed in the previous post, and it is common enough that it is worth asking even of organizations that feel confident about their answer.

Why this question matters
The gap between assumed and actual MSP coverage is one of the most common blind spots in small organization security, and it is invisible until someone specifically asks about it.
5
Ask this about accountability
Who owns vendor risk here, and how will I know if that changes?

Vendor relationships are not static. New tools get added. Old ones get forgotten but never fully removed. A vendor that was low-risk when you signed up may hold far more sensitive data two years later, because the relationship expanded without anyone reassessing it.

A strong answer names a specific person accountable for tracking the organization's vendor landscape and flagging changes to leadership, the same accountability principle covered in the leadership post from this blog's foundational series, applied here to vendors specifically. A weak answer is that nobody owns it, or that it is everyone's job, which functions the same as nobody's.

Why this question matters
Without a named owner, vendor risk drifts silently upward as an organization adds tools and relationships over time, and nobody notices until something goes wrong.

What a good answer sounds like

Across all five questions, the pattern that separates a strong answer from a weak one is the same: specificity versus reassurance. "We're covered" is not an answer. "Our MSP contract covers patching and monitoring but not incident response, and we identified that gap in our last review" is an answer. The second version took someone actually checking. The first is usually a guess dressed up as confidence.

The test to apply: After hearing an answer to any of these five questions, ask yourself whether you could describe a specific decision that was made or a specific fact that was verified. If the answer is just a feeling of confidence with nothing behind it, the conversation is not finished.

What this series has covered

Over four posts, this series moved from two real breaches that hit organizations entirely through their vendors, through the specific questions worth asking before signing any contract, through the myth that outsourcing IT means outsourcing security, and now to the leadership questions that keep the whole thing from quietly sliding back into nobody's job.

The four-post series at a glance
  • Post 1 Real-World Stories: The breach that wasn't yours, how the Kaseya and Blackbaud incidents hit hundreds of small organizations through their vendors.
  • Post 2 Practical How-To: The five questions to ask before you sign with any vendor, no formal program required.
  • Post 3 Myths and Mistakes: Your MSP isn't your security team, four assumptions that quietly shift risk to nobody.
  • Post 4 Leadership Lens: What your board should know about who has your data, and what good answers actually sound like.

The through-line is the same one that runs through everything on this blog: security that is defensible, not enterprise complexity for its own sake. You do not need to eliminate vendor risk. You need to know where it lives, ask the right people the right questions, and be able to explain the decisions you made if something ever goes wrong.

The ask for this week: Take question one into your next leadership conversation: how many vendors actually touch our sensitive data, and do we have a list? If the honest answer is no, that is this week's starting point.

Ready for a clear picture of your vendor exposure?

A 30-day Security Business Review maps your critical vendors alongside your internal risk and gives leadership a prioritized, defensible way to close the gaps that matter most.

Start a Conversation
Leadership Lens Board Governance Third-Party Risk Vendor Risk Executive Communication vCISO