This series opened with two breaches that hit hundreds of small businesses and nonprofits through vendors, not through anything those organizations did wrong on their own systems. It moved through the specific questions worth asking before signing any vendor, and the myth that outsourcing IT means outsourcing security responsibility. This final post is about who is actually accountable for all of it.
In most small organizations, the honest answer is nobody, specifically. Vendor decisions get made by whoever needs the tool fastest. Contracts get signed by whoever has signing authority, often without a second read for data or security terms. Nobody owns the full picture of which vendors hold what, because nobody was ever asked to.
"The question a board needs to answer is not 'is our vendor secure.' It is 'do we know which vendors matter most, and did anyone ever check.'"
You do not need to become a contracts expert or a security specialist to close this gap. You need to ask a small number of questions, consistently, and expect specific answers rather than reassurance. What follows are five that belong in your next leadership or board conversation.
This question sounds basic. In most small businesses and nonprofits, it is genuinely unanswered. Vendors accumulate over years, added by different staff for different projects, and no one has ever consolidated the list. A strong answer names a real, if imperfect, inventory: which platforms hold donor, client, financial, or employee data, and who at the organization manages each relationship.
A weak answer is "I'm not sure, IT would know" followed by IT not actually knowing either, because the list was never anyone's job to keep.
This question forces a concrete answer instead of an abstract one. A strong response names the vendor, describes what data or access they hold, and gives a realistic picture of what your organization would need to do: who to notify, what regulatory obligations apply, and roughly what it would cost in time and reputation.
Both incidents that opened this series show what this looks like in practice. The nonprofits affected by the Blackbaud breach did not choose when or how their donors found out, the vendor's timeline and disclosure decisions drove that. Knowing in advance what your exposure would look like is the difference between a plan and a scramble.
This is a governance question, not a legal one. You are not asking leadership to interpret contract law. You are asking whether anyone has actually read these sections for your highest-risk vendors, as covered in the previous post's questions, and whether the answers are documented somewhere accessible.
A strong answer points to a specific review that happened, even an informal one. A weak answer assumes the standard terms are fine because nobody flagged a problem, which usually means nobody looked.
Given how common the "our MSP handles security" assumption is, this deserves its own direct question at the leadership level. A strong answer describes the actual scope of the MSP relationship in plain terms: what they monitor, what they do not, and who is responsible for the gap.
A weak answer is a confident "they take care of all of that" from someone who has not actually read the contract. This is precisely the myth addressed in the previous post, and it is common enough that it is worth asking even of organizations that feel confident about their answer.
Vendor relationships are not static. New tools get added. Old ones get forgotten but never fully removed. A vendor that was low-risk when you signed up may hold far more sensitive data two years later, because the relationship expanded without anyone reassessing it.
A strong answer names a specific person accountable for tracking the organization's vendor landscape and flagging changes to leadership, the same accountability principle covered in the leadership post from this blog's foundational series, applied here to vendors specifically. A weak answer is that nobody owns it, or that it is everyone's job, which functions the same as nobody's.
What a good answer sounds like
Across all five questions, the pattern that separates a strong answer from a weak one is the same: specificity versus reassurance. "We're covered" is not an answer. "Our MSP contract covers patching and monitoring but not incident response, and we identified that gap in our last review" is an answer. The second version took someone actually checking. The first is usually a guess dressed up as confidence.
What this series has covered
Over four posts, this series moved from two real breaches that hit organizations entirely through their vendors, through the specific questions worth asking before signing any contract, through the myth that outsourcing IT means outsourcing security, and now to the leadership questions that keep the whole thing from quietly sliding back into nobody's job.
- Post 1 Real-World Stories: The breach that wasn't yours, how the Kaseya and Blackbaud incidents hit hundreds of small organizations through their vendors.
- Post 2 Practical How-To: The five questions to ask before you sign with any vendor, no formal program required.
- Post 3 Myths and Mistakes: Your MSP isn't your security team, four assumptions that quietly shift risk to nobody.
- Post 4 Leadership Lens: What your board should know about who has your data, and what good answers actually sound like.
The through-line is the same one that runs through everything on this blog: security that is defensible, not enterprise complexity for its own sake. You do not need to eliminate vendor risk. You need to know where it lives, ask the right people the right questions, and be able to explain the decisions you made if something ever goes wrong.
Ready for a clear picture of your vendor exposure?
A 30-day Security Business Review maps your critical vendors alongside your internal risk and gives leadership a prioritized, defensible way to close the gaps that matter most.
Start a Conversation