Their security posture becomes your incident.
February 24, 2026
When you connect a vendor to your systems or hand them your data, you inherit their security posture. That is a technical fact rather than a moral position. Their access is access, their credentials work on your systems, and their software runs with your permissions.
Several of the largest publicized breaches of the past decade began at a supplier rather than at the victim, which is why this is now a control family in nearly every framework.
Most organizations cannot produce an accurate vendor list, which makes everything downstream theoretical.
Build it from several imperfect sources and reconcile: accounts payable, which catches anything being paid for, the contract repository, your identity provider for anything with single sign on, and network or SaaS discovery for the things nobody told you about.
The gap between the finance list and the discovery list is usually the interesting part, and it is the same exercise as shadow IT discovery.
If every vendor gets the same long questionnaire, nobody completes it honestly and nobody reads the answers. The program becomes paperwork that protects nobody.
Tier by what the vendor could actually cause. The questions that matter are what data they hold, what access they have to your systems, whether a failure on their side stops your business, and whether they are subject to the same regulations you are.
The office snack supplier and the payroll provider with directory access are not the same risk and should not receive the same treatment.
For high tier vendors, ask for evidence rather than assertions. A SOC 2 Type II report or an ISO 27001 certificate is worth far more than a completed questionnaire, and it is the single most useful thing to request.
Read the report properly. Check the scope, because a SOC 2 covering a different product than the one you are buying is common. Check the period covered. Read the exceptions section, which is where the actual findings are and which almost nobody reads.
Standard questionnaires such as the Shared Assessments SIG or the Cloud Security Alliance CAIQ reduce the burden on vendors who get asked constantly. Reusing a standard set is better for everyone than inventing your own.
For the highest tier, a call with their security team tells you more in thirty minutes than any document. You learn quickly whether there is a real program behind the answers.
SecurityScorecard and Bitsight assess vendors from the outside using externally observable signals: exposed services, certificate hygiene, leaked credentials, and reputation data.
That is real information and it is not the same as knowing whether internal controls work. A company can have a clean external footprint and no access management at all.
Use ratings as a monitoring signal and a conversation starter, not as a verdict. A sudden drop is worth a phone call.
An assessment is a snapshot. The contract is what you can enforce for the next three years.
The clauses worth fighting for are breach notification within a defined and short period, the right to audit or to receive current attestations, security requirements stated specifically rather than as reasonable measures, restrictions on subcontracting and offshoring, data return and deletion on exit, and liability that is not capped at one month of fees.
Security teams are often brought in after signature. Getting involved before is the highest leverage change most programs can make.
Your vendor has vendors. If your critical SaaS provider runs on one cloud region and your backup provider runs on the same one, you have less redundancy than the contracts suggest.
You will rarely get a full picture down the chain. What you can do is ask high tier vendors about their critical dependencies and notice when the same names appear across many of your suppliers.
A once a year review means an incident at a vendor in month two is discovered in month twelve.
Practical continuous monitoring is a mix of ratings alerts, watching for breach news naming your vendors, tracking certificate expiry and renewals, and reviewing what access each integration still has.
That last one is the most neglected. Access granted for a project that ended three years ago is still access, and it is one of the most common findings in a real assessment.
Week 6 of the mentorship runs a real vendor assessment end to end, including writing the risk decision and the contract requirements.