Supply Chain Attacks: The Backdoor You Forgot About
Your business might have perfect security. Your payroll provider might not. Your HVAC vendor with remote building access might not. Your cloud file-sharing service might not. Here is what to do about risks you cannot directly control.
The wake-up call
In 2024, a single software update from an IT management company called Kaseya was compromised. Attackers pushed ransomware through the update to 1,500 businesses β none of whom had done anything wrong. They trusted their IT provider. That trust cost them an average of $45,000 per business in recovery costs.
You Are Only as Secure as Your Weakest Vendor
Think about every company that has access to your data or systems: your payroll provider has Social Security numbers and bank details for every employee. Your accounting firm has your financial records. That cloud storage service has your customer contracts. The HVAC company has a remote login to your building management system. Your website host has your customer database. Your email marketing tool has your client list. Your IT support company has administrator access to everything.
Any one of these companies getting breached means your data gets exposed. And under most data protection laws, you are responsible for notifying your customers β not the vendor who got hacked.
| Vendor Type | Data They Have | Risk Level |
|---|---|---|
| Payroll / HR provider | SSNs, bank accounts, salary data | Critical |
| MSP / IT support | Admin access to all systems | Critical |
| Accounting firm / bookkeeper | Financial records, tax data | Critical |
| Cloud storage / file sharing | Contracts, customer data, IP | High |
| Email marketing platform | Customer list, email history | High |
| Website host / e-commerce | Customer orders, payment records | Critical |
| CRM system | Customer details, pipeline, notes | High |
Step 1: Inventory Every Vendor
Most small business owners cannot name every company that has their data off the top of their head. That is the first problem. Pull your accounts payable list. Every recurring charge is a vendor. Every vendor either has your data or could get it. Make the list. It will be longer than you think. (The average 20-person company I have audited has 40-60 vendors with some level of data access.)
Step 2: Sort by Risk
Not all vendors are equal. Triage them into three buckets:
- Tier 1 (Critical): Has your customer data, financial data, employee PII, or admin access to your systems. These get the full treatment below.
- Tier 2 (Significant): Has business contact information, non-sensitive communications. Basic due diligence.
- Tier 3 (Minimal): No data access (office cleaning, vending machine supplier). No action needed.
Step 3: Send the Security Questionnaire
For Tier 1 vendors, send a simple questionnaire. I have used this exact one with clients. It fits on one page:
Vendor Security Assessment β Quick Version
1. Do you require multi-factor authentication (MFA) for all user accounts that access customer data? [Yes / No]
2. Do you encrypt customer data at rest and in transit? [Yes / No]
3. Do you have a written incident response plan? [Yes / No]
4. Will you notify us within 24 hours of discovering a breach affecting our data? [Yes / No]
5. Do you undergo independent security testing (penetration test, SOC 2 audit, ISO 27001 certification)? [Yes / No] β If yes, can you share the latest summary report?
6. Do you carry cyber insurance that covers client data? [Yes / No]
7. How do you handle data deletion when our contract ends?
A vendor that answers "No" to questions 1, 2, or 4 is a serious risk. A vendor that will not answer at all is an even bigger risk.
Step 4: Put It in the Contract
If you have any leverage at all β and if you are paying them, you have leverage β add these three clauses to vendor contracts:
- Data Processing Agreement (DPA): Required under GDPR, recommended everywhere else. Specifies what data they can process, for what purpose, and what security measures they must maintain.
- Breach notification clause: "Vendor shall notify Client within 24 hours of discovering a security incident affecting Client data." 24 hours, not 30 days. You need time to respond.
- Right to audit: "Client reserves the right to request evidence of Vendor's security controls annually." You may never exercise this. But having it means they cannot ignore your questionnaire.
Step 5: Have an Offboarding Plan
When you stop working with a vendor, your data should stop being in their systems. Send a formal offboarding request: delete our data, confirm in writing. For Tier 1 vendors, request a certificate of deletion. Most will push back β "our retention policy keeps backups for 90 days." Accept that, but get the timeline in writing. After 90 days, follow up.
The Bottom Line
You cannot prevent your vendors from getting breached. You can make sure that when they do, you find out fast, your notification obligations are clear, and your liability is limited. The difference between a vendor breach that costs you $10,000 and one that costs you $100,000 is usually just one thing: whether you had a contract that required them to tell you within 24 hours, or whether you found out from a news article three weeks later.