Threats 7 min read

Supply Chain Attacks: The Backdoor You Forgot About

Your business might have perfect security. Your payroll provider might not. Your HVAC vendor with remote building access might not. Your cloud file-sharing service might not. Here is what to do about risks you cannot directly control.

The wake-up call

In 2024, a single software update from an IT management company called Kaseya was compromised. Attackers pushed ransomware through the update to 1,500 businesses β€” none of whom had done anything wrong. They trusted their IT provider. That trust cost them an average of $45,000 per business in recovery costs.

You Are Only as Secure as Your Weakest Vendor

Think about every company that has access to your data or systems: your payroll provider has Social Security numbers and bank details for every employee. Your accounting firm has your financial records. That cloud storage service has your customer contracts. The HVAC company has a remote login to your building management system. Your website host has your customer database. Your email marketing tool has your client list. Your IT support company has administrator access to everything.

Any one of these companies getting breached means your data gets exposed. And under most data protection laws, you are responsible for notifying your customers β€” not the vendor who got hacked.

Vendor TypeData They HaveRisk Level
Payroll / HR providerSSNs, bank accounts, salary dataCritical
MSP / IT supportAdmin access to all systemsCritical
Accounting firm / bookkeeperFinancial records, tax dataCritical
Cloud storage / file sharingContracts, customer data, IPHigh
Email marketing platformCustomer list, email historyHigh
Website host / e-commerceCustomer orders, payment recordsCritical
CRM systemCustomer details, pipeline, notesHigh

Step 1: Inventory Every Vendor

Most small business owners cannot name every company that has their data off the top of their head. That is the first problem. Pull your accounts payable list. Every recurring charge is a vendor. Every vendor either has your data or could get it. Make the list. It will be longer than you think. (The average 20-person company I have audited has 40-60 vendors with some level of data access.)

Step 2: Sort by Risk

Not all vendors are equal. Triage them into three buckets:

  • Tier 1 (Critical): Has your customer data, financial data, employee PII, or admin access to your systems. These get the full treatment below.
  • Tier 2 (Significant): Has business contact information, non-sensitive communications. Basic due diligence.
  • Tier 3 (Minimal): No data access (office cleaning, vending machine supplier). No action needed.

Step 3: Send the Security Questionnaire

For Tier 1 vendors, send a simple questionnaire. I have used this exact one with clients. It fits on one page:

Vendor Security Assessment β€” Quick Version

1. Do you require multi-factor authentication (MFA) for all user accounts that access customer data? [Yes / No]

2. Do you encrypt customer data at rest and in transit? [Yes / No]

3. Do you have a written incident response plan? [Yes / No]

4. Will you notify us within 24 hours of discovering a breach affecting our data? [Yes / No]

5. Do you undergo independent security testing (penetration test, SOC 2 audit, ISO 27001 certification)? [Yes / No] β€” If yes, can you share the latest summary report?

6. Do you carry cyber insurance that covers client data? [Yes / No]

7. How do you handle data deletion when our contract ends?

A vendor that answers "No" to questions 1, 2, or 4 is a serious risk. A vendor that will not answer at all is an even bigger risk.

Step 4: Put It in the Contract

If you have any leverage at all β€” and if you are paying them, you have leverage β€” add these three clauses to vendor contracts:

  • Data Processing Agreement (DPA): Required under GDPR, recommended everywhere else. Specifies what data they can process, for what purpose, and what security measures they must maintain.
  • Breach notification clause: "Vendor shall notify Client within 24 hours of discovering a security incident affecting Client data." 24 hours, not 30 days. You need time to respond.
  • Right to audit: "Client reserves the right to request evidence of Vendor's security controls annually." You may never exercise this. But having it means they cannot ignore your questionnaire.

Step 5: Have an Offboarding Plan

When you stop working with a vendor, your data should stop being in their systems. Send a formal offboarding request: delete our data, confirm in writing. For Tier 1 vendors, request a certificate of deletion. Most will push back β€” "our retention policy keeps backups for 90 days." Accept that, but get the timeline in writing. After 90 days, follow up.

The Bottom Line

You cannot prevent your vendors from getting breached. You can make sure that when they do, you find out fast, your notification obligations are clear, and your liability is limited. The difference between a vendor breach that costs you $10,000 and one that costs you $100,000 is usually just one thing: whether you had a contract that required them to tell you within 24 hours, or whether you found out from a news article three weeks later.