Your third-party risk is your risk
Customers do not distinguish between a breach you caused and one your vendor caused. Neither, increasingly, do regulators.
Modern software is assembled rather than built. A typical application depends on a payment processor, an identity provider, an analytics platform, an email service, a support tool, and several hundred packages nobody has read. Each is a decision to trust an organisation you do not control with something you cannot afford to lose.
The security programme in most companies does not reflect this. Considerable effort goes into hardening code that runs inside the perimeter, and comparatively little into the dependencies through which the most consequential recent breaches have actually arrived.
Why the questionnaire does not help
Vendor security review in most organisations means a questionnaire completed once, at purchase, by the vendor’s sales engineer. It produces a document for the file and almost no information about ongoing posture.
It is a point-in-time attestation about a continuously changing system, and it asks the vendor to grade their own work. The questions that would actually reduce risk are different, and they are mostly about what happens when something goes wrong.
Questions that produce useful answers
- What data does this vendor hold, and what is the concrete impact if all of it becomes public? Answer specifically, not in categories.
- What access do they hold into our systems, and is it scoped to what they actually need or to what was convenient at integration time?
- How would we find out about a compromise — from them, from a monitoring signal of our own, or from a journalist?
- What is the notification commitment in the contract, and what is the remedy if they miss it?
- Could we operate without them for a week, and what does the degraded mode look like?
- Who reviews this relationship annually, and when did that last actually happen?
Concentration is the underrated risk
Individual vendor risk is manageable. Correlated vendor risk is not. If eleven of your critical dependencies run on the same cloud region, or authenticate through the same identity provider, you have a single point of failure distributed across eleven contracts and no single owner.
Very few organisations map this. Those that do generally find the picture more concentrated than they expected — and that discovery, rather than any questionnaire, is what tends to change the architecture.
Let's build the system your business will run on next.
Tell us where it hurts. We'll bring the architects, engineers, and delivery model to fix it — and scale it.