Your security is only as strong as the vendors you trust with your data. A payroll processor or MSP breach can become your breach. Here's a lightweight way to manage it.
Inventory who touches data
List every vendor with access to systems or information — email, accounting, CRM, IT support, cloud storage. Our website security tools guide covers the technical side.
Ask three questions
- Do they have a BAA / data-processing agreement? (required for PHI)
- Do they use MFA and encrypt data?
- What's their incident-notification timeline?
Monitor, don't set-and-forget
Re-check key vendors annually and watch for breach notices. Tie this into your security checklist.
Frequently Asked Questions
How do I assess a vendor's security?
Request: (1) SOC 2 Type II or ISO 27001 certification, (2) Security questionnaire (use CISA's template), (3) Incident response plan, (4) Data handling procedures, (5) Access control policies. Verify certifications are current. For cloud vendors, review their shared responsibility model. For payment processors, verify PCI DSS compliance.
What should I include in a vendor security agreement?
Include: (1) Security requirements and standards, (2) Data protection obligations, (3) Incident notification requirements, (4) Right to audit or third-party audit rights, (5) Data breach liability, (6) Termination and data return procedures, (7) Regular security reviews. Use a standard template and customize for each vendor's risk level.