Vendor Risk Management: You Keep the Liability
Your vendor's breach is your notification event, your fine, your lawsuit. How to tier by blast radius, what to put in contracts, and what SOC 2 hides.
Tier by Blast Radius, Not by Invoice
Almost every vendor risk program sorts vendors by spend, because spend is the number procurement already has. It is the wrong number.
Four questions produce the right tiering:
- Can this vendor's failure stop revenue collection within 48 hours? Payment processing, order management, the billing platform, the EHR that generates claims.
- Does this vendor hold regulated data? Health, payment card, personal data under state privacy law, controlled unclassified information.
- Does this vendor have privileged or persistent access into your environment? Managed service providers, identity providers, anything with an API key, anything with a VPN account, anything with a standing admin credential.
- Is this vendor single-sourced? If they fail, is there a substitute, and how long would switching take?
Answer yes to any of those and the vendor is Tier 1, whatever the contract is worth.
Run that against the actual list and the results are uncomfortable. A $9,000 a year e-signature tool with API access to every contract the company has signed rates higher than a $2 million facilities management contract. An offshore development contractor with repository access rates higher than the insurance broker. The tiering that matters has almost no correlation with the tiering procurement produced.
Target and the HVAC Contractor
In 2013, attackers entered Target's network using credentials stolen from Fazio Mechanical Services, a refrigeration and HVAC subcontractor with access to an external vendor billing portal. From there they moved laterally into the network and onto point of sale systems. Roughly 40 million payment cards and 70 million customer records were exposed. Target settled with state attorneys general for $18.5 million, and both the CEO and CIO departed.
Sort that vendor list by spend and an HVAC subcontractor lands near the bottom. Sort it by network access and the same vendor is Tier 1. The entire breach fits in the gap between those two orderings.
Security Questionnaires Measure the Ability to Answer Questionnaires
This is the thing the vendors selling questionnaire automation will never write down.
A security questionnaire is a self-assessment. The vendor answers it, the vendor grades itself, and the answers are filled in by whoever was assigned the task, frequently a sales engineer working from a previous response library. A mature vendor with weak controls produces a better questionnaire than an immature vendor with strong ones, because questionnaire quality measures process maturity in responding to questionnaires.
What to ask for instead, all of which is independently verifiable:
- The penetration test report, including the scope section. The summary is marketing. The scope section says what was excluded, and that is where the finding lives.
- The SOC 2 exceptions list and management responses. Not the opinion. The exceptions.
- Restore test records with dates. Not a backup policy. Evidence that a restore was performed and what it took.
- The subprocessor list. Who else touches your data.
- The cyber insurance declarations page. Limits, retention, and whether the policy would respond to the scenario you care about.
- The three most recent security incidents and their postmortems.
That last one is the most useful question in vendor diligence, and it filters hard. A vendor that says it has never had a security incident is either not looking or not telling you. Every organization of meaningful size has incidents. What separates them is whether incidents get detected, investigated, and written up. A vendor that hands over three honest postmortems is demonstrating a capability that no questionnaire can fake.
What a SOC 2 Report Actually Tells You
A SOC 2 report is the artifact most often mistaken for assurance. Reviewing a report is not the same as testing a control, and the report contains several things that most buyers never read.
- Type I is close to meaningless. It attests that controls were designed appropriately at a single point in time. Type II tests whether they operated over a period. If you are handed a Type I, ask when the Type II is coming.
- Read the scope section first. It defines which systems and which trust services criteria were examined. A report can be entirely clean and cover a fraction of the environment your data sits in.
- The exceptions matter more than the opinion. Management responses to exceptions tell you how the organization reacts when something is found.
- The period has ended. A report covering a period that closed eight months ago says nothing about the last eight months.
- Carve-out versus inclusive method. Under the carve-out method, the vendor's own subservice organizations were excluded from examination entirely. Their controls were not tested by anyone you are relying on.
- The auditor was selected and paid by the vendor. This does not make the report worthless. It does make it an opinion purchased by the party being examined.
Complementary User Entity Controls
Near the back of most SOC 2 reports is a section listing the controls the report assumes you are operating. Access reviews on your side. Configuration of the features the vendor provides. Enforcement of multi-factor authentication on accounts you administer.
These are the Complementary User Entity Controls, and they are the part of the report that allocates responsibility back to the customer. They are almost never read by the buyer. When a breach happens in a shared-responsibility model, this section is where the vendor's counsel will point.
The 2024 intrusions affecting customers of a major cloud data platform illustrate the point precisely. The platform itself was not breached. Customer tenants that had not enforced multi-factor authentication were accessed using credentials harvested from information-stealing malware on unrelated machines. Every affected customer could have held a clean SOC 2 report from the vendor. The control that failed was theirs.
Fourth-Party Risk Is Where the Concentration Hides
Your vendor has vendors. Their failure reaches you through a contract you never signed with a company you have never heard of.
In early 2022, the Lapsus$ group compromised a support engineer's workstation at Sitel, an outsourced customer support provider working for Okta. Okta confirmed that up to 366 customers were potentially impacted. The vendor those customers had assessed was Okta. The company that was breached was a subcontractor most of them did not know existed.
The subprocessor list is the document that would have surfaced it, and it is a routine thing to request.
The larger use of that list is mapping. Collect subprocessor lists across your Tier 1 vendors and lay them side by side. What emerges is usually not a list of independent risks but a concentration: six vendors running in the same cloud region, four using the same identity provider, three depending on the same payments processor, several using the same managed service provider.
That is portfolio risk, and no vendor risk platform will show it to you, because each vendor is assessed in isolation. A correlated failure takes out several suppliers at once, which is exactly the scenario a business continuity plan built around single-vendor failure does not cover.
Concentration You Have No Contract With
The February 2024 ransomware attack on Change Healthcare is the clearest illustration available. Attackers entered through a remote access portal that did not have multi-factor authentication enabled. The operational consequences ran for weeks and reached organizations across US healthcare: providers unable to submit claims, pharmacies unable to verify benefits, practices going without revenue long enough to need emergency funding.
Many of those organizations had no contractual relationship with Change Healthcare at all. Their exposure ran through clearinghouses and billing intermediaries. No questionnaire would have surfaced it, because the dependency was not in anyone's vendor list. It was in the plumbing.
The Contract Is the Control
Assessment tells you what the risk is. The contract determines who pays for it. This is the section no competing article writes, and it is the one with money attached.
- Breach notification measured in hours from discovery, not from confirmation. Twenty-four to seventy-two hours. The word confirmed is the loophole vendors use to delay notification for weeks while they investigate, which consumes the window in which your own regulatory clock is running.
- Audit rights that survive a SOC 2. Vendors routinely answer an audit request by sending their report instead. Say explicitly that the report does not satisfy the right.
- Recovery commitments as contract terms. RTO and RPO with service credits attached, not an SLA aspiration in a marketing page.
- Flow-down to subcontractors, plus notice of subprocessor changes and a right to object.
- Cyber liability minimums, with your organization named as additional insured, and a waiver of subrogation. Request the declarations page, not a certificate.
- Security breach indemnity carved out of the general liability cap. This is the one that matters most. A cap set at twelve months of fees on a $40,000 contract gives you $40,000 against a notification event that can cost millions. If you negotiate one term, negotiate this one.
- Data return and certified deletion on exit, with a deadline.
Run a coverage check across your Tier 1 agreements: what percentage contain each of the clauses above. The answer is usually low enough to be worth showing a board.
When a Critical Vendor Refuses
Every program hits this and no published guidance addresses it. A vendor you cannot replace declines to provide evidence, or answers with marketing.
What is actually available:
- Recognize the leverage window. You have leverage at renewal and almost none mid-term. Requirements that are not in the contract at signature are requests, not obligations.
- Price the refusal. Compensating controls, additional insurance, escrow arrangements, or segmentation that limits what the vendor can reach. Refusal has a cost; make it explicit.
- Get the refusal in writing, from someone with a title. That document is your evidence of reasonable diligence. It matters to your regulator, your insurer, and your own board.
- Start a replacement evaluation. Even if you never execute it, knowing the switching cost converts an unbounded dependency into a number.
- Accept it explicitly, or not at all. A documented, named, time-bounded risk acceptance is a governance act. An undocumented one is the finding.
Vendor Risk in M&A
Absent from every competing page, and the area where the exposure is largest for anyone acquiring a business.
The Vendor List in the Data Room Is the Wrong List
What you receive is the accounts payable ledger. What you need is the access list. They are different populations, and the difference is where the risk sits.
Missing from the AP ledger: software bought on corporate cards by individual departments, free-tier tools with production data in them, integrations authorized through OAuth that never generated an invoice, and contractors with standing credentials. Shadow SaaS does not appear in diligence because it does not appear in accounting.
What to Request Instead
- The identity provider's list of connected applications and OAuth grants, which shows what actually has access
- Expense reports filtered for software vendors
- The subprocessor lists of the target's Tier 1 vendors
- All agreements with assignment and change of control clauses flagged, since a vendor may be able to reprice or walk at closing
- Any critical vendor the target is operating with out of contract
The TSA Period
In a carve-out, the seller's vendors continue touching your data under the seller's contracts during the transition services period. Your remedy runs through a seller who is, commercially, now a stranger. Nobody is negotiating on your behalf, and the vendor has no direct obligation to you.
That exposure should be priced before signing, not discovered in month four.
Inherited Breach Liability
An incident that occurred before close but is discovered after it lands on the acquirer. Marriott's acquisition of Starwood is the canonical case: the intrusion dated to 2014, the acquisition closed in 2016, disclosure came in 2018, and the regulatory penalty fell on Marriott. The UK Information Commissioner's Office expressly cited the adequacy of due diligence at acquisition.
What a Program Actually Costs
No competing page will name a number, so here is an honest range. For a company under $500 million in revenue, a functioning program runs roughly half an FTE to two FTEs, plus tooling, plus legal time on contract language.
The more useful observation is where the value sits. Nearly all of it is in the top fifteen to twenty-five vendors. A program that attempts to assess four hundred vendors annually produces paperwork rather than safety, consumes the budget that should have gone into contract negotiation, and gives everyone involved the impression that the work is being done.
What the Board Should See
Not a heat map and not an average security score. Five things:
- Count of Tier 1 vendors, and which business function each one halts
- The concentration map: where multiple vendors share a single underlying dependency
- Accepted risks, with the name of the executive who accepted each one
- Contractual coverage rate across Tier 1 agreements
- Time to replace, per critical vendor
That last column is the one that changes conversations. A dependency with no estimated replacement time is not a managed risk.
Related Reading
Frequently Asked Questions
What is vendor risk management?
The practice of identifying, assessing, and controlling risk taken on through third parties a company depends on. The practical framing matters more than the definition: when a vendor is breached, it is generally the customer's notification event, the customer's regulatory exposure, and the customer's litigation. The vendor's obligation is limited to whatever the contract says, which in most mid-market agreements is a liability cap set at twelve months of fees. Vendor risk management exists because liability does not transfer with the work.
How should vendors be tiered?
By blast radius, not by spend. Four questions: can this vendor's failure stop revenue collection within 48 hours; does it hold regulated data; does it have privileged or persistent access into your environment; is it single-sourced. Any yes makes it Tier 1 regardless of contract value. Spend-based tiering systematically under-rates small vendors with deep access, which is precisely the profile of the HVAC subcontractor whose credentials were used to reach Target's network in 2013.
Are security questionnaires useful?
Marginally, and less than the effort they consume. A questionnaire is a self-assessment completed by the party being assessed, often from a previous response library. It measures a vendor's maturity at answering questionnaires, which correlates weakly with actual control effectiveness. Independently verifiable artifacts are worth more: the penetration test scope section, the SOC 2 exceptions list, dated restore test records, the subprocessor list, and the cyber insurance declarations page. The single most useful request is the three most recent incidents and their postmortems.
What does a SOC 2 report not tell you?
More than most buyers realize. Type I attests to design at a point in time and tests nothing. The scope section defines what was excluded and should be read first. The period covered has already ended, sometimes many months ago. Under the carve-out method the vendor's own subservice organizations were not examined at all. The auditor was selected and paid by the vendor. And the Complementary User Entity Controls section lists controls the report assumes the customer operates, which is where responsibility is allocated back to you and where vendor counsel will point after an incident.
What is fourth-party risk?
Risk arriving through your vendor's vendors. The 2022 Okta incident is the clearest example: attackers compromised a support engineer's workstation at Sitel, an outsourced support subcontractor, and Okta confirmed up to 366 customers were potentially impacted. The vendor those customers assessed was fine; its subcontractor was not. Requesting subprocessor lists surfaces these relationships, and mapping them across your Tier 1 vendors usually reveals concentration, several notionally independent vendors sharing one cloud region, identity provider, or processor.
What contract terms matter most for vendor security?
Breach notification in hours from discovery rather than from confirmation, since confirmation is the loophole used to delay. Audit rights that explicitly are not satisfied by sending a SOC 2. Recovery time and recovery point commitments with service credits. Security requirements flowed down to subcontractors with notice of subprocessor changes. Cyber liability minimums with your organization named as additional insured. Certified data deletion on exit. Most important: a security breach indemnity carved out of the general liability cap, because a cap of twelve months of fees is not a remedy for a notification event.
What do you do when a critical vendor refuses to cooperate?
Recognize that leverage exists at renewal and rarely mid-term. Price the refusal through compensating controls, additional insurance, or segmentation that limits reach. Get the refusal in writing from someone with a title, because that document evidences reasonable diligence to regulators, insurers and your board. Begin a replacement evaluation even if you never execute it, since knowing the switching cost converts an unbounded dependency into a number. Then accept the risk explicitly, named and time-bounded, or do not accept it. An undocumented acceptance is the audit finding.
How does vendor risk transfer in an acquisition?
Badly, and it is rarely diligenced properly. The vendor list in the data room is the accounts payable ledger, not the access list, and the gap between them holds shadow SaaS bought on corporate cards, OAuth-authorized integrations that never invoiced, and contractors with standing credentials. Request the identity provider's connected application list instead. Also flag assignment and change of control clauses, which may let vendors reprice at closing. During a transition services period the seller's vendors continue touching your data under the seller's contracts, with no direct obligation to you. And breaches that occurred pre-close but surface post-close land on the acquirer, as Marriott's acquisition of Starwood demonstrated.
MOVEit: The Vendor You Never Heard Of
In May and June of 2023, the Cl0p ransomware group exploited a zero-day vulnerability in MOVEit Transfer, a managed file transfer product from Progress Software. The resulting campaign reached roughly 2,770 organizations and more than 95 million individuals.
The detail that matters for vendor risk is how most victims were reached. A large share of affected organizations had never purchased MOVEit and had never heard of it. Their payroll provider used it. Their benefits administrator used it. Their pension fund's third-party administrator used it. The exposure arrived through a product two steps removed from any contract they had signed.
Three things follow.
First, the question do we use this product is the wrong question during a supply chain event. The right one is which of our vendors and their vendors use it, and answering that requires a subprocessor inventory maintained before the event, not assembled during it.
Second, a vendor questionnaire completed in January would have shown nothing. The vulnerability did not exist yet. Point-in-time assessment cannot address a risk that has not been discovered, which is an argument for contractual notification obligations rather than more frequent assessments.
Third, the organizations that responded well were the ones that could answer the question quickly. Not the ones with the most thorough assessments. The ones with an accurate list.
The typical liability cap in a mid-market vendor agreement, expressed as twelve months of fees paid. On a $40,000 contract that is $40,000 of recovery against a breach notification event that can cost several million. The cap is the single most important number in the agreement and it is almost never negotiated.
How Cloudskope Can Help
Cloudskope evaluates vendor and third-party exposure for mid-market companies and PE-backed portfolios, working from what vendors actually have access to rather than from what the accounts payable ledger shows. For sponsors, vendor and fourth-party concentration is a standard component of M&A Cyber and Technical Due Diligence, including the shadow SaaS and OAuth grants that never appear in a data room.
Where the question is what is connected to your environment right now, Cloudskope SARTUS answers it in six days: three days finding what current controls missed across Microsoft 365, Azure, dark web exposure and active compromise, and three days fixing it. Connected applications and standing OAuth grants are part of what that surfaces, and they are usually the vendors nobody on the finance side knew about.
Nothing here is legal advice. Contract language should be reviewed by counsel.
.png)