Your Weakest Security Control Belongs to Somebody Else
Small business breaches increasingly arrive through a vendor with legitimate access. A right-sized third-party risk program, including the register and contract language.
The short answer
When a small business is breached through a vendor, no security tooling fires, because nothing malicious happened: somebody with permission used their permission. A right-sized program starts with an inventory pulled from accounts payable, your identity platform, and your remote access tool, then tiers vendors into three levels.
A 40-person company can harden its own environment fairly well. What it cannot easily control is the bookkeeping firm with remote access to the accounting server, the marketing agency with admin rights to the website, the practice management vendor holding patient records, and the IT provider with domain administrator credentials to everything.
Each of those relationships is a legitimate access path that bypasses most of what you installed. When a small business gets breached through a vendor, none of the security tooling fires, because nothing malicious happened. Somebody with permission used their permission.
Build the list before you build the program
Almost no small business has a complete inventory of who has access to what. Start there and do not skip to controls.
Pull the list from three places, because none of them is complete on its own. Accounts payable will show you who you pay, which catches the software nobody told you about. Your identity platform will show which external accounts exist in your tenant. Your remote access tool will show who connects and how.
For each vendor record five things. What data they touch. What access they hold and how they authenticate. What happens to your business if they are down for a week. What happens if they are breached. Who at your company owns the relationship.
That last field solves more problems than the rest combined. Ownerless vendor relationships are where old access lives forever.
Tier them, then stop treating them the same
Three tiers is enough.
Critical vendors hold regulated data, have privileged access to your systems, or would halt operations if they failed. Your IT provider, your practice management or case management system, your payroll processor, your accounting firm. These get real diligence, annual review, and contract terms.
Important vendors touch business data without regulated content and would be disruptive but survivable. Your CRM, your file storage, your marketing platform. These get a questionnaire at onboarding and a light annual check.
Everything else gets an inventory entry and nothing more. A subscription to a stock photo library does not need a security review, and pretending otherwise is how programs collapse under their own weight.
Diligence that is proportionate
For critical vendors, ask for four things. A SOC 2 Type II report or equivalent independent attestation, reviewed rather than filed. Confirmation of MFA on all access to your environment. Their incident notification commitment, with a number of hours in it. Their cyber liability insurance limits.
For your IT provider specifically, add two more. Whether their own remote access tooling requires MFA, and whether their technicians use individual named accounts rather than a shared credential. Both have been factors in incidents where a compromise at a provider reached many client environments at once.
The important vendor tier gets a short questionnaire, ten to fifteen questions, sent once at onboarding.
Contract language worth insisting on
Small businesses often underestimate their bargaining power, particularly with regional vendors who want the logo.
Four provisions worth asking for. Breach notification within a defined number of hours, not a vague promptness standard. A right to terminate for a material security failure. Data return and certified deletion on termination, with a timeline. A liability cap that is not comically low relative to the data involved.
If you are in a regulated field, add the required agreements: a business associate agreement for protected health information, and whatever flow-down obligations your own client contracts impose on you.
The access hygiene that matters more than paperwork
Diligence is annual. Access is daily, and this is where the real risk sits.
Every vendor gets individual named accounts, never a shared login. Vendor accounts require MFA with no exceptions for convenience. Standing access is replaced with time-bound access wherever the vendor's workflow permits it, so the bookkeeper who needs the server two days a month does not have a permanent path the other 28.
Review vendor accounts quarterly and disable what has not been used. A remarkable proportion of vendor accounts in small business environments belong to companies the business stopped working with years ago.
And when a relationship ends, run an offboarding: disable accounts, revoke API keys and OAuth grants, rotate any shared credential they knew, and confirm data return in writing.
Get the register
The Vendor Risk Register is a workbook with the inventory sheet, automatic tiering based on data and access answers, a diligence tracker with review dates, the short questionnaire for the important tier, the contract clause checklist, and an offboarding checklist for ending a relationship cleanly.
Building the initial list takes an afternoon. Maintaining it takes about an hour a quarter, and it is the artifact your insurer, your auditor, and your largest client will all eventually ask to see.
Frequently asked questions
How should a small business manage vendor security risk?
Build a complete inventory first, pulled from accounts payable, your identity platform, and your remote access tool, because no single source is complete. Then tier vendors into critical, important, and routine, and apply diligence proportionate to the tier. Treating every vendor the same is how programs collapse under their own weight.
What should I ask my IT provider about their own security?
Two questions beyond standard diligence: whether their remote access tooling requires multi-factor authentication, and whether their technicians use individual named accounts rather than a shared credential. Both have been factors in incidents where a compromise at a provider reached many client environments at once.
What contract terms should I ask a vendor for?
Breach notification within a defined number of hours rather than a vague promptness standard, a right to terminate for material security failure, data return and certified deletion on termination with a timeline, and a liability cap that is not comically low relative to the data involved.
How do I offboard a vendor securely?
Disable their accounts, revoke API keys and OAuth grants, rotate any shared credential their staff knew, and confirm data return or deletion in writing. Then review quarterly, because a remarkable proportion of vendor accounts in small business environments belong to companies the business stopped working with years ago.
Related reading
- Your AI Tools Have Logins Now, and Nobody Is Managing Them
- The Voice on the Phone Is Not Your CFO
- MFA Stopped Being Enough About Two Years Ago
- The Microsoft 365 Settings Most Phoenix Businesses Never Turned On
- Anyone Can Send Email as Your Company Until You Fix This
- Offboarding an Employee in 60 Minutes
