Every organisation depends on suppliers who hold its data or connect to its systems, and a meaningful share of incidents arrive through them. The standard response is a vendor questionnaire programme — and the standard outcome is a large archive of completed spreadsheets that nobody revisits and that changed no decision.
Why questionnaire programmes underperform
A self-assessment questionnaire asks a supplier to describe their own security. Responses are written by people motivated to close a sale, frequently by a sales engineer rather than a security practitioner, and are rarely verified.
The deeper problem is that most programmes apply the same process to every vendor regardless of exposure. A supplier with production database access and a supplier providing office snacks receive similar scrutiny, which spreads limited effort thinly and buries the genuinely important reviews in volume.
Tier by exposure
Effort should follow risk, and risk follows access rather than spend.
- What data do they hold? Personal data, financial data, intellectual property, credentials.
- What access do they have? Network connectivity, production access, administrative rights, and whether that access is standing or on demand.
- How critical are they to operations? Could you continue trading if they were unavailable for a week?
- Can they reach your customers? Suppliers embedded in your product or communicating on your behalf carry amplified risk.
- Do they sub-contract? Their suppliers become your fourth-party exposure.
- A small number of vendors will be high tier. Those deserve genuine assessment; the long tail deserves a light-touch process that does not consume the time the high tier needs.
Evidence that means something
- Request an independent report — a SOC 2 Type II or ISO 27001 certificate — and actually read it, including the scope statement and any exceptions rather than only the cover page.
- Check that the scope covers the service you are buying, which is a frequent mismatch.
- Ask for a penetration test summary and, more revealingly, how findings were remediated and retested.
- Ask how they would notify you of a breach affecting your data, and within what timeframe.
- For high-tier vendors, ask about their own supplier management.
- Verify a small number of critical claims independently rather than accepting every answer.
- Re-assess periodically — an assessment from three years ago describes an organisation that may no longer exist in that form.
Contracts are the real leverage
Assessment identifies risk; contract terms let you do something about it. Security requirements belong in the agreement rather than in a questionnaire response, and the terms worth securing are consistent.
Breach notification obligations with a defined timeframe; a right to audit or to receive assurance reports; requirements around sub-processors and prior notice of changes; data location and handling commitments; deletion or return of data at termination; and defined security standards with consequences for failure. These are far easier to obtain during procurement than afterwards, which is why security involvement before signature matters more than any post-hoc review.
Technical controls you own
Assessment and contracts are administrative. The controls you fully control are technical, and they matter more.
Give suppliers the minimum access necessary, prefer time-bound access over standing access, require the same authentication strength you apply internally, segment their connectivity so it cannot reach unrelated systems, log and monitor their activity as you would any privileged user, and ensure access is revoked promptly when a contract ends — which, like employee offboarding, is where orphaned access accumulates.
Related from TechBiz Security
Sources & further reading
- NIST SP 800-161 — Cybersecurity Supply Chain Risk Management
- CISA — Supply Chain Security
- NIST — Cybersecurity Framework
- CIS Critical Security Controls
0 comments
Leave a comment