Compliance & GRC

Third-Party Risk: Securing What You Do Not Control

Every organisation depends on suppliers who hold its data or connect to its systems, and a meaningful share of incidents arrive through them. The standard response is a vendor questionnaire programme — and the standard outcome is a large archive of completed spreadsheets that nobody revisits and that changed no decision.

Third-Party Risk: Securing What You Do Not Control

Why questionnaire programmes underperform

A self-assessment questionnaire asks a supplier to describe their own security. Responses are written by people motivated to close a sale, frequently by a sales engineer rather than a security practitioner, and are rarely verified.

The deeper problem is that most programmes apply the same process to every vendor regardless of exposure. A supplier with production database access and a supplier providing office snacks receive similar scrutiny, which spreads limited effort thinly and buries the genuinely important reviews in volume.

Tier by exposure

Effort should follow risk, and risk follows access rather than spend.

  • What data do they hold? Personal data, financial data, intellectual property, credentials.
  • What access do they have? Network connectivity, production access, administrative rights, and whether that access is standing or on demand.
  • How critical are they to operations? Could you continue trading if they were unavailable for a week?
  • Can they reach your customers? Suppliers embedded in your product or communicating on your behalf carry amplified risk.
  • Do they sub-contract? Their suppliers become your fourth-party exposure.
  • A small number of vendors will be high tier. Those deserve genuine assessment; the long tail deserves a light-touch process that does not consume the time the high tier needs.
Tier by exposure, not by contract value
Tier by exposure, not by contract value

Evidence that means something

  1. Request an independent report — a SOC 2 Type II or ISO 27001 certificate — and actually read it, including the scope statement and any exceptions rather than only the cover page.
  2. Check that the scope covers the service you are buying, which is a frequent mismatch.
  3. Ask for a penetration test summary and, more revealingly, how findings were remediated and retested.
  4. Ask how they would notify you of a breach affecting your data, and within what timeframe.
  5. For high-tier vendors, ask about their own supplier management.
  6. Verify a small number of critical claims independently rather than accepting every answer.
  7. Re-assess periodically — an assessment from three years ago describes an organisation that may no longer exist in that form.

Contracts are the real leverage

Assessment identifies risk; contract terms let you do something about it. Security requirements belong in the agreement rather than in a questionnaire response, and the terms worth securing are consistent.

Breach notification obligations with a defined timeframe; a right to audit or to receive assurance reports; requirements around sub-processors and prior notice of changes; data location and handling commitments; deletion or return of data at termination; and defined security standards with consequences for failure. These are far easier to obtain during procurement than afterwards, which is why security involvement before signature matters more than any post-hoc review.

Contract terms are the leverage you actually have
Contract terms are the leverage you actually have

Technical controls you own

Assessment and contracts are administrative. The controls you fully control are technical, and they matter more.

Give suppliers the minimum access necessary, prefer time-bound access over standing access, require the same authentication strength you apply internally, segment their connectivity so it cannot reach unrelated systems, log and monitor their activity as you would any privileged user, and ensure access is revoked promptly when a contract ends — which, like employee offboarding, is where orphaned access accumulates.

Related from TechBiz Security

Sources & further reading

Frequently asked questions

Do vendor security questionnaires reduce risk?
On their own, very little. They are self-assessed, rarely verified, and often completed by sales staff. They demonstrate that a process exists but change outcomes only when combined with independent evidence, contractual terms and technical access controls.
How should we prioritise vendors for assessment?
By exposure rather than contract value — what data they hold, what access they have, how critical they are to operations, and whether they can reach your customers. A small high-tier group deserves genuine assessment; the long tail needs a light-touch process.
Is a SOC 2 report from a vendor sufficient?
It is useful evidence, but it must be read rather than filed. Check that the scope covers the service you are purchasing, review any exceptions noted by the auditor, and confirm the report is current.
What security terms should be in a vendor contract?
Breach notification with a defined timeframe, a right to audit or receive assurance reports, sub-processor notification requirements, data location and handling commitments, deletion or return of data at termination, and defined security standards with consequences for failure.

Related reading

0 comments

Leave a comment

Comments are moderated before appearing.