Your Biggest Risk Is Someone Else’s Company
Here’s an uncomfortable truth I’ve had to explain in a lot of boardrooms: some of your most dangerous risk isn’t inside your company at all. It’s sitting in the systems of vendors you signed a contract with and then mostly forgot about. You spent the year hardening your own environment, and meanwhile the softest way in is a company you onboarded eighteen months ago and haven’t thought about since.
Every integration is a door. Every SaaS tool with access to your data is a door. Every contractor’s laptop is a door. You can build a beautiful fortress — and then hand keys to sixty different companies of wildly varying security maturity, and an attacker only needs the weakest one. They don’t have to beat your security. They have to beat the least-funded vendor in your supply chain, and then walk in through the door you propped open for them yourself.
The attack comes through the trusted door
The reason supply-chain attacks work so well is that the access is already legitimate. When an attacker compromises a vendor that has real, sanctioned access to your environment, your defenses often wave them right through — because from the inside it doesn’t look like an intrusion. It looks like the integration doing exactly what it’s allowed to do. That’s the nightmare version: not someone breaking a window, but someone walking in with a key you cut for them, past monitoring that was never tuned to be suspicious of a partner.
I’ve had to explain to more than one leadership team that our biggest single point of failure that quarter was a company they’d never heard of — a small vendor, deep in a workflow, with far more access than anyone had ever re-examined. That’s the pattern, over and over. The risk isn’t the vendors you scrutinize. It’s the ones that quietly accumulated access while nobody was looking.
Questionnaire theater
Most vendor-risk programs are theater. You send a 200-question spreadsheet, the vendor’s sales engineer fills it out optimistically, you file it in a folder nobody opens again, everyone feels compliant, and nothing is actually safer. I’ve built these programs, and I’ve watched them curdle into a box-checking ritual inside of a year — a process that generates paperwork and the comfortable illusion of diligence, while the real access sits unexamined.
The questionnaire isn’t worthless, but it answers the wrong question. It tells you what the vendor is willing to claim about themselves on a form. It tells you nothing about what they’d actually do the morning they get breached, or how much of your data they can really reach, or whether the access you granted three years ago still matches what they need today.
Tier your vendors or run out of effort
What actually reduced risk, when I ran vendor programs, was ruthless prioritization. Not every vendor matters equally, and treating them as if they do is how you burn your whole budget on paperwork before you reach the ones that could sink you. The vendor that processes your payments or holds your customer data earns real scrutiny — technical review, contractual teeth, a concrete plan for the day they have an incident. The vendor that runs the office coffee app gets a light touch and a calendar reminder.
The contract is a control, not paperwork
People forget that the contract is one of the strongest security controls you have with a vendor, because it’s the one moment you have real leverage — before you’ve signed. That’s when you get a right to audit, a breach-notification clause with an actual deadline measured in hours instead of “promptly,” minimum security requirements with consequences attached, and clarity on exactly what data they can hold and for how long. Try to negotiate any of that after an incident and you’ll discover how little leverage you have left.
Offboarding is where it quietly rots
Everyone focuses on onboarding a vendor — the review, the questionnaire, the contract. Almost nobody focuses on the other end, and that’s where the real decay happens. You stop using a tool, the subscription lapses, the team moves on — but the integration is still live, the API key still works, the access token nobody rotated is still valid. I’ve walked into companies and found active credentials for vendors they hadn’t done business with in years. That’s not a door you forgot to lock. It’s a door to a building you forgot you owned.
So vendor offboarding gets treated as a security event, not a procurement afterthought. When a relationship ends, the access ends with it — keys revoked, tokens killed, integrations torn down, and someone actually confirming it happened rather than assuming it did. The same discipline applies to access that’s merely stale: a vendor whose scope crept far beyond what they need today is carrying risk you’re getting no value for. Reviewing and trimming that access on a schedule is unglamorous, and it’s exactly the kind of boring work that closes the doors attackers actually use.
Assume they’ll be breached
The mature move isn’t trusting your vendors more. It’s designing for the day one of them fails — because at sixty vendors, over enough years, one of them will. Least privilege on their access, so a compromised vendor can’t reach the whole kingdom. Monitoring on what they can actually touch, so their bad day shows up on your radar instead of in a reporter’s inbox. A contract that forces them to tell you fast. And an honest internal answer to the question: if this specific vendor were fully compromised tonight, what could the attacker reach through them — and are we okay with that?
You’re not trying to guarantee your vendors are perfect. You can’t, and pretending you can is how these programs become theater. You’re making sure that their worst day doesn’t automatically become yours. That’s the whole discipline — not more trust, but less dependence on trust, backed by least privilege, real monitoring, and a contract with teeth.