Threatnexis

Every vendor connected to your systems is a door into your business you don’t fully control. 61% of 2024 supply-chain attacks originated one hop removed from the primary vendor — not the vendor itself, but something the vendor depended on. Most small and mid-sized businesses have never inventoried which vendors can touch sensitive data, let alone reviewed how well those vendors protect it.

Vendor security scorecard cheat sheet covering vendor risk tiers, sample VSAQ, and scoring rubric
Our vendor security scorecard framework — download the full free edition below.

When a Vendor Becomes the Breach

A 40-person accounting firm outsourced its client document portal to a third-party SaaS vendor. The vendor left a known vulnerability unpatched for 97 days. Attackers used it to access tax records for over 1,200 clients. The firm had never reviewed the vendor’s security practices, and its contract had no breach-notification requirement — it learned about the incident from a client, not the vendor. Notification costs, legal fees, and lost clients topped $310,000.

Not All Vendors Deserve the Same Scrutiny

Reviewing every vendor with the same depth wastes time on low-risk relationships and starves the ones that actually matter. Tier vendors first, based on what they touch:

What to Ask Every Tier 1 and Tier 2 Vendor

A Vendor Security Assessment Questionnaire (VSAQ) belongs in every new contract and every annual review. At minimum, ask about:

Score every response on a consistent 0–100 scale so results are comparable period over period — a vendor whose score drops for two consecutive reviews should be escalated regardless of its absolute score.


Get the Free Vendor Security Scorecard

Download the free edition: the 4-tier risk framework, a sample Vendor Security Questionnaire, and the 0–100 scoring rubric — everything you need to start tiering and reviewing your vendor list today.

Managing a Large Vendor List?

The full Premium Toolkit adds the complete 34-question VSAQ across all six sections, a fourth-party risk register for subprocessor exposure, a security contract clause library, onboarding/offboarding checklists, and a vendor score trend dashboard. See how we help small businesses manage vendor risk end-to-end.

Leave a Reply

Your email address will not be published. Required fields are marked *

Book a Session