You can do everything right internally and still be breached through someone else’s mistake. Your bookkeeper’s software, your web developer’s admin access, the platform holding your customer records, the managed service provider with remote access to every machine you own.
This is supplier risk, or third-party risk, and it is one of the least managed exposures in small and mid-sized business. Not because it is difficult, but because nobody owns it.
Start with the list, because there usually isn’t one
Before any assessment, frameworks, or questionnaires, do the unglamorous thing: write down every external party that has access to your systems or your data.
Include:
- Software platforms holding customer, staff or financial data
- Anyone with remote access to your machines or network
- Contractors and freelancers with logins
- Anyone with access to your website, domain or DNS
- Payroll, accounting and bookkeeping providers
- Former providers whose access was never revoked
That last category is where the surprises live. Access is granted at the start of a relationship and almost never removed at the end of one. We regularly find live accounts belonging to providers a business stopped working with years earlier.
Then ask what each one could actually do
Not every supplier deserves the same scrutiny. Sort them by what a compromise would mean for you.
A design agency with access to a marketing folder is a different risk from a provider with domain administrator rights. The question is not “do I trust them” but “if this supplier were breached tomorrow, what would the attacker have?”
Focus your effort on the small number with deep access or sensitive data. That is usually three to five relationships, not thirty.
The questions worth asking
For the suppliers that matter, you do not need a lengthy questionnaire. A short, direct conversation covers most of it:
- Do your staff use MFA on the systems that touch our data?
- Where is our data stored, and who else can access it?
- Have you had a security incident in the last two years, and what changed as a result?
- How would you notify us if our data were involved in a breach, and how quickly?
- When our relationship ends, what happens to our data and your access?
You are listening as much for the manner of the answer as the content. A supplier who answers clearly and without defensiveness has thought about it. A supplier who is evasive or dismissive has told you something useful.
The controls that do the heavy lifting
Give the least access that works. The default tends to be full administrator because it is easier and avoids callbacks. Scope it down.
Use named accounts, not shared ones. If a supplier logs in as admin, you cannot tell who did what, and you cannot revoke one person without disrupting everyone.
Diarise a review. Twice a year, go through the list and remove what is no longer needed. This single habit resolves most of the problem.
Have an offboarding step. When a supplier relationship ends, revoking access should be on the same checklist as the final invoice.
On the contract side
For meaningful relationships, it is reasonable to expect a few things in writing: a breach notification obligation with a defined timeframe, clarity on where data is held, and a commitment about data return or deletion at the end. This is increasingly standard and rarely contentious.
The honest summary
Supplier risk is not a technology problem, it is a housekeeping problem. Most of the value comes from knowing who has access, removing what is stale, and reducing what remains to the minimum that still lets people do their jobs. An afternoon of this beats a policy document nobody reads.
Want help building that access inventory and cutting it back safely? Get in touch and we will work through it with you.