Your security is only as strong as the vendors you've handed the keys to. The breach that hurts you most may not be yours at all — it may be a supplier's, with your data inside it.
You've outsourced the work, not the responsibility
Every SaaS tool, contractor, and integration is a door into your business that someone else maintains. When they're careless, you inherit the consequence — and your clients won't distinguish between your breach and your vendor's. The responsibility doesn't transfer along with the data.
For any vendor holding meaningful data, know:
- What exactly they hold — and whether they should still hold all of it.
- How they'd notify you of a breach, and how fast.
- Who, on their side and yours, can access it — and whether access ends when people leave.
- What happens to your data when the contract does.
You can outsource the work and the infrastructure. You cannot outsource the accountability for what happens to your clients' data.
You don't need to audit every vendor to the same depth — concentrate on the few that hold the most sensitive data. For those, a short, direct set of questions, asked before you sign and revisited yearly, is worth more than any certificate on a website.