Vendor and Supply Chain Risk: Your Security Is Only as Good as Theirs

You can harden every laptop you own, train every employee, and still get breached — because the attacker never went after you directly. They went after your bookkeeper, your practice management software vendor, your marketing agency, or the IT provider with remote access to your servers. Then they used a connection you set up on purpose, with credentials that were supposed to be there.

This pattern has grown steadily, and small businesses feel it disproportionately. You are connected to more third parties than ever — payroll, accounting, CRM, scheduling, backup, remote support — and each connection is a door with someone else's lock on it.

Start with an inventory: who has access to what

Most businesses cannot answer this question, which is the real problem. Before you can manage vendor risk you need a list. Keep it simple — a spreadsheet is fine — and for each vendor record:

  • What systems or data they can reach, and how (a login, a remote access tool, an API key, a connected app).
  • Whether that access is standing or granted per request.
  • Who at your company owns the relationship.
  • Whether their access is covered by MFA and monitored.

Build the list from what exists, not from what you remember. Check your Microsoft 365 or Google Workspace admin console for connected third-party apps, your line-of-business systems for external users, and your remote access tools for accounts that are not yours. What turns up is usually surprising.

Least privilege and MFA for every vendor account

Vendor accounts tend to get more permission than they need, because broad access is easier to set up and nobody wants a support call blocked by a permissions error. That convenience is exactly what an attacker inherits.

  • Give each vendor its own named account. Never a shared login, and never one used by multiple people at the vendor.
  • Require MFA on every vendor account, without exception. If a vendor cannot support it, that is a finding worth escalating.
  • Scope the permissions to the job. A billing vendor rarely needs domain admin. An agency almost never needs access to your file server.
  • Prefer just-in-time access. Enable remote access when it is needed and turn it off when the work is done.
  • Log and alert on vendor logins, especially outside normal hours or from unexpected locations.

Remove dormant integrations

Every business has them: the app someone connected during a trial three years ago, the former agency's admin account, the API key for a tool nobody uses. These integrations keep their permissions indefinitely and nobody watches them, which makes them ideal for an attacker. Review connected apps and external accounts at least twice a year and revoke anything without a current owner and a current reason.

Ask vendors better questions

You do not need an enterprise risk program to ask a few pointed questions before you hand over access. Reasonable vendors answer them without friction, and the reluctant ones tell you something too:

  • Do you hold a SOC 2 Type II report or equivalent independent audit, and can we see it under NDA?
  • Is MFA required for your own staff, including the ones who support our account?
  • How quickly will you notify us of a security incident affecting our data, and by what method?
  • Where is our data stored, who else can access it, and what happens to it when we leave?
  • Do you use subcontractors or offshore support that can reach our systems?

Weigh the answers against how much access the vendor has. A tool holding client records deserves scrutiny; a contractor with no system access does not.

Put it in the contract

Verbal assurances are not much help after an incident. When you sign or renew, look for breach notification with a defined timeframe, a requirement to maintain reasonable security controls, clear data ownership and deletion at termination, and confirmation that the vendor carries cyber liability coverage. For vendors with deep access, have your attorney review it.

Watch software updates too

Supply chain risk includes the software itself. Attackers have compromised legitimate update channels and management tools to reach every downstream customer at once. You cannot audit a vendor's build pipeline, but you can limit the blast radius: segment the network, keep immutable backups, and run detection that flags trusted software behaving strangely.

Equal Tech Solutions helps businesses map vendor access, tighten permissions, and ask the right questions before granting a connection — including the questions you should be asking us.

If you are not sure which third parties can reach your systems right now, that is the place to start. Equal Tech Solutions serves Chattanooga, Cleveland, and the Southeast US. Contact Equal Tech Solutions for a vendor access review.