WATCH: Good Fences Make Good Neighbors: Managing Third Party Cybersecurity Risk
This guide is drawn from OrbitalFire’s Customer Learning Series webinar “Good Fences Make Good Neighbors: Managing Third Party Risk,” featuring OrbitalFire CEO Reg Harnish. Watch the Recording, or read the full guide below.
The most famous cyberattack on a major retailer didn’t start with the retailer. It started with their HVAC vendor — a small company that had network access to maintain heating and cooling systems and became the entry point for one of the largest retail data breaches ever recorded.
That was Target. But the same mechanic applies to businesses of any size.
When an attacker can’t get through your front door, they go around back. They look for a vendor, contractor, or software provider with access to your systems and go through them instead. Third-party risk isn’t a concept invented for Fortune 500 compliance departments. It’s the reason your security program needs to extend past your own walls.
Your Cybersecurity Program Is More Inherited Than You Think
Here’s a framing that clarifies a lot: a significant portion of your cybersecurity program is already inherited from your third parties.
When you work with Microsoft, Salesforce, your payroll processor, or your MSP, you’re inheriting their security controls as part of your environment. Their encryption practices, their access management, their incident response procedures — all of that becomes part of what you’re relying on to protect your data. If they do it well, that’s a strength. If they don’t, you’re exposed to risk you didn’t create and can’t directly control.
The flip side is just as important: risk is cascading in both directions. Your vendors and cloud providers are introducing risk into your environment. And your customers — the organizations downstream from you — are inheriting risk from you. If you experience a breach, your customers will be on the phone asking what happened to their data. Understanding that picture, not just the risk coming in but the risk going downstream, is what third-party risk management is actually about.
Five Categories Worth Paying Attention To
Not every vendor relationship carries the same weight. A useful way to think about this is to classify third parties based on what they can reach.
Regulated data. Vendors who handle data subject to HIPAA, CMMC, NYSDFS, or PCI DSS requirements carry some of your regulatory exposure with them. If they mishandle data that’s regulated, your organization faces the consequences.
Personally identifiable information. Payroll processors, HR systems, and benefits administrators hold employee data: Social Security numbers, banking information, compensation records. A breach at your payroll vendor affects real people directly.
Intellectual property. If you’re in manufacturing or professional services, your trade secrets and proprietary processes are often your most valuable assets. Subcontracting any work means another organization handling information that, if leaked, could cause lasting damage.
Elevated privilege. This is where your IT firm or MSP sits. In most cases, your managed service provider has what amounts to unfettered access — every computer, every network device, every piece of data in your digital environment. They can often make changes without your knowledge. That level of access puts MSPs in a category of their own, warranting more scrutiny than almost any other vendor relationship.
Reputational assets. Brand, relationships, business reputation — these matter less in the day-to-day vendor evaluation for most smaller businesses, but they’re worth a note if a partner is consumer-facing and could expose your name in a breach.
What to Actually Ask When You’re Evaluating a Vendor
Most smaller businesses will never conduct a full vendor security audit. There’s a practical middle ground.
SOC 2 certification. If a technology vendor or cloud provider can hand you a SOC 2 Type II report, that’s meaningful. It’s an independent audit confirming their security controls were actually operating over a period of time, not just documented on paper.
That said, be realistic about what a SOC 2 means in practice. A lot of the questionnaires that get sent between organizations are theater: procurement or legal is enforcing the process, and in many cases, neither side fully understands the questions or the answers. A vendor sending back a SOC 2 report satisfies the form requirement. Whether their actual security posture is strong is a separate question.
Cyber insurance. A vendor with cyber liability coverage has, at minimum, been through an underwriting process that required them to demonstrate basic controls. It’s not a guarantee, but it’s a signal worth asking about.
Patch cycle and access management. Unpatched systems are one of the most common entry points for attackers. A vendor who can’t describe how they keep their own systems current likely isn’t on top of it.
Data handling on exit. When the relationship ends, what happens to your data? This question is asked far less often than it should be. Get a written answer and a timeline before signing anything.
Contract Language That Does Real Work
The contract is where your expectations become enforceable. A few provisions that matter:
Material impact notification. You want your contract to require any third party to notify you if they experience something that materially affects your organization — data exposure, operational disruption, anything significant. The phrase “material impact” is the right framing; it’s broad enough to cover things you can’t anticipate.
The notification timeline is worth thinking through carefully. The shorter you set it, the more pressure you put on the vendor at exactly the moment when information is still incomplete and fast-moving. A 24-hour requirement sounds good on paper but often produces inaccurate early reports. Somewhere in the 24 to 72-hour range, once an incident has been formally declared, is a reasonable standard. Your cybersecurity advisor can help you work through what makes sense for your specific situation.
Right to audit. For high-risk vendors — especially your MSP — reserve the right to request security assessments. Most won’t push back on a reasonable ask.
Termination and data deletion. Require written confirmation that your data has been deleted when the relationship ends, with a specified timeline.
A Practical Alternative for Smaller Organizations: The Due Diligence Binder
Here’s something most smaller businesses don’t know: when a large customer sends you a 300-question security questionnaire, you may not need to answer it at all.
If you’ve built a documented cybersecurity program — a written information security policy, an incident response plan, a business continuity plan, PCI attestation or penetration testing results, and a statement that you’re working toward a recognized framework like NIST 800-171 or the HIPAA Security Rule — you can bundle those documents into a single package. Call it your due diligence binder.
When the questionnaire arrives, you send the binder instead. The cover statement says something like: we have adopted a recognized cybersecurity framework, we undergo annual risk assessments from independent experts, and here is our documentation. In many cases, that closes the inquiry entirely. The questionnaire gets checked off, the vendor relationship continues, and you’ve answered the spirit of the question without filling out a form that neither side fully understood anyway.
If that sounds like a reason to build the program, it is.
Third Party Risk Isn’t One and Done: It’s an Ongoing Responsibility
Third-party risk isn’t a one-time review. Vendors accumulate. Access drifts. Relationships end but credentials don’t always get cleaned up.
Once a year, pull your vendor inventory and review it: is each relationship still active, is the access level still appropriate, and has anything about the vendor changed that warrants a closer look? Give vendors exactly the access they need to do their job and no more — an IT vendor managing email doesn’t need access to financial systems. And when a relationship ends, revoke access the same day. This is where most organizations fall short: employees get deprovisioned (sometimes), but former vendors often don’t.
Ready to understand your real third-party exposure? Reach out to Chat
Frequently Asked Questions About Third-Party Risk Management
What is third-party cyber risk?
Third-party cyber risk is the security exposure your organization carries because of what your vendors, suppliers, contractors, and partners can access. When those organizations experience a security incident, the effects can extend directly into your environment. Managing it means understanding who has access, evaluating whether their security is adequate, and limiting what they can reach.
How do I know if a vendor is a security risk?
Start by asking questions they should be able to answer: Do you carry a SOC 2 report? Do you have cyber liability insurance? How do you handle data deletion when a contract ends? How frequently do you apply security updates? A vendor who can’t answer basic security questions — or who becomes defensive when asked — is worth scrutinizing more closely. Requesting their security documentation or insurance certificate is a reasonable ask for any vendor with significant access to your systems or data.
What should I include in a vendor security questionnaire?
For most smaller businesses, the essentials cover it: What data do you handle on our behalf, and where is it stored? Do you have a SOC 2 Type II report? What is your patch management cycle? Do you carry cyber liability insurance? How quickly will you notify us in the event of a breach affecting our organization? What is your process for data deletion when our contract ends? Higher-risk vendors — particularly your MSP — may warrant a more detailed assessment.
Is my IT provider a third-party risk?
Yes, and typically the highest-risk one. IT providers and MSPs often have persistent, administrator-level access to every system in your environment and can often make changes without your knowledge. An attacker who compromises an MSP can reach every client on their roster. Vet your IT provider at least as carefully as any other vendor, request their security certifications, and ask specifically how they protect privileged access.
Do I need to manage third-party risk if I’m a small business?
Third-party risk is present in any organization that relies on external vendors, which is virtually every business. The scope scales with the number and sensitivity of those relationships. The baseline — know who has access, ask basic security questions, limit access to what’s needed, revoke it when the relationship ends — is achievable at any size.
View the webinar on our YouTube Channel here.



