Third-party vendor risks
Vendors, suppliers, and service providers all extend your attack surface and your business-continuity risk.
Supply chain risks
Hardware manufacturers: routers and switches are assembled from many suppliers’ parts, so tampered components are a real threat. Trace origins with supply chain assessments and trusted foundry programs.
Secondary and aftermarket sources are cheap but risky: counterfeit or tampered gear may carry malware.
Software providers: check licensing, authenticity, known vulns, and malware. Open source lets you read the code; proprietary you scan. Service providers, MSPs, and SaaS: vet their cybersecurity, breach response, and track record.
A supply chain attack hits a weaker supplier to reach the real target. The CHIPS Act of 2022 funds US semiconductor manufacturing to cut foreign dependence. Defend with due diligence, monitoring and audits, industry info-sharing, and contractual security clauses.
Vendor assessment
Penetration testing of suppliers (simulated attacks on their systems), a right-to-audit clause (contractual permission to inspect their processes), internal audits (their self-assessment), independent assessments (a neutral third party), and supply chain analysis (the whole chain, not just the vendor).
Selection and monitoring
Selection is like hiring: due diligence on financial stability, history, testimonials, and culture fit, checking for conflicts of interest. Vendor questionnaires standardize comparison, and rules of engagement set communication and data-sharing boundaries.
Monitoring means performance reviews against agreed standards, plus two-way feedback loops.
Agreements to know cold
- SLA: the service standard the client can expect, with penalties.
- MOA: formal, spelling out responsibilities.
- MOU: looser, mutual intent without detail.
- MSA: general terms across many transactions.
- SOW: project specifics: deliverables, timelines, milestones.
- NDA: confidentiality of shared sensitive info.
- BPA / JV: partnership terms: profit sharing, IP ownership, exit.