Vendor Risk Management: How to Assess Third-Party Security Risks Before They Impact Your Business
Eli Carpenter
VanderNet Security Engineer
Key Takeaways
- 1.Vendor security assessments should be tailored to the risk level of each vendor
- 2.AI vendors require specialized security questionnaires beyond standard questions
- 3.Supply chain attacks have increased by more than 400% in recent years

Nearly every modern business relies on software, cloud applications, and third-party vendors to keep operations running efficiently. But this raises several important questions: Do you know what data these tools and vendors have access to? How secure are your cloud applications and software? Do you know what security practices your vendors are following? What do these vendors do with your data? These types of questions often go unanswered for most small and medium sized businesses, and even for some larger businesses. All of these questions and many more should be part of your vendor risk management process.
Vendor risk management is the process of identifying, assessing, and monitoring the cybersecurity, compliance, operational, and data privacy risks associated with third-party vendors that supply software, cloud applications, or services to your business. The process involves evaluating the vendor through a vendor security assessment, and a security questionnaire.
When evaluating a new software, tool, or vendor, the number one question is usually price, followed by does the product or service solve a problem or fill a need in your business. While of course these are both very important questions and are necessary to ask, it is just as important to know what security your vendors have in place and what they do with your data. Even if a software tool perfectly fits a need and doesn't cost very much, if they don't have proper security in place or are selling your data, then it probably isn't worth doing business with them.
Vendor Security Assessment: What should be required?
The first step towards proper vendor risk management is having a defined vendor security assessment. Ask them questions! Find out what they are actually doing when it comes to security and have a list of requirements and nice to haves. However, it is important to note that the requirements for each vendor can vary depending on what the vendor is doing for you.
Low Risk Vendors: (Vendors that don't handle any of your data)
- Multi-Factor Authentication (MFA) should be mandatory
- Having an Incident Response Plan
- Do your own research, check online reviews of the vendor.
**Pro tip, ask AI! LLMs like ChatGPT, Grok, and Gemini can do a great job of evaluating a potential vendor for security. Just don't solely rely on these tools.
Moderate Risk Vendors: (Vendors that handle PII, customer data, and your business' data)
- SOC 2 Certification should be mandatory
- SOC 2 Type II is even better
- ISO 27001 Certification also goes a long way in verifying security
- Data Encryption in transit and at rest
High Risk Vendors: (Vendors that handle very sensitive information such as financial or health related data)
- Independent third-party penetration tests
- PCI DSS certification for any vendor handling transactions
- HIPAA compliance for any vendor that handles health related data
Now, these requirements are not catch-all requirements. While they are very important, it is just as important for you as the business leader to determine what is best for your business. There are a plethora of questions that should be included in a solid security questionnaire for vendor risk management. But the actual questions that are asked and what answers are acceptable can heavily depend on what your business does and the type of data you handle. Here's a quick rundown of some of the more important questions.
Security Questionnaire: What should I ask?
- What is your data retention policy?
- Do you sell or distribute data to other companies?
- What is your data segmentation policy?
- What level of data encryption do you use?
- Do you have cybersecurity insurance in place?
- Are any security audit or penetration test reports available for review by clients?
- Have you experienced any data breaches or security incidents in the last 24 months?
AI tools are becoming increasingly more common and should require their own specific questions to ask on-top of the standard questions due to the complexity and security risks that can come with AI usage.
AI Vendor Security Questionnaire
- What AI model do you use?
- Do you use our data for AI model training?
- If so, can this AI model training be disabled?
- Do you provide data to third-party AI providers?
- How long is AI interaction data retained?
- Are AI generated outputs isolated from other customers?
- What safeguards are in place to prevent data leakage between customers?
Why does it matter to me?
Cybercriminals have been increasingly targeting software, cloud application, and service providers as an easy way to attack multiple companies at once. These incidents, commonly referred to as supply chain attacks have increased by more than 400% in recent years. Nearly 45% of companies globally have been impacted each year by this type of attack. (Kaspersky IT Security Research)
It sounds like a lot, doesn't it? At the end of the day, you are ultimately responsible for your data, along with your customer's data that they have entrusted to you. The last thing you want to have happen is to be the reason that your data, or your customer's data was stolen or sold. Many business owners don't have the time, expertise, or resources to perform comprehensive vendor risk assessments. This is where VanderNet comes in. We not only protect your data with enterprise security tools, but we will also handle the entire vendor risk management process. VanderNet helps organizations identify third-party risks, evaluate vendor security controls, review compliance certifications, and build effective vendor risk management programs. Whether you're evaluating a new software platform, reviewing an existing vendor, or implementing a formal vendor screening process, our team can help ensure your vendors meet the security standards your business requires. You can rest easy knowing that we will make sure your vendors are keeping your data safe. Because proper vendor risk management can ultimately make or break your business.
Even if a software tool perfectly fits a need and doesn't cost very much, if they don't have proper security in place or are selling your data, then it probably isn't worth doing business with them.
Want a personalized risk assessment?
Get a clearer view of where your IT, security, and support strategy stand today.
Eli Carpenter
VanderNet Security Engineer
Eli Carpenter is a security engineer specializing in vendor risk management, third-party assessments, and helping organizations build robust vendor security programs.


