
Your Vendor's Breach Is Your Breach
Nearly half of confirmed breaches now involve a company other than the one that has to make the phone call.
Executive Summary
- Attackers rarely need your front door. They come through the bookkeeper, the payroll platform, the scheduling app, or the IT provider that already holds a key to your systems.
- The 2026 Verizon Data Breach Investigations Report found a third party involved in 48 percent of the more than 22,000 confirmed breaches it examined, up from 30 percent the year before.
- Being small is no protection. You were not chosen, your vendor was, and the fix is not technical. It is a short list of questions asked before you sign.
You Bought Software. You Inherited Their Security.
Count the outside companies that can reach into your business right now. Payroll holds every employee's Social Security number. The bookkeeper signs into your bank portal. Your IT provider can open any machine you own, at any hour, without asking first. None of those were security decisions. They were business decisions, and each one quietly extended your risk into a company whose security you have never laid eyes on.
Attackers do this arithmetic better than most owners. Breaking into one accounting platform is a single job that pays out across hundreds of that platform's Clients. Breaking into those hundreds one at a time is hundreds of jobs. The math has never favored the defender, which is why the third-party share of breaches keeps climbing.
That is where the small-business defense collapses. “We are too small to be a target” is frequently true and completely beside the point. Nobody picked you. Somebody picked your vendor, and your records happened to sit in the same database as everyone else's. You did not fail a security test. You were never handed one.
Five Questions, Asked Before You Sign
You do not need a vendor risk program. You need to stop signing blind. Before the next renewal, and before the next new tool, ask:
- What of ours do you hold, and where does it live? Data you did not know they had is data you cannot protect.
- Who on your side can see it? “Any of our support staff” is a very different answer than “two named administrators.”
- How quickly do you tell us when something goes wrong? Get a number of days, in the contract. Six weeks of silence is a real outcome, and cheaper to negotiate away now than to discover later.
- Do you require multi-factor authentication on your own systems? A vendor who cannot answer this has answered it.
- Who audits you, and may we see the summary? An audit report is not proof of safety, but a vendor nobody has ever examined is a different animal.
Then handle what sits entirely inside your control. Shut off access nobody uses: the agency you stopped working with, the abandoned pilot tool, the departed employee whose login still works on the vendor's side.
The Takeaway
You cannot audit your suppliers the way a bank does, and nobody expects you to. You can know which outside companies hold your data, ask five plain questions, and put notification timing in writing. That is an afternoon of work. It is also the difference between hearing about a breach from your vendor and hearing about it from your Clients.
How Simulint Helps with Third Party Risk Management
Most small companies have nobody whose actual job is to ask these questions. Our third party risk management program does the asking: we build the list of who holds your data, assess each vendor against a real control set, and hand back a ranked view of which relationships to fix first. Learn more at https://simulint.com/.
