Two people reviewing a printed contract at an office table

ComplianceCybersecurity

Securing your supply chain: Practical cybersecurity steps for small businesses

Verizon’s 2026 Data Breach Investigations Report found that breaches involving a third party jumped 60% in a year and now make up nearly half of all breaches. That is the case for supply chain cybersecurity in one sentence. Your firewall can be current and your staff can all use MFA, and attackers still come in through your billing service, your payroll provider or the remote support tool a software vendor uses to reach your server.

You can’t control your vendors’ security. You can control which vendors you use, what they can reach and what you require of them, and none of it needs a procurement department.

48%

Share of breaches in Verizon’s 2026 Data Breach Investigations Report that involved a third party, up 60% from the year before

Supply chain cybersecurity: what an attack looks like in a real office

Your supply chain is every outside company whose product or service touches your data or systems. For a typical office that includes:

  • Cloud software such as Microsoft 365 and your practice management, accounting, CRM and payroll platforms.
  • Vendors with remote access, like line-of-business software support, your phone or copier provider, and your IT provider.
  • Service providers that receive your data, such as billing companies, bookkeepers, shredding services and marketing agencies.
  • Hardware and software you install, including updates and browser extensions.

In practice it often looks like nothing at all. A vendor’s support account signs in at an odd hour. A routine update arrives on schedule. A browser extension someone installed months ago starts doing something new, and we have seen bad extensions at client offices. Attackers like this route because one breached vendor can lead to many customers at once.

Warning signs worth a closer look

Verizon also found that only 23% of the third-party organizations it tracked fully fixed missing or poorly configured MFA on exposed cloud accounts. Assuming vendors have the basics covered is a gamble. These are the signs that deserve a question:

Two people reviewing a document at a table
  • A vendor that can’t say whether its own staff use MFA, how it encrypts your data, or how fast it would tell you about a breach.
  • A shared login that several vendor technicians use, or remote access that stays on all the time.
  • Third-party apps connected to Microsoft 365 that nobody remembers approving.
  • Vendor sign-ins from new locations or outside normal hours.
  • A vendor holding sensitive data with no security terms in its contract, or no contract at all.

How to stop it: third party risk management for a small office

List every vendor

Build a simple spreadsheet of every vendor, app and service that can reach your systems or sensitive data. For each, note what data they hold or can see, how they connect (cloud login, remote access tool, VPN, installed agent, email), who at your company owns the relationship, and the contract renewal date. Check card statements and Microsoft 365 app permissions, since most organizations find tools nobody remembers approving. Our guide to vendor management and IT procurement covers the buying side.

Sort them by risk

NIST’s Quick-Start Guide for Cybersecurity Supply Chain Risk Management recommends setting criteria for how critical each supplier is and sorting them into levels. Three tiers work for most small organizations. High-risk vendors hold or can reach sensitive data, have admin or remote access, or would stop your business if they went down. Medium-risk vendors have limited data or access, or an outage would hurt without stopping you. Low-risk vendors have no access to systems or sensitive data. Ask the high tier real questions, including whether they have an independent audit such as a SOC 2 report.

Put security in the contract

For higher-risk vendors, the contract should cover the safeguards they must keep (MFA, encryption, access controls), how quickly they must tell you about an incident affecting your data, limits on who can reach your data and whether they can use subcontractors, and what happens to your data when the contract ends.

For some organizations this is a legal requirement. HIPAA allows a covered entity to share PHI with a business associate only after getting written assurances, a business associate agreement, that the vendor will safeguard it (see our healthcare IT page). We hold ourselves to that standard, with signed BAAs from every vendor that can touch PHI. The FTC Safeguards Rule requires tax, accounting and other covered financial firms to select service providers that can maintain appropriate safeguards, require those safeguards by contract and periodically assess providers based on their risk (more on our accounting and financial firms page).

Give vendors the least access possible

  • Give each vendor its own named accounts, never a shared login, and require MFA.
  • Limit access to the specific systems they support, and separate those systems on the network where you can.
  • Turn remote access on when it is needed and off when the job is done.
  • Remove access promptly when a contract ends or a vendor’s employee leaves.
  • Review third-party apps connected to Microsoft 365 and remove the ones you no longer use.

Watch for trouble

Monitor sign-ins and remote sessions so unusual vendor activity stands out, and keep endpoint detection and response on your devices so malicious activity arriving through a trusted tool still gets caught. Every one of our clients has a 24/7 security operations center watching those alerts, and backups that are immutable, so a compromised vendor account can’t delete them.

What to do if a vendor tells you it was breached

  1. Find out what data, accounts and systems of yours were involved.
  2. Reset every credential connected to that vendor, including service accounts and API keys.
  3. Limit or cut off the vendor’s access until you know more.
  4. Check sign-in logs and devices for unusual activity tied to the vendor.
  5. Talk to counsel and your cyber insurer about whether you have notification duties.
  6. Update your vendor list and decide whether the relationship should continue.

Add vendor breaches to your incident response plan ahead of time: who calls the vendor, who decides whether to cut off access, and who handles notification. Our post on what cyber insurance covers is worth reading alongside it.

Most offices find their vendor list is longer than they expected, and the high-risk part of it is short. Book an intro call and we’ll help you build that list and decide what to ask the vendors at the top of it. It fits within our cybersecurity services and compliance support.

FAQ

Frequently asked questions

What is vendor risk management?

Vendor risk management is how you decide which outside companies can reach your data or systems, what you require of them and how you watch them. For a small office it means a list of every vendor, sorting them by risk, security terms in the contracts of high-risk vendors, least-privilege access and monitoring of vendor sign-ins. HIPAA and the FTC Safeguards Rule both require parts of it.

Why is vendor risk management important?

Verizon’s 2026 Data Breach Investigations Report found that breaches involving a third party rose 60% in a year, to 48% of all breaches. Attackers come in through a billing service, a payroll provider or a vendor’s remote support tool, because one breached vendor can lead to many customers. Your own firewall and MFA don’t close that route.

Sources: Verizon: 2026 Data Breach Investigations Report news release, May 2026; Verizon: 2026 DBIR Executive Summary; NIST SP 1305: CSF 2.0 Quick-Start Guide for Cybersecurity Supply Chain Risk Management; eCFR: 16 CFR 314.4, FTC Safeguards Rule elements; HHS: Business associates guidance.

Talk to an advisor

Questions about your own environment?

Our team can walk through how this applies to your organization, with honest recommendations and no pressure.