Vendor security guide
A practical cyber supply-chain risk assessment
A small business supply-chain assessment starts with a complete vendor inventory and criticality rating. For each supplier, document data, access, integrations, operational dependency, hosting location, subcontractors, authentication, encryption, incident notification, backup, recovery, portability, deletion, assurance evidence, and an accountable business owner.
Know every connected supplier
Review high-impact vendors more deeply
Turn expectations into enforceable terms
Build the vendor inventory
Include cloud platforms, managed services, website and e-commerce providers, accountants, payroll, payment services, marketing tools, mobile apps, open-source components, contractors, and any supplier with system or data access.
Record owner, service, data, authentication, integration, privilege, location, dependency, renewal, and exit method.
Tier the risk
Rate operational criticality, data sensitivity, privilege, connectivity, concentration, substitutability, and recovery time. A vendor that can administer every endpoint needs deeper review than a low-impact communications tool.
Apply more evidence and shorter review cycles to high-impact suppliers instead of sending the same questionnaire to everyone.
Turn findings into action
Resolve missing MFA, excessive access, unclear incident notification, weak deletion, unsupported technology, single-person dependencies, absent backups, untested recovery, and poor portability.
Track each decision, exception, compensating control, owner, due date, and next review. Risk acceptance should be explicit, not accidental.
Primary sources
This page separates sourced facts from North Star's operational guidance. Check the current source before relying on a changing price, rule, list, or technical standard.
Questions businesses ask
Which vendors belong in the inventory?
Include any supplier, contractor, platform, app, component, or service that accesses data, systems, identities, facilities, or a critical business process.
Should every vendor complete the same questionnaire?
No. Use criticality and access to determine the depth of review and evidence required.
How often should vendors be reassessed?
Set a risk-based schedule and reassess after material changes, incidents, acquisitions, service changes, or new access.
Turn the research into an operating plan
North Star can help assess the environment, define scope, document ownership, implement controls, and verify the result.
Plan a security assessment