Vendor security guide

A practical cyber supply-chain risk assessment

A small business supply-chain assessment starts with a complete vendor inventory and criticality rating. For each supplier, document data, access, integrations, operational dependency, hosting location, subcontractors, authentication, encryption, incident notification, backup, recovery, portability, deletion, assurance evidence, and an accountable business owner.

Inventory

Know every connected supplier

Criticality

Review high-impact vendors more deeply

Contract

Turn expectations into enforceable terms

Build the vendor inventory

Include cloud platforms, managed services, website and e-commerce providers, accountants, payroll, payment services, marketing tools, mobile apps, open-source components, contractors, and any supplier with system or data access.

Record owner, service, data, authentication, integration, privilege, location, dependency, renewal, and exit method.

Tier the risk

Rate operational criticality, data sensitivity, privilege, connectivity, concentration, substitutability, and recovery time. A vendor that can administer every endpoint needs deeper review than a low-impact communications tool.

Apply more evidence and shorter review cycles to high-impact suppliers instead of sending the same questionnaire to everyone.

Turn findings into action

Resolve missing MFA, excessive access, unclear incident notification, weak deletion, unsupported technology, single-person dependencies, absent backups, untested recovery, and poor portability.

Track each decision, exception, compensating control, owner, due date, and next review. Risk acceptance should be explicit, not accidental.

Primary sources

This page separates sourced facts from North Star's operational guidance. Check the current source before relying on a changing price, rule, list, or technical standard.

Questions businesses ask

Which vendors belong in the inventory?

Include any supplier, contractor, platform, app, component, or service that accesses data, systems, identities, facilities, or a critical business process.

Should every vendor complete the same questionnaire?

No. Use criticality and access to determine the depth of review and evidence required.

How often should vendors be reassessed?

Set a risk-based schedule and reassess after material changes, incidents, acquisitions, service changes, or new access.

Turn the research into an operating plan

North Star can help assess the environment, define scope, document ownership, implement controls, and verify the result.

Plan a security assessment