1 min read
Before You Hire a Cybersecurity Vendor: 7 Questions That Reveal the Truth
Choosing a cybersecurity vendor isn't like hiring a plumber. The wrong choice doesn't just cost you time and money — it can leave your business...
5 min read
Totalcare IT
:
Updated on July 6, 2026
When the U.S. government launched Operation Warp Speed — the effort to develop and distribute COVID-19 vaccines at unprecedented speed — cybersecurity wasn't the headline story. But behind the scenes, CISA assembled a task force specifically to protect the supply chain from attack.
CISA is the United States’ Cybersecurity and Infrastructure Security Agency. A task force was created within CISA during Operation Warp Speed to oversee the security of the vaccine development process. On that task force was Josh Corman, who is a senior advisor at CISA as well as the founder of IAmTheCavalry.org, a grassroots organization focused on the intersection of digital security, public safety, and human life. Corman understands the gravity of supply chain resilience, and that it cannot be accomplished without communication between all stakeholders.
As part of that communication, one of the first things you do when you take over a cybersecurity project is a detailed asset and vendor inventory. In the case of Operation Warp Speed, there were many vendors to catalog. And each vendor posed a potential security threat to the operation if they were somehow compromised.
A Verge article explains, “What worried Corman weren’t places like Pfizer and Moderna. Those big, name brand companies all employ in-house cybersecurity experts. He was worried about companies like the one making an mRNA ingredient: small, anonymous groups that made bits and pieces pivotal for vaccines, but that might not have ever thought they’d need to protect against a hacking campaign.”
Most often, these smaller companies are within the supply chain of the bigger companies and can be easily overlooked when conducting a vendor inventory.
“‘I asked, what are those smaller, less obvious players that, if they’re disrupted, means there’s no vaccine? And no one had an answer,’ Corman says."
So Corman started a thorough inventory. “The list was dynamic — at the start of the process, it focused on groups involved in vaccine research and development. Then it shifted to companies working with the manufacturing and distribution of the shots. Overall, the group identified hundreds of companies involved in the process that could have been risks.”
Wow. What a great example of how an incomplete vendor inventory could have severely impacted the mission of Operation Warp Speed. One overlooked vendor with poor security could have shut down the operation completely if they were victim to a cyber attack.
Vendor inventories are a critical action every Idaho business should be completing and updating regularly with their IT team. Why spend the time and money to secure your environment if you are using a vendor that is below the cybersecurity poverty line? It doesn’t make sense.
Know your vendors’ security posture and what they are doing to protect YOU in their practices. This is something you have the right to know and should know – especially if you want to be approved for cyber insurance.
Think through who currently has access to your environment: your software providers, cloud platforms, payroll processor, accounting system, IT support, remote monitoring tools, EHR or ERP vendor, email security provider, and any SaaS tools your team uses. Each one is a potential entry point.
Attackers figured this out years ago. Rather than hitting a well-defended target directly, they go after a vendor with access to that target. The 2013 Target breach came through an HVAC contractor. The 2020 SolarWinds attack hit thousands of organizations through a compromised software update. The pattern repeats because it works.
This is why CIS Control 15 — Service Provider Management — is a formal security standard, not just a best practice. For businesses pursuing CMMC, cyber insurance, or SOC 2, your ability to demonstrate vendor oversight isn't optional. It's audited.
You can't manage risk you haven't catalogued. The first step is knowing who your vendors are, what they have access to, and what the impact would be if they were compromised.
For most businesses in the 25–150 employee range, this list is longer than people expect. Software subscriptions accumulate. Integrations get set up and forgotten. Someone added a third-party tool two years ago and no one documented it.
Your inventory should capture at minimum: the vendor name, what they access (data, systems, or both), what data types they touch, and who internally owns that relationship.
Once you have the list, categorize by impact:
Your coffee vendor and your cloud hosting provider should not receive the same level of security scrutiny. Focus where the blast radius is largest.
For high-risk vendors, you need to understand their security posture before you're relying on them — not after an incident.
The questions that matter most:
For healthcare vendors, you'll also need a signed Business Associate Agreement before they can legally access protected health information. For defense contractors or businesses pursuing CMMC, your vendor's security posture directly impacts your compliance standing — their gaps can become your finding.
You shouldn't have to build a full security questionnaire from scratch. CIS has published templates, and your IT partner should be able to help you run these assessments.
Certifications like SOC 2, ISO 27001, and HIPAA attestation aren't guarantees of security. They're evidence that a vendor has built and tested security controls, had an independent auditor verify them, and cares enough to maintain them.
Think of them as references, not guarantees. A vendor with a current SOC 2 Type II report has gone through a meaningful process. A vendor that can't tell you what framework they're certified against is a different conversation.
Cyber insurance is worth asking about too. A vendor that carries adequate coverage has cleared at least a minimum bar with their insurer — which increasingly requires documented security controls to obtain.
This is where most businesses fall short. They complete a vendor assessment during onboarding and never look at it again.
Vendor risk changes. A company that was well-managed two years ago may have grown fast, cut security staff, or been acquired. A tool you set up in 2022 may have changed ownership entirely. Software products reach end-of-life. Compliance certifications expire.
Annual reviews for high-risk vendors is a reasonable baseline. If a vendor has a public security incident — even if your data wasn't involved — that's a trigger to revisit the assessment.
The goal isn't to make your vendors jump through endless hoops. It's to make sure the organizations you depend on are taking the same care with your data that you'd take yourself.
For manufacturers and engineering firms in the Treasure Valley and East Idaho, vendor risk has an additional layer: your operational technology vendors. The companies providing your SCADA systems, industrial control software, or equipment firmware updates may have remote access to your production environment — and that access often gets set up without the same scrutiny applied to business systems.
If a vendor has remote access to your shop floor or production line, that access deserves the same review process as any other high-risk vendor. Know who has it, why they have it, and how it gets turned off when the engagement ends.
If you don't have a vendor inventory today, start by listing every tool and service your business uses and identifying which ones touch sensitive data or connect to your systems. That list alone will surface things that need attention.
From there, a structured vendor risk review — tied to your next renewal cycle or annual technology review — is a practical way to work through the list without it becoming an all-consuming project.
At TotalCare IT, vendor risk management is part of how we approach security assessments for businesses in Boise, Idaho Falls, and the surrounding region. If you're not sure where your vendor exposure stands, that's a good starting point for a conversation. Talk to us here.
1 min read
Choosing a cybersecurity vendor isn't like hiring a plumber. The wrong choice doesn't just cost you time and money — it can leave your business...
1 min read
When most people think about cybersecurity threats, they imagine hackers sitting behind screens in far-away places. While those threats are real,...
1 min read
A Construction Company’s Guide to New Software (Without Opening the Digital Floodgates) Construction companies love tools.