Every payroll platform, scheduling app, and file-sharing tool a business signs up for becomes a small extension of its network. Most companies can name their firewall and antivirus provider without hesitation, but few could list every outside vendor with access to their data. Third-party vendor risk usually starts there, and it’s worth understanding before a compromised tool forces the issue.
Why third-party vendor risk is bigger than most businesses realize
Third-party vendor risk made headlines this year when a compromised third-party file-sharing tool used by the Los Angeles City Attorney’s Office exposed 7.7 terabytes of Los Angeles Police Department data, a story we covered in detail in our earlier piece on the LA City Attorney breach. The lesson reaches well beyond city government. Verizon’s DBIR shows third-party involvement in breaches climbing from 15% to 30% in the 2025 report and to 48% in the 2026 edition. That figure spans businesses of every size, including plenty without a dedicated security team watching for this kind of exposure.
Most of that increase traces back to ordinary vendor relationships, things like an invoicing platform or a scheduling app. Each one holds a copy of business data or a line into a company’s systems, and its security depends entirely on the vendor’s own practices. For California businesses handling customer or employee records, that carries legal weight as well as reputational risk.
The vendor risk blind spot most businesses don’t check
Most small and midsize businesses don’t keep a written list of every vendor and software tool with access to their data. Contracts get signed for convenience, a free trial turns into a permanent fixture, and no one revisits the arrangement once it’s working. The National Institute of Standards and Technology addresses this directly in its cybersecurity supply chain risk guidance, which calls on organizations to identify, assess, and monitor risk across every vendor relationship. That includes the vendors that don’t feel obviously sensitive. That guidance was written with large federal systems in mind. The underlying habit still scales down easily, coming down to knowing what you have and treating every vendor relationship as a security relationship.
In practice, that blind spot usually includes file-sharing tools, scheduling platforms, payroll providers, and SaaS accounts an employee signed up for without asking IT first. A scheduling app might only need a name and an email address to work, while a file-sharing account could hold years of client contracts. Both carry the same exposure whether they feel that way or not.
What a real vendor risk assessment looks like
A vendor risk assessment doesn’t need to be complicated to be useful. It starts with a short set of questions for every vendor with access to business data. Ask how the data is stored, whether multifactor authentication is supported, who at the vendor owns security, and how quickly they’d notify the business if something went wrong.
California law already expects this level of diligence. Under Civil Code Section 1798.81.5, a business that shares a California resident’s personal information with an outside vendor by contract must require that vendor to maintain reasonable security procedures of its own. A vendor risk assessment lines up closely with what state law already assumes a business is doing.
For most businesses, the assessment can start small. Start by reviewing existing contracts for security language and asking new vendors direct questions before signing, then revisit vendors already in place on a set schedule instead of leaving them unchecked indefinitely.
How managed cyber security in Bakersfield and Visalia closes the gap
Grapevine MSP builds its cyber security services around this exact problem for San Joaquin Valley businesses, reviewing where data lives outside a company’s own systems as well as inside them. That includes IT support that watches for unusual activity around the clock, so a compromised vendor tool gets caught early.
It also extends to the cloud tools a business already depends on daily. As a Tier 1 Cloud Solutions Provider, Grapevine MSP’s cloud services team manages Microsoft 365 permissions and access directly. Default settings are often where vendor-related risk quietly builds up, and this kind of hands-on management covers the accounts and software most businesses never get around to checking on their own.
A vendor risk checklist to start with
A few steps can meaningfully reduce third-party vendor risk without a full technology overhaul.
- List every vendor and tool that can access business data, including ones that feel low risk, like scheduling or file-sharing platforms.
- Ask new vendors directly how they store data and how quickly they’d notify the business of an incident.
- Check existing contracts for security language requiring vendors to maintain reasonable procedures, beyond a basic data use clause.
- Turn on multifactor authentication everywhere it’s offered, on third-party tools as well as core systems.
- Revisit vendor access on a schedule, and remove accounts and permissions no one is using anymore.
This comes down to knowing which vendors exist and whether their security holds up to the standard a business expects of its own systems. A discovery call with Grapevine MSP is a practical way to map those blind spots and decide what to tighten up first.
FAQs
Do I need a written vendor risk policy if I’m a small business?
It helps, even in a simple form. A running list of vendors and a few standard questions for new ones covers most of the risk without added paperwork or a dedicated compliance role.
Am I responsible if a vendor I use gets breached?
Under California law, sharing personal information with a vendor by contract requires that vendor to maintain reasonable security procedures, and the business stays accountable for choosing and managing that vendor relationship in the first place.

