Skip to main content
third party risk management

1. We only use well-known software vendors, does it still apply to us?

Yes because large, well-known vendors have been the source of some of the most damaging supply chain breaches; size and reputation don’t eliminate the risk, they just change the impact scale.

2. How do we know if a vendor's SOC 2 report actually covers what matters to us?

Review the scope section of the report, it defines what systems and services are covered; if your specific use case isn’t in scope, the report doesn’t validate the controls that protect your data.

3. Should we stop using a vendor immediately after they report a breach?

Not necessarily, the right step is to immediately understand the scope, revoke access provisionally, and make a restoration decision based on what data was involved and what the vendor does to remediate.

4. How many vendors should we classify as Tier 1 high-risk?

There’s no universal number, but Tier 1 should include any vendor with access to sensitive customer data, financial systems, or your network infrastructure, for most businesses, that’s typically five to fifteen vendors.

5. Do cyber insurance policies cover losses from a vendor breach?

Many do, but coverage depends on policy language and whether you can demonstrate that reasonable vendor due diligence was in place, which is another reason to document your vendor risk management program.

Rhonda Watson

Rhonda Watson is Executive Assistant and Office Manager at BNMC, bringing over 20 years of experience supporting executives in fast-paced environments. Known for her strong interpersonal skills, sharp organizational instincts, and ability to juggle competing priorities with ease, she serves as a trusted partner to both leadership and staff, keeping operations running smoothly behind the scenes.