Vendor Cybersecurity Policy

Purpose

This policy defines the minimum cybersecurity expectations for vendors, contractors, managed service providers, consultants, SaaS providers, hosting providers, and other third parties that access company systems, process company information, or support important business services.

The objective is to make sure outsourcing a service does not mean outsourcing accountability for cybersecurity risk.

Scope

This policy applies to third parties that:

  • Access company systems or networks
  • Process or store company data
  • Access customer or employee information
  • Manage company technology
  • Provide cloud, hosting, backup, or SaaS services
  • Provide remote technical support
  • Operate critical business services
  • Receive privileged or administrative access

Vendor Ownership

Each important vendor should have an internal company owner.

The owner is responsible for:

  • Understanding the service provided
  • Knowing what systems and data the vendor can access
  • Maintaining vendor contact information
  • Coordinating security reviews
  • Reviewing vendor access
  • Escalating vendor-related incidents
  • Supporting offboarding when the relationship ends

Vendor owner: ____________________

Risk-Based Review

Cybersecurity review should be proportionate to the vendor’s risk.

Higher-risk vendors include those that:

  • Store sensitive data
  • Have administrator access
  • Manage company systems
  • Provide backup or recovery services
  • Provide identity or email services
  • Process payments
  • Host critical applications
  • Have persistent remote access
  • Support critical operations

Low-risk suppliers with no system or data access may require much less review.

Minimum Security Expectations

Where appropriate to the service, vendors should:

  • Use supported systems
  • Apply security updates
  • Use appropriate endpoint protection
  • Require MFA
  • Protect privileged accounts
  • Restrict employee access
  • Protect company data
  • Use encryption where appropriate
  • Maintain backups where required
  • Maintain logging and monitoring
  • Have an incident response process
  • Manage subcontractor access

Remove access when no longer required.

Vendor Access

Vendor access should:

  • Have an internal owner
  • Use named accounts where practical
  • Use MFA
  • Be limited to required systems
  • Use least privilege
  • Be time-limited where practical
  • Be logged where appropriate
  • Be removed when no longer needed

Shared vendor administrator accounts should be avoided where practical

Data Protection

Before a vendor receives sensitive company information, the company should understand:

  • What data will be provided
  • Why the vendor requires it
  • Where it will be stored
  • Who can access it
  • Whether subcontractors will receive it
  • How it is protected
  • How long it is retained
  • How it can be returned or deleted

Sensitive information should not be provided simply because a vendor requests it.

Incident Notification

Important vendors should have a process for notifying the company of cybersecurity incidents that may affect:

  • Company data
  • Company accounts
  • Company systems
  • Critical service availability
  • Authentication credentials
  • Vendor integrations

The company should record the vendor’s security or emergency contact details.

Business Continuity and Recovery

For critical vendors, understand:

  • What happens if the vendor becomes unavailable.
  • Whether backups exist.
  • Expected recovery capability.
  • How the company can retrieve its information.
  • Whether an alternative provider or workaround exists.
  • How the vendor communicates outages.

Critical vendor dependencies should be reflected in recovery planning.

Subcontractors

Where significant, understand whether the vendor relies on subcontractors or sub-processors.

High-risk subcontractor arrangements should not create unknown access to sensitive company data or systems.

Contract Requirements

For important vendors, contracts should consider appropriate requirements for:

  • Confidentiality
  • Data protection
  • Security controls
  • Incident notification
  • Access control
  • Data return or deletion
  • Subcontractors
  • Business continuity
  • Audit or evidence rights where justified
  • Termination assistance

Vendor Review

Important vendors should be reviewed periodically and when:

  • The service changes significantly
  • The vendor receives additional access
  • Sensitive data use changes
  • A serious incident occurs
  • The contract renews
  • The company becomes more dependent on the vendor

Vendor Termination

When a vendor relationship ends:

  • Remove accounts
  • Remove remote access
  • Revoke tokens and integrations
  • Rotate shared credentials where necessary
  • Recover company devices
  • Transfer required information
  • Delete or return company data where appropriate
  • Update internal documentation

Practical Rule

Know which third parties can reach important systems or data, limit that access, and make sure somebody inside the company remains accountable for the relationship.