4 min read

The Riskiest Vendor in Your Supply Chain Is Probably the One Nobody's Watching

The Riskiest Vendor in Your Supply Chain Is Probably the One Nobody's Watching

Quick thought experiment: pull up your organization's vendor list and sort it by contract value. Now ask — is that also your risk list?

For most procurement teams, the honest answer is no. And that gap is exactly how some of the most damaging breaches in recent memory got started — not through the flashy, expensive vendor everyone scrutinizes, but through the small, cheap, forgettable one nobody thought to ask hard questions.

The HVAC Company That Took Down Target

In 2013, attackers walked into Target's corporate network using credentials stolen from a heating and air conditioning subcontractor. Not a software vendor. Not a payment processor. An HVAC company, hired for routine billing and system monitoring.

That access chain eventually reached Target's point-of-sale systems, and tens of millions of customers' payment card details were stolen.

Here's the part that should make every procurement professional pause: that HVAC contract almost certainly looked low-risk on paper. Low spend, no obvious data access, nothing that would trigger a rigorous security review under a typical spend-based vendor tiering model. Which is exactly the point — the vendor wasn't dangerous because of what it did. It was dangerous because of the network access nobody thought to restrict.

Contract Value Is the Wrong Ruler

This is the core mismatch in a lot of procurement risk models: they're built to manage financial exposure, not cybersecurity exposure, and the two don't move together.

A $15,000-a-year vendor with persistent remote access to your network can be a bigger security liability than a $2 million vendor that never touches your systems at all. If your due diligence effort scales with contract size, you're pointing your scrutiny at exactly the wrong place half the time.

A better lens tiers vendors by:

  • What data or systems can they actually reach
  • How deeply their software or access is embedded in your environment
  • Whether their own subcontractors and dependencies are visible to you at all

That last one matters more than most procurement processes account for.

The Vendor Behind Your Vendor Behind Your Vendor

In 2020, attackers didn't breach SolarWinds' customers directly. They compromised SolarWinds' own software build process and slipped malicious code into a routine, digitally-signed update of its Orion platform. Thousands of organizations — including multiple U.S. federal agencies — installed that update as part of normal patching, and unknowingly opened a door.

Every one of those organizations had, at some point, gone through a procurement process to select SolarWinds. Most probably considered it low-risk — an established, long-standing vendor, not exactly an unknown startup. That's what makes this case worth sitting with: reasonably thorough vendor vetting didn't catch it, because the compromise happened upstream, at the build stage, somewhere procurement due diligence rarely reaches.

Then in 2021, it happened again — one layer further removed. Attackers exploited a vulnerability in Kaseya's remote-management software, used by managed service providers (MSPs) to administer their clients' systems. Because MSPs typically have broad administrative access to their customers' networks, the compromise cascaded from Kaseya, to the MSPs, to potentially thousands of downstream small and mid-sized businesses — most of whom had never even heard of Kaseya and had no direct contract with it.

If your organization uses an MSP, ask yourself right now: do you know what tools that MSP uses internally to access yourenvironment? Most procurement teams don't. That's the blind spot.

What Actually Helps

None of this means procurement teams need to become cybersecurity experts. It means a few specific habits close most of the gap:

Tier by access, not spend. A vendor with deep network access deserves scrutiny regardless of contract size.

Ask about the vendor's own vendors. "Do you maintain a software bill of materials, and will you share it?" is a fair, increasingly standard question — and a vendor who can't answer it is telling you something.

Put teeth in the contract, not just the questionnaire. A right-to-audit clause with no realistic mechanism to use it isn't much better than nothing. Same goes for a breach notification clause that says "promptly" instead of naming an actual timeframe like 72 hours.

Don't stop at signature. A vendor's risk profile doesn't freeze the day the contract is signed. Acquisitions happen, subcontractors change, security debt accumulates quietly. A once-a-year re-attestation for your higher-risk vendors catches a lot of drift that a one-time onboarding review never will.

Make sure procurement and security are actually talking. Procurement is often the first to notice something with security implications — a vendor being acquired, a subcontractor swap during renewal — before security ever hears about it. That signal is only useful if there's a clear, fast path to pass it along.

The Bottom Line

Every vendor a company brings on is a new node in its supply chain, whether it's a software platform or an HVAC contractor. Procurement is usually the first — and sometimes the only — point where that new party is formally introduced into the organization. Which makes procurement, quietly, one of the more important cybersecurity control points a company has.

Not because procurement teams need to run vulnerability scans. But because they're the ones deciding, contract by contract, who gets a foothold in the building — and whether that foothold comes with a lock on the door.