TL;DR: Vendor risk gets managed as procurement, which is why renewals feel exhausting and exposure keeps growing. Every supplier holding your data or connected to your systems is part of your attack surface, and third parties now feature in nearly half of all breaches. Build one list of who can reach what, give it an owner, and review it before each renewal.
Vendor risk conversations take more energy than they should, and most people blame the vendors. Every supplier positions itself as critical. Every renewal arrives with urgency attached. Every platform promises efficiency, visibility, and lower cost.
That’s real, but it isn’t why those conversations drain you. They drain you because you’re doing two jobs at once with a process built for one.
The first job is commercial: price, terms, licensing, how hard it would be to leave. There’s usually a process for that. The second is security: what this company can see, what it can reach, and what happens to you if they get compromised. Almost nobody has a process for that, so it gets improvised in the same meeting, under the same deadline.
Why do vendor conversations take so much energy?
Because you’re negotiating a contract and approving an access relationship at the same time, and only one has a defined process. The commercial side has a renewal date and a budget line. The access side has nothing, so it gets decided by whoever needs the tool.
That’s why the same conversation feels heavier every year. The commercial questions stay roughly constant. The access questions multiply, because each new tool connects to something, and connections rarely get removed when the tool falls out of favor.
It’s also why they feel unwinnable. You’re judging dependency, support quality, integration, security exposure, and exit difficulty, then producing an answer by Friday because the quote expires.
The vendor nobody was worried about
In August 2025, attackers stole authentication tokens from Drift, an AI chat tool owned by Salesloft, and used them to pull data out of hundreds of companies’ Salesforce environments. Google’s threat intelligence team documented the campaign and put the number of affected organizations above 700, including several major security vendors.
Sit with what that involved. A website chat widget, almost certainly bought by marketing, connected to the CRM through a token so it could log conversations. That token bypassed the login screen entirely, so multi-factor authentication was irrelevant. The attackers spent ten days hunting for credentials buried in support tickets.
Nobody had classified their chat widget as a security exposure. It was a marketing tool with a monthly invoice. The contract was signed and the procurement box was ticked, and none of it mattered, because the risk lived in the connection rather than the agreement. The same now applies to every AI tool someone connects to your email, files, or CRM.
This isn’t rare anymore. Verizon’s 2026 Data Breach Investigations Report found third-party involvement in roughly half of breaches, up sharply year over year. IBM’s 2026 research found supply chain compromise was the largest cost amplifier it measured across thirty factors, adding about $227,250 to a breach, and the slowest to catch at 258 days.
Who owns the vendor list?
Ask who patches your servers and you’ll get an answer. Ask who maintains the list of outside companies that can reach your data and the room usually goes quiet.
Here’s how it splits. Finance has the invoices, so they know who you pay. The department that bought each tool knows what it does. IT knows about the ones that came through IT. Nobody holds all three views, and nobody is accountable for the whole picture.
So the list only assembles itself after an incident, when someone has to tell a lawyer or an insurer which vendors held customer data. That’s a bad time to start.
This is fixable in an afternoon, and it’s mostly clerical. One spreadsheet, one named owner, one review date. No governance program, no platform, which is the part most businesses assume they need and so never begin.
What belongs on a vendor list?
Not contract terms. Five things: what data they hold, what access they have, what breaks if they go down, how long replacement would take, and who inside your business owns the relationship. Put the renewal date in a sixth column so the review has a trigger.
Sort by access, not by spend. Your most expensive vendor may hold nothing sensitive, while a $40-a-month tool has a standing connection into your email and files. Cost tells you little about exposure, which is why finance-led reviews miss the ones that matter.
Then ask the concentration question. If your largest vendor disappeared tomorrow, how many things stop? Most small businesses have quietly built one or two single points of failure and find out during an outage rather than a review.
How do you check what your vendors can actually reach?
Open the list of connected applications in your Microsoft 365 or Google Workspace admin console and read it. In Microsoft 365 that’s Enterprise applications in the Entra admin center, which shows every outside app someone has granted access to, and what permissions it holds.
Most owners have never seen this screen, and the first look is usually uncomfortable. There will be tools nobody uses anymore, tools nobody recognizes, and at least one with broader permissions than anyone intended.
While you’re there, check your consent setting. By default, Microsoft lets users approve applications themselves for permissions that don’t require an administrator, which is how tools get connected without anyone in charge knowing. Microsoft tightened this for files and sites in 2025, but plenty of tenants still allow more than their owners realize. Restricting consent, or routing requests to an admin, is a short conversation with whoever manages your Microsoft 365 environment.
The last step is the one everyone skips. When you stop using a vendor, remove the connection, not just the subscription. A canceled invoice doesn’t revoke a token.
What to ask at renewal
Three questions, asked 90 days out rather than three days out. What data does this vendor hold now, versus when we signed? What access do they still need? And what would we do if they were breached tomorrow?
Answer that last one in writing, because your clients will eventually ask you the same thing. Vendor security questionnaires are now routine in professional services, manufacturing, and anything touching regulated data, and “we trust our suppliers” doesn’t win contracts.
Timing changes the dynamic more than negotiating skill does. A review starting three months out is a business decision. The same review three days before expiry is a renewal you’re going to sign, and the vendor knows it too. Working through the security side with an outside advisor, as part of a security review, takes the pressure off the deadline.
One more reason to care: when a supplier’s mailbox is compromised, the fraudulent invoice arrives from their real address, which is why email filtering and payment verification belong in the same conversation.
The takeaway
Vendor management feels exhausting because it’s handled as procurement when half of it is access control. The commercial process has an owner and a calendar. The access side usually has neither.
You don’t need a program. You need a list of who can reach what, one person accountable for it, and a review that starts before the renewal quote lands.
If you’d like help building that list and finding what’s already connected to your systems, book a short call. The first pass usually turns up something nobody knew was there.
Frequently Asked Questions
What is third-party or vendor risk?
The exposure created by outside companies that hold your data or connect to your systems. If a supplier is compromised, attackers reach you through a trusted connection. Verizon’s 2026 report found third parties involved in roughly half of breaches.
How did attackers use a chat tool to reach Salesforce data?
They stole the authentication tokens the chat tool used to connect to customers’ Salesforce accounts. Those tokens work like a pre-approved key, so attackers never touched a login screen and MFA offered no protection. More than 700 organizations were affected.
What should a small business vendor inventory include?
What data each vendor holds, what system access they have, what breaks if they go down, how long replacement would take, who owns the relationship internally, and the renewal date. Sort by access rather than cost, since price is a poor indicator of exposure.
How do I see which apps have access to my Microsoft 365?
Sign in to the Microsoft Entra admin center and open Enterprise applications, which lists every third-party app granted access and the permissions it holds. Review it, remove what’s unused, and check your user consent setting while you’re there.
Does canceling a subscription remove a vendor’s access?
Not necessarily. Billing and access are separate. A vendor’s connection to your systems can survive long after you stop paying, so removing the app or revoking its token should be a step in your offboarding process.
Find Out What’s Already Connected
Most businesses are surprised by what shows up the first time someone reads the full list of applications with access to their data. Z-JAK helps Louisville companies build a vendor inventory, close unused connections, and get a review on the calendar before renewals arrive. Get in touch and we’ll take a look together.
