A Charlotte-area RIA we worked with earlier this year had exemplary internal security. Phishing-resistant MFA on Microsoft 365. EDR on every endpoint. Immutable backups. Real SOC coverage. Their incident didn't start on their network. It started at their outsourced bookkeeper — a small firm two counties over — whose accountant fell for an AiTM phish and gave up her Microsoft 365 session. That session had delegated access to the RIA's QuickBooks Online. Two days later, $84,000 in fake vendor payments went out the door.
Nobody breached the RIA. They breached the RIA's bookkeeper. The result was the same.
Third-party and supply-chain compromises now make up a growing share of the breaches the Verizon DBIR catalogs each year — roughly one in six confirmed data breaches in the 2024 report involved a partner or vendor as the entry vector. For SMBs, that number understates the pain, because the ratio of "vendors with real access to your data" versus "your own employees" is usually much higher than a Fortune 500's.
What "vendor risk" actually means for a small business
Every SMB is running dozens of third parties with access to something sensitive. A typical 40-person NC professional services firm we assess has:
- Outsourced bookkeeping or accounting (access to books, payroll, banking portals)
- Outside counsel (access to contracts, PII, sometimes client data)
- An external IT provider or MSP (privileged access to everything)
- A payroll provider (SSNs and direct-deposit routing)
- A CRM (client records, deal pipeline)
- A document management or eSign tool (executed contracts)
- An HR/benefits vendor (PII, health data)
- An outsourced marketing agency (M365 tenant access for content, sometimes brand domain access)
- A cyber insurance broker (they hold your questionnaires and often your renewal docs)
- A dozen SaaS point tools nobody remembers signing up for
Every one of those vendors is a potential path into your data. Any one of them, popped, is a bad day.
The three access patterns that matter
Vendor risk is easier to think about if you sort vendors by how they touch your environment. There are only three patterns:
1. Direct login as your users
Your bookkeeper, MSP, or marketing agency has actual user accounts in your Microsoft 365, QuickBooks, or CRM. If their laptop gets stolen, their session cookies leak, or they fall for an AiTM phish (see MFA Isn't Enough Anymore), the attacker walks in under a legitimate identity.
2. Delegated / OAuth / API access
Your payroll vendor connects to your bank via API. Your CRM integrates with your email. Your accounting tool has an OAuth grant to your document storage. These trust relationships persist without anyone typing a password — and they usually outlive the person who set them up. Half the SaaS OAuth grants in a typical M365 tenant are for tools nobody actively uses.
3. Custody without access
Your outside counsel keeps executed contracts. Your insurance broker keeps your renewal questionnaire (with all your control disclosures). Your PR firm keeps your press-ready customer list. They don't log into your systems, but they hold copies of your data in their systems. Their breach is your breach if the data is sensitive.
Vendor-risk programs that lump all three into one questionnaire miss what actually needs to be controlled for each.
Why "we sent them a questionnaire" isn't a program
The typical SMB vendor-risk process is: at contract renewal, someone sends the vendor a spreadsheet, the vendor sends it back with all "yes" answers, someone files it. That's compliance theater. Real vendor risk management does four things the questionnaire doesn't:
- Limits the blast radius on day one. The vendor gets the least access needed to do the job — not "domain admin because it's easier." Delegated access. Named accounts. No shared logins. MFA required on their end. Documented in writing.
- Watches the access continuously. Sign-in logs are reviewed. Unusual OAuth grants get flagged. The MSP's after-hours access gets logged and alerted on.
- Has a plan for their breach. If the vendor gets popped, you know what to do — who to call there, whose tokens to revoke here, what to tell your clients — before it happens.
- Reviews on a cadence, not on incident. Every 12 months you look at every vendor with production access, and prune what's not needed.
The North Carolina angle
For NC RIAs and financial advisors, vendor risk is not optional — it's an explicit expectation under the amended SEC Reg S-P (2024), which requires an incident response program that specifically addresses service-provider oversight and includes vendor notification obligations. For healthcare practices, HIPAA's Business Associate framework has been requiring documented vendor security posture and BAAs for years — but the audit evidence has gotten thinner as SaaS sprawl has grown. For anyone subject to a client audit (RIAs, defense contractors under CMMC, MSPs whose clients demand SOC 2), vendors and sub-vendors are the exact place auditors focus in 2026.
NC's Identity Theft Protection Act (75-65) also does not care whether the breach was “yours” or a vendor's — if unencrypted PII of NC residents got out, you have a notification obligation.
What WHT recommends
A vendor-risk program that a 20-to-150-employee firm can actually run:
- List every vendor with access, this month. One spreadsheet. Columns: vendor name, contact, what data or system they touch, access pattern (direct / delegated / custody), owner on your side, contract renewal date. Most firms have never done this. It usually takes an afternoon and produces uncomfortable surprises.
- Categorize by criticality. Tier 1: has admin access to your production data or can move money (MSP, bookkeeper, payroll). Tier 2: has significant delegated or user access (CRM, HR system, marketing agency). Tier 3: holds copies of your data (counsel, insurance broker, PR). Tier 4: everything else.
- Set minimum controls per tier. Tier 1 vendors get real diligence — SOC 2 Type II or equivalent, MFA (phishing-resistant preferred) on any account with access to your data, documented offboarding process, breach notification within 24 hours in writing. Tier 2 gets a lighter but real review. Tier 3 gets a data-handling attestation and BAAs where required. Tier 4 gets basic hygiene.
- Kill unused OAuth grants and dormant vendor accounts. In Entra ID (Microsoft 365), review Enterprise Applications and audit the permissions granted. Anything not actively used in 90 days gets revoked. Do the same in Google Workspace, Salesforce, and QuickBooks. This is one of the highest-ROI half-days in security.
- Contractual language that actually helps. New vendor contracts should require: written notification of any incident affecting your data within 24-72 hours, right to audit or receive a SOC 2/pen-test summary, defined offboarding process, and a specified breach-notification contact. Standard templates from your outside counsel are fine — but read them before signing.
- Include vendor scenarios in your tabletop. When you run your next 90-minute tabletop, dedicate one round to “your MSP just got breached, what do you do?” and one to “your bookkeeper's Microsoft 365 mailbox got taken over, what do you do?” The gaps you find are the ones that matter.
- Review annually. Once a year, walk the whole list. Prune vendors you no longer use. Reconfirm access is minimum needed. Update contact lists. This is a two-hour meeting, once a year.
Vendor risk is not glamorous. It's spreadsheets and cleanup. But the last three ugly incidents we worked in Charlotte started at a vendor, not at the client. The client had done the work. The vendor hadn't. It didn't matter which side was responsible — the client took the loss.
Not sure who has access to your environment?
We'll run a vendor-access review for your Microsoft 365 tenant and key SaaS tools, produce a tiered vendor list with real controls per tier, and hand you a 30-day cleanup plan. Flat fee, no follow-on obligation.