Vet your vendors

Vendor incidents usually begin with a handover nobody questioned.

Their gap becomes your incident.

Accountability for a compromise extends to whoever you share content with. Five questions can identify their gaps before they become yours.

A vendor is anyone you hand content to: a subcontractor, a colorist, a transcription service, a cloud tool. If you're a freelancer and you pass work along, this is your supply chain too.

Before you send anything, you can also check the TPN company registry. It's free, an account costs nothing, and it lists TPN members along with the shield status each one holds — a quick way to see where a third-party vendor stands before you hand over sensitive content.

Five questions. One email. Fifteen minutes.

You don't need to be a security expert. The answers show whether a vendor takes the basics seriously.

  1. Is multi-factor authentication enabled and if so, for which accounts (e.g. email, file transfers, remote access, etc.)?

    Stolen passwords are one of the most common issues in industry security alerts, which makes this a great place to start.

    Good answer: Yes on all accounts and for everyone, not just administrators.
    If not: Ask your vendor to enable MFA. It's usually free and can be turned on for a whole team in one setting.
  2. Who can access our content, and how is access removed when someone leaves or changes roles?

    Unnecessary access widens the damage if something goes wrong. Additionally, the process for employees who leave the company is a good indicator of how well access is managed.

    Good answer: A named access list, with access reviewed when someone's role changes and removed the day they leave the company.
    If not: Ask your vendor to start keeping a simple access list, and to remove someone's access both when their role changes and when they leave.
  3. How is our content stored and delivered, and is it encrypted at both stages?

    Storage and delivery are where content is most often exposed, through unsecured drives, personal cloud accounts, or unencrypted transfers.

    Good answer: Access-controlled storage and a managed transfer service, both named and both encrypted.
    If not: Tell your vendor encryption is expected at rest and in transit. Most can switch tools quickly once they know.
  4. Do subcontractors or freelancers touch our content? If so, are they under agreement (e.g. NDA, confidentiality, etc.) and do you get our approval first?

    The chain usually runs one step further than you think, and you can't approve someone you don't know exists.

    Good answer: Yes. We get your approval before any subcontractor touches your content, and they follow the same rules we do.
    If not: Ask for approval before any subcontractor is added, and the same basics (MFA, access controls) applied to them.
  5. If something goes wrong, do you have a response plan that includes us, and how quickly will you tell us?

    Fast, clear notification is often what limits the damage.

    Good answer: A named contact and a same-day or next-business-day commitment to notify, even before all the facts are known.
    If not: Ask them to name a contact and agree on a notification timeline now, before you need it.
Free · no account needed · copy and send
Up next for Sam

Train your team

Asking the questions showed Sam what the vendors were doing. The same habits had to hold at home — so Sam turned to free security training the whole team could take.

Train your team →