.Our IT has been outsourced, so this is with the supplier.
There's a big risk for me right now.
The execution can be with the supplier. The consequences of failure, data loss or a security incident are ultimately with your organisation.
Therefore, you don't just want to assess critical IT providers on price, service and satisfaction.
You want to know if you have enough certainty about security, continuity and recovery.
Step 1: first determine whether the supplier is really critical
Question:
- a key process shall cease without this Party;
- processes the supplier's sensitive data;
- he/she has management rights;
- is difficult to switch;
- recovery depends heavily on this party;
- use critical subcontractors.
The more .ja.ja. the more the assessment.
Step 2: Understand the service and the responsibility limit
This sounds simple, but it often goes wrong here.
Record:
- the supplier's management;
- the organisation itself;
- who is responsible for accounts;
- who's patching;
- monitoring;
- who takes care of backup;
- who detects incidents;
- who's doing recovery.
An unclear border almost always leads to delays during incidents.
Step 3: demand for concrete security measures
I wouldn't just ask:
.
Question also:
- Our service falls within the scope;
- how admin access is secured;
- shall be required to do so;
- how vulnerabilities are managed;
- how logging is monitored;
- how staff are screened where relevant;
- how to separate our data;
- how changes are controlled.
The answer ‘we follow best practices’ is too vague.
Step 4: request proof
Evidence may consist of:
- ISO 27001 certification;
- SOC/ISAE report;
- audit report;
- penetration test;
- vulnerability reporting;
- restore test;
- SLA reporting;
- incident statistics;
- Control statement.
Do not judge only whether a document exists.
Look at:
- Scope;
- date;
- exceptions;
- relevant findings.
Step 5: assess continuity
Question:
- what is the agreed availability;
- which RTO and RPO apply;
- when recovery has been tested;
- which dependencies exist;
- what happens to ransomware;
- how quickly the service can be restored elsewhere;
- which capacity is available in case of a major incident.
A 99.9% SLA says nothing about the quality of recovery after a complex cyber attack.
Step 6: Review incident management
Pre-capture:
- the time limit for reporting incidents;
- who is contact person;
- what information you receive;
- how often updates are made;
- who conducts forensic research;
- how data is secured;
- who supports legal notifications.
Ask for a recent incident or exercise.
Not to settle the supplier, but to see how the process really works.
Step 7: look at admin access
External administrators often have very wide rights.
Check:
- individual accounts;
- MFA;
- privileged access;
- logging;
- temporary rights;
- periodic reviews;
- offboarding;
- subcontractors.
A shared administrator account would prompt me to ask for it.
Step 8: look at the supplier chain
Ask which subcontractors are essential.
Examples include:
- Cloud Provider;
- data centre;
- support partner;
- authentication service;
- backup provider.
You want to know where concentration risk is and what changes are reported.
Step 9: assess contract and SLA content
I would like to see at least that agreements exist on:
- security;
- access;
- incident reporting;
- logging;
- backup;
- recovery;
- right of audit;
- Insurance;
- subcontractors;
- data ownership;
- exit;
- data deletion.
Contractual text is not a guarantee, but an important control tool.
Step 10: Test exit question
Let's say:
♪ If we have to leave in three months, what do we need? ♪
Look at:
- export formats;
- documentation;
- configurations;
- dates;
- accounts;
- transfer;
- costs;
- dependency on intellectual property;
- escrow where relevant.
A difficult departure increases supplier risk.
How do you judge the answers?
I wouldn't just score on a subject.
Note:
- risk;
- evidence;
- open uncertainty;
- owner;
- Follow-up.
Examples include:
| Subject matter | Status | Evidence | Open Point |
|---|---|---|---|
| MFA management accounts | Green | Configuration + audit report | None |
| Restore | Orange | Backup reporting | No recent full restore test |
| Incident Notification | Orange | Contract | No clear first reporting period |
| Exit | Red | None | Export and transfer not worked out |
That gives a lot more grip than one supplier.
What questions does a CFO ask?
For finance, I would look at:
- continuity impact;
- concentration risk;
- financial health;
- exit costs;
- liability limits;
- insurance;
- repair costs.
What questions does a CIO or IT manager ask?
This is the focus of the debate:
- technical controls;
- management rights;
- integrations;
- logging;
- patching;
- monitoring;
- recovery;
- change management.
What questions does governance or oversight ask?
They don't have to read every control report.
I'd like to know:
- which suppliers are critical;
- where there is no significant evidence;
- where the main residual risks are;
- which actions are lagging behind;
- which party makes the organisation disproportionate.
That's controllable information.
My main supplier demand
If I had to choose one question, it's:
.
This will automatically ignore sales brochures and general certifications.
For a broader approach to supplier risk, read also:
Third-party risk management: How do you control digital supplier risks?


