
You can spend a fortune securing your own systems and still get breached through a supplier. Your accounting platform, your IT provider, your bookkeeper, the cloud tool your team signed up for last week: each one either holds your data or connects to your systems, and each one can become the way an attacker gets in. A vendor security review is how you check, before you hand anything over, that a supplier can be trusted with it. The good news is that you do not need a procurement department or a compliance officer to run one. You need a simple, repeatable process, and this guide gives you exactly that.
Why a vendor security review matters
Attackers have worked out that breaking into one popular supplier can hand them a path into hundreds of that supplier’s customers. Compromise a widely used piece of software or a managed service provider, and the access flows downstream to everyone who trusts it. Because the connection looks legitimate, these attacks are often harder to spot than a direct assault on your own network.
There is a legal dimension too. Under the Privacy Act, your business stays accountable for the personal information it holds even when a third party is the one storing or processing it. Handing customer records to a supplier does not hand over the responsibility. If that supplier is breached and your customers’ data is exposed, the obligations under the Notifiable Data Breaches scheme can still land on you. A short review up front is far cheaper than the clean-up afterwards.
The Australian Cyber Security Centre puts this plainly in its guidance on cyber supply chains: you cannot manage a risk you have not identified, and you should set clear security expectations with the suppliers who matter most. A vendor security review is simply how you turn that advice into a habit.
When to run one (and when not to bother)
You do not need to review every supplier to the same depth. The company that services your coffee machine does not warrant the same scrutiny as the platform that holds your customer database. The trigger for a proper review is access: does this vendor store your data, log in to your systems, or handle personal information about your staff or customers? If the answer is yes, review them before you sign. If it is no, a light touch is fine.
There are four moments when a review is worth the effort: before you onboard a new supplier, when you renew a contract, when a vendor changes ownership or suffers a breach, and once a year for the handful of suppliers your business genuinely depends on. Building the check into these moments means it happens on its own, rather than only after something has gone wrong.
Step 1: Sort your suppliers by risk
Start by listing every third party that stores your data or connects to your systems. This list is often longer than owners expect, because staff sign up for handy tools without telling anyone. If you have never mapped this, our guide to shadow IT and the apps your team uses without telling you is a useful place to begin.
Then sort the list into three tiers. High risk covers suppliers that hold sensitive data or have deep access to your systems: your accounting software, your IT provider, your core business platform. Medium risk covers tools with some access or limited data. Low risk covers everything else. Put your effort where it counts. A thorough review of your top five suppliers protects you far more than a shallow glance at fifty.
Step 2: Ask the right questions
For each high risk supplier, send a short set of questions and ask for written answers. You are not trying to catch them out; you are checking that the basics are in place and creating a record you can point to later. A practical starter set looks like this:
- Do you enforce multi-factor authentication on your staff accounts and offer it on ours?
- How is our data stored and is it encrypted, both when it is moving and when it is sitting on your servers?
- Where is our data physically held? If it leaves Australia, which countries is it stored in?
- Who on your side can access our data, and how do you limit that access to people who genuinely need it?
- How would you tell us about a breach, and how quickly? What does your incident response process look like?
- Do you hold any security certifications, such as ISO 27001 or SOC 2, or align with a recognised framework?
- How do you back up our data, and how would you restore it if something went wrong?
- What happens to our data when we leave? How is it returned or deleted?
Keep the list proportionate. Eight clear questions answered honestly tell you more than a forty-page questionnaire that nobody reads. For medium risk suppliers, a trimmed version covering multi-factor authentication, data location and breach notification is usually enough.
Step 3: Check the evidence, not just the answers
Answers on a form are a starting point, not proof. For your most important suppliers, ask for something that backs up what they told you. A copy of their ISO 27001 certificate or SOC 2 report, a summary of their most recent penetration test, or a link to their public security and privacy documentation all count. A supplier with a mature security posture will have these ready and will not be offended that you asked. A supplier that cannot produce anything, or that treats the question as an imposition, has just told you something useful.
Match the depth of evidence to the tier. For a high risk vendor holding your customer database, a certificate or audit report is reasonable. For a medium risk tool, a clearly written security page and a straight answer on multi-factor authentication may be all you need. The point is to move beyond taking claims at face value for the suppliers who could hurt you the most.
Step 4: Limit access and put it in writing
A review is only worth doing if it changes what you actually do. Two actions turn the paperwork into protection. First, grant least privilege: give every supplier only the access they genuinely need, and remove it the moment the relationship ends. An old vendor login that still works months after you stopped using the service is a gift to an attacker. The same discipline that applies inside your business, covered in our guide to restricting admin privileges, applies to the suppliers you connect to.
Second, put your expectations in the contract. Include a requirement to protect your data, to use multi-factor authentication, and above all to notify you promptly if they suffer a breach. That notification clause matters more than almost anything else, because your own obligations under the Notifiable Data Breaches scheme depend on you finding out quickly. If a supplier sits on a breach for weeks, your business is the one left explaining the delay.
Step 5: Review again, not just once
A vendor security review is not a one-off gate you pass through at onboarding and then forget. Suppliers change: they get acquired, they move data to new regions, they cut corners under financial pressure, and sometimes they get breached. Set a reminder to revisit your high risk suppliers once a year, and to run a fresh review whenever a vendor changes ownership or makes news for the wrong reasons.
Keep the records somewhere central: who you reviewed, when, what they told you, and what evidence you saw. When a client, an insurer or an auditor asks how you manage third party risk, a simple folder of completed reviews is a far better answer than a shrug. It also makes each year’s review faster, because you are updating last year’s file rather than starting from scratch.
Keep it simple and keep it going
The goal is not a perfect audit of every partner you have ever used. It is a light, honest process that you actually run: a tiered list, a short set of questions, some evidence for the suppliers that matter, least privilege access, a breach-notification clause, and a yearly look back. Done consistently, that beats an elaborate framework that lives in a drawer. Most breaches that come through suppliers exploit the basics being missing, so getting the basics right for your top few vendors closes most of the gap.
Find out where you stand
Third party risk is one piece of a bigger picture, and it is hard to know how you are tracking without a clear view of the whole. Our free self-assessment walks you through 27 plain-English questions and produces a personalised report mapped to the ACSC Essential Eight, ISO 27001 and SOC 2, so you can see where your business is strong and where the gaps are, including the risks that come through the suppliers you rely on. It takes about five to ten minutes and you get your report straight away. Take the free security assessment and get a practical picture of where you stand today.