hiलेखक: Zeeshan Mallick

आपकी Startup का सबसे बड़ा Cyber Risk उस Vendor से है जिस पर आपने भरोसा किया।

Verizon के अनुसार breaches में third-party involvement double होकर 30% हुआ। जो founders firewall protect करते हैं लेकिन vendors, contractors, SaaS और AI access ignore करते हैं, वे असली attack surface को unowned छोड़ रहे हैं।

आपकी Startup का सबसे बड़ा Cyber Risk उस Vendor से है जिस पर आपने भरोसा किया। — The Mallick View
cybersecurityfoundersceovendor-riskthird-party-riskransomwareai-governancescaling
# आपकी Startup का सबसे बड़ा Cyber Risk उस Vendor से है जिस पर आपने भरोसा किया। ## सीधा जवाब **आपका vendor आपकी attack surface का हिस्सा है।** Contract vendor को safe नहीं बनाता। Famous brand किसी SaaS tool को अपने आप safe नहीं बनाता। ऐसा access जो limited, logged, reviewed और removable नहीं है, trusted access नहीं है। यह paperwork से घिरा हुआ open door है। असहज सच यह है कि कई founders office network को protect करते हैं, लेकिन उस ecosystem को ignore करते हैं जो company तक पहुंच सकता है: payroll tools, cloud software, agencies, contractors, accountants, developers, support platforms और AI services। Company firewall खरीदती है और काम खत्म मान लेती है। Attackers उस partner को खोजते हैं जिसका login कोई भूल चुका है। Verizon की 2025 *Data Breach Investigations Report* ने 22,000 से अधिक security incidents का analysis किया, जिनमें 12,195 confirmed data breaches थीं और victims 139 countries में थे। Breaches में third-party involvement 15% से double होकर 30% हो गया।[[1](https://www.verizon.com/about/news/2025-data-breach-investigations-report)][[2](https://www.verizon.com/business/resources/reports/2025-dbir-executive-summary.pdf)] यह छोटा vendor problem नहीं है। यह board-level operating risk है। ## Founders को इन numbers को seriously लेना चाहिए Verizon के अनुसार credential abuse initial access vectors का 22% और vulnerability exploitation 20% था। Exploitation पिछले report से 34% बढ़ा। Edge devices और VPNs में exploited vulnerabilities में केवल लगभग 54% साल के दौरान पूरी तरह remediate हुईं और median remediation time 32 days था।[[1](https://www.verizon.com/about/news/2025-data-breach-investigations-report)][[2](https://www.verizon.com/business/resources/reports/2025-dbir-executive-summary.pdf)] पुराना integration या exposed admin account company में आने का shortest path बन सकता है। Report में ransomware 44% breaches में और 88% SMB breaches में मौजूद था। Median ransom paid $115,000 था।[[1](https://www.verizon.com/about/news/2025-data-breach-investigations-report)][[2](https://www.verizon.com/business/resources/reports/2025-dbir-executive-summary.pdf)] Young company के लिए यह केवल IT inconvenience नहीं है। यह hiring plan, product launch या कई महीनों की runway मिटा सकता है। Forgotten access problem बढ़ रही है। Verizon ने पाया कि 15% employees corporate devices पर generative-AI systems को regularly access करते थे। इन access patterns में 72% ने non-corporate email identifiers और 17% ने corporate email बिना integrated authentication के इस्तेमाल किया।[[2](https://www.verizon.com/business/resources/reports/2025-dbir-executive-summary.pdf)] IBM के अनुसार AI-related security incident वाली organizations में 97% के पास proper AI access controls नहीं थे, और 600 surveyed organizations में 63% के पास AI governance policy नहीं थी। High shadow-AI use ने global average breach cost में $670,000 जोड़े; IBM ने global average cost $4.44 million report की।[[3](https://www.ibm.com/think/x-force/2025-cost-of-a-data-breach-navigating-ai)] Founder को यह uncomfortable question पूछना चाहिए: **आज कितने vendors, contractors और AI tools आपके data तक पहुंच सकते हैं, भले ही आपको याद न हो कि access क्यों दिया गया था?** ## Perimeter-first बनाम ecosystem-first security | Founder assumption | जो छूट जाता है | Better operating rule | |---|---|---| | “Firewall हमें protect करता है।” | Trusted vendor approved connection से अंदर आ सकता है। | Data या systems access वाले हर third party की inventory बनाएं। | | “SaaS provider security संभालता है।” | Identity, permissions, exports और offboarding अभी भी आपकी company control करती है। | पूछें vendor क्या देख सकता है, क्यों और access कितनी जल्दी हट सकता है। | | “Contractor को सिर्फ एक हफ्ते की access चाहिए।” | Temporary access project के बाद भी बच सकता है। | Access देने से पहले expiry date लगाएं। | | “AI tool free है, इसलिए risk छोटा है।” | Data procurement review के बिना company से बाहर जा सकता है। | Tools approve करें, sensitive data block करें और company identity use करें। | | “Scale होने के बाद vendors review करेंगे।” | Next funding round से पहले breach हो सकता है। | Data sensitivity और business criticality के हिसाब से vendors tier करें। | | “MFA IT का काम है।” | Unprotected admin या vendor account सब कुछ खोल सकता है। | CEO target तय करे; technical controls compliance verify करें। | CISA की small-business guidance CEO को security role में रखती है। यह security program owner, written incident response plan, leadership tabletop exercises और MFA की सलाह देती है। CISA यह भी कहता है कि MFA faith से नहीं, technical controls से enforce होना चाहिए; systems patch होने चाहिए; backups test होने चाहिए; और ordinary laptops से administrator privileges हटाने चाहिए।[[4](https://www.cisa.gov/cyber-guidance-small-businesses)] ## Founder इस महीने ये छह controls लगा सकता है पहला, one-page access register बनाएं। हर vendor, contractor, agency, integration, AI service और admin account लिखें। कौन सा data touch होता है, owner कौन है, purpose क्या है, last review कब हुआ और removal method क्या है—सब record करें। अगर access का कोई owner नहीं है, तो access company को own कर रहा है। दूसरा, vendor paperwork और vendor risk को अलग देखें। Data-protection clause useful है, लेकिन यह नहीं बताती कि former employee का login अभी live है या नहीं। Evidence मांगें: MFA, role-based access, breach notification, backup और recovery, subcontractors, audit logs और termination के बाद deletion। तीसरा, least privilege लागू करें। Vendor को केवल वही data और permissions दें जो काम के लिए जरूरी हैं। Test environment चले तो production access न दें। Limited export चले तो सारे customer records न दें। चौथा, access को expire कराएं। हर temporary account की end date होनी चाहिए। हर vendor के पास offboarding checklist हो। Privileged access monthly और बाकी third-party access quarterly review करें। पांचवां, vendor breach की rehearsal करें। कौन access बंद करेगा, vendor को कौन call करेगा, customers को कौन inform करेगा, evidence कौन बचाएगा और operations जारी रखने का फैसला कौन करेगा? CISA tabletop exercises की सलाह देता है क्योंकि जिसे कभी practice नहीं किया गया, वह plan केवल document है। छठा, AI को magic नहीं, vendor समझें। Company accounts, approved tools, data rules, access logs और external model में paste न किए जाने वाले information की clear list रखें। Boundaries के बिना speed security debt बन जाती है। ## कड़वी सच्चाई Founders कहते हैं कि वे partners पर trust करते हैं। यह सच हो सकता है। फिर भी यह समस्या हल नहीं करता। Trusted partner hack हो सकता है। Trusted contractor password reuse कर सकता है। Trusted tool configuration error से data expose कर सकता है। Control को chain में हर व्यक्ति की good intentions की गलती से बचना चाहिए। **आपका firewall आपकी security strategy नहीं है। आपका access map है।** अगर आप हर outside party का नाम नहीं बता सकते जो customer data, money, source code या production systems तक पहुंच सकता है, तो आपके पास vendor list नहीं है। आपके पास fail होने की permission वाला invisible co-founder है। ## Frequently asked questions ### क्या third-party involvement का मतलब vendor की गलती है? नहीं। Verizon का third-party measure केवल बताता है कि breach में third party शामिल था। यह नहीं बताता कि vendor legally responsible था या careless था। Operating lesson यह है कि partner access आपकी exposure बदलता है। ### Startup को पहले किन vendors को review करना चाहिए? उन vendors से शुरू करें जो customer data, payment information, source code, production systems, identity systems या backups तक पहुंच सकते हैं। सबसे high-impact access पहले review करें। ### पहला vendor-security control क्या होना चाहिए? हर third party के लिए owner, purpose, data scope, last review date और removal method वाला access register बनाएं। फिर ऐसा access revoke करें जिसका current owner या business reason नहीं है। ### क्या MFA vendor risk solve करता है? नहीं। MFA account takeover risk कम करता है, लेकिन least privilege, patching, logs, backups, vendor review और incident plan की जगह नहीं लेता। CISA इसे key control कहता है, complete security program नहीं। ### क्या startup को generative-AI tools ban कर देने चाहिए? जरूरी नहीं। Better approach approved tools, company identity, clear data rules, access controls और monitoring है। IBM data दिखाता है कि governance के बिना AI adoption measurable security gap बनाता है। ### Breach के बाद CEO को vendor से क्या पूछना चाहिए? पूछें कि क्या हुआ, कौन से systems और data प्रभावित हुए, access कब contain हुआ, evidence क्या है, कौन से controls fail हुए और क्या बदलेगा। Internal owner answers और next actions document करे। ## References 1. [Verizon, “2025 Data Breach Investigations Report: Alarming surge in cyberattacks through third-parties”](https://www.verizon.com/about/news/2025-data-breach-investigations-report). 2. [Verizon, *2025 Data Breach Investigations Report — Executive Summary*](https://www.verizon.com/business/resources/reports/2025-dbir-executive-summary.pdf). 3. [IBM, “2025 Cost of a Data Breach Report: Navigating the AI rush without sidelining security”](https://www.ibm.com/think/x-force/2025-cost-of-a-data-breach-navigating-ai). 4. [CISA, “Cyber Guidance for Small Businesses”](https://www.cisa.gov/cyber-guidance-small-businesses).

Master Collective न्यूज़लेटर

संस्थापकों, पूंजी और रणनीतिक विकास पर संक्षिप्त विचार पाएं।

कॉल बुक करें