enBy Zeeshan Mallick

Your Startup’s Biggest Cyber Risk Is the Vendor You Trusted.

Verizon says third-party involvement in breaches doubled to 30%. Founders who protect the firewall but ignore vendors, contractors, SaaS tools, and AI access are leaving the real attack surface unowned.

Your Startup’s Biggest Cyber Risk Is the Vendor You Trusted. — The Mallick View
cybersecurityfoundersceovendor-riskthird-party-riskransomwareai-governancescaling
# Your Startup’s Biggest Cyber Risk Is the Vendor You Trusted. ## Direct answer **Your vendor is part of your attack surface.** A contract does not make a supplier safe. A brand name does not make a SaaS tool safe. Access that is not limited, logged, reviewed, and removable is not trusted access. It is an open door with paperwork around it. The controversial truth is that many founders protect the office network while ignoring the ecosystem that can reach the company: payroll tools, cloud software, agencies, contractors, accountants, developers, support platforms, and AI services. The company buys a firewall and calls the job done. Attackers look for the partner with a forgotten login. Verizon’s 2025 *Data Breach Investigations Report* analysed more than 22,000 security incidents, including 12,195 confirmed data breaches across victims in 139 countries. Third-party involvement in breaches doubled from 15% to 30%.[[1](https://www.verizon.com/about/news/2025-data-breach-investigations-report)][[2](https://www.verizon.com/business/resources/reports/2025-dbir-executive-summary.pdf)] That is not a minor supplier problem. It is a board-level operating risk. ## The data founders should take personally Verizon reports that credential abuse accounted for 22% of initial access vectors and vulnerability exploitation for 20%. Exploitation increased 34% from the prior report. Only about 54% of exploited edge-device and VPN vulnerabilities were fully remediated during the year, and the median time to remediate was 32 days.[[1](https://www.verizon.com/about/news/2025-data-breach-investigations-report)][[2](https://www.verizon.com/business/resources/reports/2025-dbir-executive-summary.pdf)] A vendor with an old integration or an exposed administrator account can become the shortest path into your company. The report also found that ransomware appeared in 44% of breaches and in 88% of SMB breaches. The median ransom paid was $115,000.[[1](https://www.verizon.com/about/news/2025-data-breach-investigations-report)][[2](https://www.verizon.com/business/resources/reports/2025-dbir-executive-summary.pdf)] For a young company, that is not an IT inconvenience. It can erase a hiring plan, a product launch, or months of runway. The hidden access problem is growing. Verizon found that 15% of employees routinely accessed generative-AI systems on corporate devices. Of those access patterns, 72% used non-corporate email identifiers and 17% used corporate email without integrated authentication.[[2](https://www.verizon.com/business/resources/reports/2025-dbir-executive-summary.pdf)] IBM reports that 97% of organizations with an AI-related security incident lacked proper AI access controls, while 63% of 600 surveyed organizations had no AI governance policy. High shadow-AI use added $670,000 to the global average breach cost, which IBM reported at $4.44 million.[[3](https://www.ibm.com/think/x-force/2025-cost-of-a-data-breach-navigating-ai)] This is the uncomfortable founder question: **how many vendors, contractors, and AI tools can still access your data today, even if you forgot why they were given access?** ## Perimeter-first versus ecosystem-first security | Founder assumption | What it misses | Better operating rule | |---|---|---| | “Our firewall protects us.” | A trusted vendor can enter through an approved connection. | Inventory every third party with access to data or systems. | | “The SaaS provider handles security.” | Your company still controls identity, permissions, exports, and offboarding. | Ask what the vendor can access, why, and how quickly access can be removed. | | “The contractor only needs access for a week.” | Temporary access often survives the project. | Set an expiry date before access is granted. | | “The AI tool is free, so the risk is small.” | Data can leave the company without a procurement review. | Approve tools, block sensitive data, and use company identity. | | “We will review vendors after we scale.” | A breach can arrive before the next funding round. | Tier vendors now by data sensitivity and business criticality. | | “MFA is an IT task.” | Unprotected admin or vendor accounts can unlock everything. | CEO owns the target; technical controls verify compliance. | CISA’s guidance for small businesses puts the CEO in the security role. It recommends a security program owner, a written incident response plan, leadership tabletop exercises, and MFA. It also says MFA must be enforced with technical controls, not faith; systems must be patched; backups must be tested; and administrator privileges should be removed from ordinary laptops.[[4](https://www.cisa.gov/cyber-guidance-small-businesses)] ## The six controls a founder can install this month First, make a one-page access register. List every vendor, contractor, agency, integration, AI service, and administrator account. Record the data touched, owner, purpose, last review date, and removal method. If nobody owns the access, the access owns you. Second, separate vendor risk from vendor paperwork. A signed data-processing clause is useful, but it does not tell you whether an old employee still has a live login. Ask for evidence: MFA, role-based access, breach notification, backup and recovery, subcontractors, audit logs, and deletion after termination. Third, use least privilege. Give a vendor only the data and permissions needed for the job. Do not provide production access when a test environment works. Do not provide all customer records when a limited export works. Fourth, make access expire. Every temporary account should have an end date. Every vendor should have an offboarding checklist. Review privileged access monthly and all other third-party access quarterly. Fifth, rehearse the vendor breach. Ask: who shuts off access, who calls the vendor, who informs customers, who preserves evidence, and who decides whether operations can continue? CISA recommends tabletop exercises because a plan that has never been practised is only a document. Sixth, treat AI as a vendor, not magic. Use company accounts, approved tools, data rules, access logs, and a clear list of information that may not be pasted into an external model. Speed without boundaries becomes security debt. ## The hard truth Founders often say they trust their partners. That may be true. It is also beside the point. A trusted partner can be hacked. A trusted contractor can reuse a password. A trusted tool can expose data through a configuration error. The control must survive the good intentions of every person in the chain. **Your firewall is not your security strategy. Your access map is.** If you cannot name every outside party that can reach customer data, money, source code, or production systems, you do not have a vendor list. You have an invisible co-founder with permission to fail. ## Frequently asked questions ### Is third-party involvement the same as vendor fault? No. Verizon’s third-party measure means a third party was involved in the breach, not that the vendor was legally responsible or careless. The operational lesson is that partner access changes your exposure. ### Which vendors should a startup review first? Start with vendors that can reach customer data, payment information, source code, production systems, identity systems, or backups. Review high-impact access before low-risk tools. ### What is the first vendor-security control to install? Create an access register with an owner, purpose, data scope, last review date, and removal method for every third party. Then revoke access that has no current owner or business reason. ### Does MFA solve vendor risk? No. MFA reduces account-takeover risk, but it does not replace least privilege, patching, logging, backups, vendor review, or an incident plan. CISA calls MFA a key control, not a complete security program. ### Should a startup ban generative-AI tools? Not automatically. The better approach is approved tools, company identity, clear data rules, access controls, and monitoring. IBM’s data shows that AI adoption without governance creates a measurable security gap. ### What should a CEO ask a vendor after a breach? Ask what happened, which systems and data were affected, when access was contained, what evidence is available, what controls failed, and what is changing. Have an internal owner document the answers and next actions. ## References 1. [Verizon, “2025 Data Breach Investigations Report: Alarming surge in cyberattacks through third-parties”](https://www.verizon.com/about/news/2025-data-breach-investigations-report). 2. [Verizon, *2025 Data Breach Investigations Report — Executive Summary*](https://www.verizon.com/business/resources/reports/2025-dbir-executive-summary.pdf). 3. [IBM, “2025 Cost of a Data Breach Report: Navigating the AI rush without sidelining security”](https://www.ibm.com/think/x-force/2025-cost-of-a-data-breach-navigating-ai). 4. [CISA, “Cyber Guidance for Small Businesses”](https://www.cisa.gov/cyber-guidance-small-businesses).

Master Collective Newsletter

Receive concise perspectives on founders, capital and strategic growth.

Book a Call