Cybersecurity Glossary
Vendor Due Diligence
Checking what a supplier does with your data and systems before you sign, and again later.
What Vendor Due Diligence means
Due diligence does not have to be a hundred question spreadsheet. For most small organisations the useful version is a short set of plain questions about access, internal controls, breach notification, data location and what happens at the end of the contract, plus a copy of any certification the supplier claims.
Why Vendor Due Diligence matters for small businesses and nonprofits
The 2026 Verizon Data Breach Investigations Report put third party involvement in forty eight percent of breaches. Your security is partly your bookkeeper security and your web agency security, and most companies have never written down who those parties are.
What to do about Vendor Due Diligence
- List every supplier with access to your data or systems, then rank them by what they could reach
- Send the same six questions to each, and treat a vague answer as an answer
- Put deletion at the end of the contract in writing, with a date
Not sure where you stand on this?
We review your current setup against the basics, tell you plainly what is covered and what is not, and give you a ranked list with effort and cost. No jargon and no scare tactics.
Checking what a supplier does with your data and systems before you sign, and again later.