Vendor Risk Scoring System: 5 Powerful Steps

Kevin Mabry shares a practical, 5-step vendor risk scoring system for small firms. Learn why 48% of breaches involve third parties and how to protect your data.
Why Your Small Firm is Now a Target via Your Vendors
Since I started helping small professional service firms back in 1999, I’ve watched the threat landscape shift from bored teenagers creating nuisances to highly organized criminal syndicates seeking maximum profit. Today, in 2026, the game has changed again. If you run a firm with 10 to 100 employees, you’ve likely spent money on a firewall, decent antivirus, and maybe even some security training for your team. But here is the reality I see every day: your front door might be locked, but your vendors are holding the keys to the back door, and many of them are leaving that door wide open.
According to the Verizon 2026 Data Breach Investigations Report, third-party involvement in breaches has jumped significantly, now accounting for 48% of all confirmed breaches—up from just 30% a year ago. Attackers have realized that instead of trying to hack fifty small law firms or accounting practices individually, they can just hack one software provider or IT service that all fifty firms use. I call this the "Concentration of Risk," and if you don't have a system to measure it, you are effectively flying blind.
Key Takeaways for Small Business Owners
- Supply Chain is the #1 Vector: Nearly half of all breaches now originate through a vendor or partner relationship.
- Small Does Not Equal Safe: 43% of cyberattacks target small businesses, often because they are the easiest way to reach larger targets.
- The "One and Done" Myth: Checking a vendor's security once at the start of a contract is no longer enough; risk management must be a continuous cycle.
- Financial Stakes: The average cost of a supply chain compromise has reached $4.91 million, and for a small firm, a single incident can cost between $120,000 and $1.24 million—enough to put most out of business.
- Plain English Works Best: You don't need a PhD in cybersecurity to manage vendor risk. You need a structured, 5-step scoring system that turns technical noise into business decisions.
The High Cost of "Assuming" Your Vendors are Secure
In my 26 years of doing this, the most heartbreaking calls I get are from business owners who thought they were doing everything right. I remember working with a 20-person architecture firm recently. They had a great internal culture, strong passwords, and MFA on everything they controlled. But they used a specialized cloud-based rendering service that didn't require MFA for its administrative accounts. A criminal group gained access to that vendor, stole the architecture firm’s proprietary designs, and held them for a $250,000 ransom. The firm assumed the vendor was secure because the software was "industry standard."
That assumption is a $4.91 million gamble. According to the IBM Cost of a Data Breach Report 2025, supply chain breaches take 26 days longer to detect than average breaches because we inherently trust the traffic and access coming from our established partners. While the average breach takes 241 days to identify and contain, a vendor-related breach often drags on for 267 days. That’s nearly nine months of a criminal sitting in your systems, watching your emails, and waiting for the perfect moment to strike.
Step 1: Build a Real Inventory (No, Your QuickBooks Isn't Enough)
The first step in my 5-step scoring system is knowing who you are actually doing business with. Most owners think they have five or six key vendors. When I sit down with them and we dig into the "Shadow IT"—the apps employees signed up for with a credit card without telling anyone—that number usually jumps to fifty or sixty.
You need to list every entity that has access to your data, your systems, or your physical office. This includes:
- Software Providers (SaaS): CRM, email, accounting tools, and project management.
- IT and Security Partners: Your MSP, web host, and backup providers.
- Professional Services: Your outside counsel, tax preparers, and consultants.
- Physical Vendors: The cleaning crew that has keys to the office, the HVAC company with remote access to your thermostat, and the shredding service.
If you don't know they exist, you can't score the risk they pose.
Step 2: Classify Vendors by "Data Gravity"
Not all vendors are created equal. If your cleaning service gets hacked, it’s a problem, but it’s not an existential threat to your firm. If your cloud file storage provider gets hacked, it’s a catastrophe. I use a simple 3-tier classification system to save my clients time:
| Tier | Description | Examples |
|---|---|---|
| Tier 1: Critical | Direct access to client PII, financial data, or core operations. No easy fallback if they go down. | Cloud Storage, ERP, Managed Service Provider (MSP). |
| Tier 2: Important | Access to internal business data (non-sensitive) or helpful but non-essential tools. | Marketing automation, Project management tools, Travel agencies. |
| Tier 3: Low Risk | No data access. Low operational impact if they disappear for a week. | Office supply vendors, Janitorial services (if no keys), Landscaping. |
Stop wasting time doing deep security audits on your coffee supplier. Focus 80% of your energy on Tier 1.
Step 3: Apply the Scoring Matrix
This is where we turn "gut feelings" into a measurable score. I recommend a simple 1–10 scale based on five key dimensions. You don't need a technical team to do this; you just need to ask for specific documents from your vendor. If they won't give them to you, that is a red flag in itself.
The Five Dimensions of the Sentree Score:
- Third-Party Validation (Weight: 30%): Do they have a SOC 2 Type II report or an ISO 27001 certification? These are independent audits. In my experience, a vendor who says "trust us, we’re secure" but has no audit is someone you should avoid.
- Access Control (Weight: 25%): Do they require Multi-Factor Authentication (MFA) for all their employees? Do they offer MFA for your users? If the answer is no, their score should drop significantly.
- Data Handling (Weight: 20%): Is your data encrypted "at rest" (while sitting on their servers) and "in transit" (while moving to your computer)?
- Incident Response (Weight: 15%): Do they have a written plan for what happens if they get hacked? Will they notify you within 24 hours? Under the latest FTC Safeguards Rule updates, reporting thresholds have lowered, making this timeline critical for your own compliance.
- Financial Stability (Weight: 10%): A vendor that goes bankrupt can be just as disruptive as a vendor that gets hacked.
Step 4: The "Trust but Verify" Assessment
Once you have the numbers, you have to verify them. I once worked with a mid-sized law firm that sent out a security questionnaire to their document hosting provider. The vendor checked all the right boxes, but when we asked to see their last penetration test summary, it was three years old. A lot changes in three years in cybersecurity.
For Tier 1 vendors, you must see the proof. Ask for:
- A copy of their SOC 2 Type II report (read the "Exceptions" section—that's where the skeletons are buried).
- Proof of Cyber Liability Insurance. If they don't have it, they might not have the funds to help you recover after a breach.
- A summary of their most recent penetration test.
If a vendor is too small to have a SOC 2 report, I look for their Written Information Security Plan (WISP). Every firm handling sensitive data should have one. If they don't know what a WISP is, they aren't ready to handle your clients' data.
Step 5: Continuous Monitoring (The Lifecycle Approach)
The biggest mistake I see small firms make is treating vendor risk like a box they check during onboarding and then forget about for three years. In 2026, risk is dynamic. A vendor that was secure in January could be sold to a less-secure parent company in June or suffer a major breach in October.
I advise my clients to set a "Trigger-Based Review" schedule:
- Tier 1 Vendors: Reviewed every 6 months or whenever they announce a major software update or change in ownership.
- Tier 2 Vendors: Reviewed annually.
- Event Triggers: Any time you see a news report about a vulnerability in a tool you use, your score for that vendor should be updated immediately.
Tools like BitSight or SecurityScorecard can provide a "letter grade" for your vendors' external security posture. These are great data points, but I tell my clients they are just one part of the score—not the whole story. You still need to know how they handle your specific data internally.
The Real Cost of Doing Nothing
I know what you’re thinking: "Kevin, this sounds like a lot of work for my 15-person firm." You’re right. It is work. But let’s look at the ROI. According to the 2026 Verizon DBIR, 60% of small businesses that suffer a major cyberattack go out of business within six months. The cost of prevention—setting up this system and spending a few hours a month managing it—is about 50 to 60 times less than the cost of recovery.
A typical recovery for a small firm involving forensics, legal fees, and downtime starts at around $120,000. Managing your vendor risk costs a fraction of that in time and software. In my book, that's not just a security decision; it's a smart business decision.
Frequently Asked Questions
What is a "Fourth-Party" risk?
This is the risk posed by your vendor's vendors. For example, if you use a cloud CRM, and that CRM uses Amazon Web Services (AWS) to store data, AWS is your fourth party. You should ask your Tier 1 vendors how they manage their third-party risks.
How do I handle a vendor that refuses to answer my security questions?
In 26 years, I’ve learned that silence is a symptom. If a vendor refuses to provide a SOC 2 or answer basic questions about MFA, they are telling you that they don't take your data seriously. You have to decide if that risk is worth the service they provide. Often, there is a competitor who will provide that transparency.
Does the FTC Safeguards Rule apply to my small firm?
If you handle customer financial information—including tax prep, mortgage brokering, or investment advice—the answer is almost certainly yes. The rule specifically requires you to oversee your service providers and ensure they are maintaining safeguards. Failure to do so can lead to heavy fines and legal repercussions.
What is the most important question to ask a new vendor?
"Can you show me your most recent independent security audit?" If they can’t, or they point you to a generic marketing page, you know exactly where they stand on the maturity scale.
Final Thoughts
Cybersecurity doesn't have to be a dark art. It’s about making better decisions with the information you have. By implementing a Vendor Risk Scoring System, you are taking control of the "back door" to your firm. You are telling your clients, your employees, and your partners that you are a professional organization that respects the trust placed in you. If you need help building your first inventory or classifying your tiers, reach out. This is what I’ve been doing since 1999, and I’m here to help you get it right.
Related Articles in Vendor Risk Management
- 5 Tips for Effective Vendor Risk Management program
- 7 Powerful Steps for Your Vendor Risk Management Checklist
- 5 Powerful Steps to Assess Vendor Risk Effectively
- 7 Critical Ways Vendor Risk Assessment Services Protect You
- 5 Shocking Pitfalls of Vendor compliance requirements
- 5 Powerful Third-Party Risk Monitoring Tools for SMBs
- 5 Powerful Ways to Reduce Vendor Cybersecurity Risks
- 5 Powerful Steps: Vendor Contract Risk Analysis
- 5 Powerful Benefits of Vendor Risk Management Software
- 5 Powerful Steps: Guide to Vendor Risk Assessments
- 7 Critical Small business vendor risks You Must Address
- 5 Proven Vendor Cyber Risk Management Solutions for Security
- 5 Essential Top Vendor Risk Management Tools to Win
- 5 Epic Gains from Vendor Risk Assessment Template
- 7 Epic Best Practices for Vendor Security
- 3 Critical Ways To Evaluate Vendor Cybersecurity Programs
- 5 Effective Vendor Risk Mitigation Strategies for Businesse
- 5 Powerful Gains With Vendor Risk Management Outsourcing
- The Ultimate Third-Party Risk Compliance Guide: 5 Steps
- 5 Hidden Dangers in Vendor risk management for SMBs — Complete guide on Vendor Risk Management
- 7 Hidden Vendor Risk Management Challenges Unveiled
- 5 Essential Vendor Risk Reduction Solutions
Watch: Stop Vendor Attacks: SMB Cyber Defense in 3 Steps 🚨
Kevin Mabry
Founder & CEO, Sentree Systems
Kevin Mabry is the founder and CEO of Sentree Systems, a cybersecurity company serving small professional service firms with under 100 employees. Since starting his business in 1999, Kevin has spent more than 26 years helping organizations protect sensitive information and make smarter technology and security decisions.
His work focuses on helping business owners protect client data, reduce cyber risk, and avoid the operational disruption caused by ransomware, account takeovers, phishing, and other preventable threats. Kevin is known for explaining cybersecurity in plain English without vendor hype, unnecessary jargon, or treating cybersecurity like generic IT support.
Is your business protected?
Get a free security assessment. We'll identify your biggest risks and give you a clear, plain-English action plan — no obligation.
Schedule Your Free Assessment