The economics explain everything. Breaching one mid-market company yields one victim. Breaching one widely used vendor — a file-transfer product, a remote-management tool, a payroll processor — yields every customer at once, delivered through the trusted channels their firewalls were configured to welcome. Verizon's 2026 DBIR put third-party involvement at 48% of breaches, up from 30% the year before. Attackers didn't get twice as lucky; they industrialized the approach.
For an SMB the problem is sharper than for an enterprise, because so much of the stack is outsourced: email lives with one vendor, files with another, payroll with a third, and your IT provider itself holds administrative keys to everything. Each relationship is a door. Most companies have never counted the doors.
The four ways vendor risk actually reaches you
- Compromised software updates. The vendor ships poisoned code; your systems install it obediently, signed and trusted.
- Breached service providers holding your data. The payroll, benefits, legal, or file-sharing vendor is breached — and your employees' or clients' data walks out of their building, with your name on the notification letter.
- Remote-access tools and IT providers. The tools that manage networks at scale are the highest-value target of all — one console, hundreds of client networks. Ask any provider (including us) how their own access is secured, segmented, and monitored. It's the most revealing question in the industry.
- Plain old compromised email. A supplier's mailbox falls, and the "updated banking details" invoice arrives mid-thread from a real address at the right moment — the mechanism behind much of the $3.05 billion in BEC losses the FBI logged last year.
What "managing it" looks like on an ordinary month
Vendor risk management sounds like an enterprise program, so here's the SMB-sized version in practice. Once: build the inventory and tier it — an afternoon with the accounts-payable list open, because AP knows every vendor you actually pay. Monthly: five minutes reviewing new vendor accounts and access grants; anything with admin-level reach gets a second signature. Quarterly: one standing agenda item — which vendor relationships ended, and did their access end with them? That last question finds something surprising almost every time we run it for a new client: the marketing agency from two contracts ago still syncing a shared drive, the former IT provider's remote agent still installed on three machines.
Annually: re-verify the top tier. Current SOC 2 or equivalent, MFA attestation, breach-notification clause in the current contract version — not the one from 2022. None of this requires software you don't own or expertise you have to hire; it requires a calendar and an owner. That's precisely why it doesn't happen in most businesses — and why, when the disclosure email eventually arrives from some vendor's counsel, the companies that did this quiet work read it as an item to process instead of an emergency to survive.