A mid-sized professional services firm renews its vendor risk questionnaire every year. Every vendor on the list checks the boxes: SOC 2 report on file, encryption in place, a named security contact. The audit trail looks clean. Then a scheduling vendor with access to client calendars gets compromised, and the firm spends three weeks explaining to clients why a tool nobody thought twice about became the entry point for a breach.

This is not a rare story. Verizon’s 2025 Data Breach Investigations Report found that third-party involvement in confirmed breaches doubled year over year, jumping from roughly 15 percent to 30 percent of all breaches analyzed. Vendor risk has moved from a compliance footnote to one of the most common ways organizations get hurt, and the standard questionnaire most businesses rely on was not built for that reality.

EasyIT, a Columbus, Ohio-based managed IT and cybersecurity provider that works with healthcare, legal, manufacturing, and nonprofit organizations across the region, has reviewed enough of these questionnaires to see the pattern. They tend to confirm that a vendor has controls. They rarely test whether those controls actually hold up when something goes wrong.

The Checklist Confirms Existence, Not Resilience

Most vendor questionnaires ask some version of the same questions: Do you encrypt data at rest? Do you have a SOC 2 or ISO 27001 certification? Do you carry cyber liability insurance? These are reasonable starting points, but they answer a narrow question: does the vendor have a control on paper.

They don’t answer whether that control was tested in the last 12 months, how long it takes the vendor to detect an intrusion, or what the vendor’s actual track record looks like when something fails. A vendor can hold a valid certification and still take weeks to notice a compromised account, because certification audits sample controls at a point in time. They don’t measure how a vendor performs under pressure.

NIST has been pushing organizations toward a different posture for exactly this reason. Its cyber supply chain risk management guidance frames vendor evaluation around ongoing visibility into a supplier’s practices, not a one-time form, treating vendor relationships as something to monitor continuously rather than approve once and forget.

The Subcontractor Problem Nobody Asks About

A vendor questionnaire almost never asks who the vendor’s own vendors are. That gap matters more than it used to. A cloud-based practice management platform might rely on a separate hosting provider, a separate backup service, and increasingly, a third-party AI tool for document summarization or scheduling automation. Each of those relationships extends the attack surface, and the organization that filled out the original questionnaire usually has no visibility into any of them.

This is the fourth-party risk problem, and it is where a lot of real-world incidents originate. A vendor can be entirely honest and diligent about its own security posture while still depending on a subcontractor with weaker practices. Associations whose members share client data, financial records, or protected health information with outside platforms are exposed to this layer whether they know it or not.

Response Time Matters More Than the Presence of a Plan

Nearly every questionnaire asks whether a vendor has an incident response plan. Almost none ask how quickly that vendor is contractually required to notify a client after discovering a breach, or what the vendor’s actual remediation history looks like. A plan that exists on paper but takes a vendor 30 days to activate provides very little practical protection. Verizon’s research also flagged that the median time to remediate a leaked credential found in a public code repository was 94 days in the incidents it reviewed, a gap wide enough for significant damage to occur before anyone even knows there is a problem.

For member organizations that handle sensitive client information, that distance between “we have a plan” and “we notified you within 24 hours” is the difference between a contained incident and a public one.

AI Tools Are Quietly Becoming Vendors Too

Many organizations have adopted AI-powered features inside tools they already use, from email assistants to document generation, without treating that functionality as a new vendor relationship. It often is one. Data may be processed by a separate AI provider, stored in a separate environment, or used to train models in ways the original vendor questionnaire never anticipated because it predates the feature entirely.

EasyIT’s AI security consulting work, including its Microsoft AI Readiness Audits, has been built around this exact blind spot: identifying where data is flowing into AI tools that were never formally evaluated, and where access permissions inside platforms like Microsoft 365 have quietly expanded beyond what the original vendor agreement covered.

What a Better Set of Questions Looks Like

Associations advising their members on vendor selection, and the members themselves, are better served by questions that go beyond certification status:

  • What is the vendor’s contractual notification window after discovering a breach, in hours, not days
  • Who are the vendor’s own critical subcontractors, and has the vendor disclosed them
  • When was the vendor’s incident response plan last tested, and what did that test find
  • Does the vendor use AI features that process client data, and where is that data stored
  • What access does the vendor actually have to systems and data, and is that access scoped to what the relationship requires
  • What happens contractually if the vendor is breached and the member organization’s data is exposed as a result

None of these questions require specialized tooling to ask. They require a shift in what the questionnaire is trying to find out. A checklist confirms compliance. These questions confirm what happens under real conditions.

Vendor Risk Is an Ongoing Relationship, Not a Onetime Form

The organizations that manage vendor risk well tend to treat it the way they treat any other operational risk: reviewed regularly, updated as vendor relationships change, and tied to actual consequences rather than a signature on a form. That shift matters most for organizations that don’t have a dedicated security team reviewing these relationships year-round, which describes most small and mid-sized businesses in professional services, healthcare, and nonprofit work.

For associations supporting members through this shift, the goal isn’t to hand out a longer form. It’s to help members ask questions that reveal how a vendor actually behaves when something goes wrong, not just what it claims on paper. EasyIT works with organizations across Columbus on exactly this kind of vendor and data access review as part of its broader cybersecurity and AI governance services, and is glad to be a resource for association members working through what their current vendor evaluation process is and isn’t catching.

How Much Should Your Organization Pay For IT Support Services in Columbus?

How Much Should Your Organization Pay For IT Support Services in Columbus?

Many of our competitors will never reveal how much you should pay to outsource your IT support?

Not with EasyIT.

Download Your Free Complimentary Managed IT Services Pricing Guide.

pa