IT vendor security incidents are not hypothetical – they are a documented, growing category of supply chain risk that every business leader must understand before signing a managed IT contract. Most executives spend considerable time evaluating whether an IT vendor can protect their business. Fewer stop to ask the more uncomfortable question: what happens if the vendor itself gets hit? The company you trust to manage your systems, your backups, and your employees’ devices is also a door into your environment. If that door gets kicked in on their side, you need to know exactly what happens next – and you need to know before you sign anything.
- Why Your IT Vendor’s Own Security Posture Is Your Problem
- Question 1: How Quickly Will You Tell Me If You Are Breached?
- Question 2: What Are Your Contractual Obligations to Me During an Incident?
- Question 3: Does Your Cyber Liability Policy Cover Downstream Client Impact?
- Question 4: Can I See Your Incident Response Plan?
- Red Flags That Should End the Conversation
- What a Trustworthy Answer Actually Looks Like
- How to Weigh This When Making Your Decision
Why IT Vendor Security Incidents Are Your Problem Too
When you hire a managed IT firm, you are not just buying services. You are extending implicit trust. That vendor gets administrative access to your systems, your data, and often your employees’ email and devices. In security, that kind of access is called a privileged relationship – and it is exactly what attackers look for when they target supply chains.
The 2020 SolarWinds attack was the headline example of IT vendor security incidents cascading downstream, but it was not an isolated event. Attackers have learned that compromising one trusted vendor can give them access to dozens or hundreds of downstream clients at once. Managed IT providers are a high-value target for precisely this reason. The Cybersecurity and Infrastructure Security Agency (CISA) has published detailed guidance on managed service provider risks, and the message is clear: the vendor’s security posture is part of your security posture.
This is not about distrust. It is about due diligence. A vendor confident in their own security controls will welcome these questions. One who deflects or gets defensive is telling you something important.
Question 1: How Quickly Will You Tell Me If You Are Breached?

This is the most time-sensitive question on the list – and the answer reveals how seriously a vendor treats their obligations to you.
Ask for a specific number. Not “promptly.” Not “as soon as possible.” Ask: within how many hours of detecting a breach affecting your internal systems will you notify me? The answer should be a hard number, written into the contract.
Here is why the breach notification timeline matters. If an attacker compromises your vendor’s systems and gains access to tools that touch your environment, every hour without notification is an hour that attacker may be moving through your network. A 24-hour notification window is concerning. A 72-hour window – which some vendors cite as an industry norm – can be catastrophic for a small or mid-size business.
You need time to act: isolate systems, alert your own cyber liability insurer, notify your legal counsel, and in some cases, notify your own clients or regulators. IT vendor security incidents that go unreported for days hand attackers a critical head start.
Follow-up questions worth asking in this same conversation:
- Who specifically will contact me – a named person or a generic support queue?
- Will I receive notification even if the vendor is still assessing whether my environment was affected?
- Is this notification obligation written into my service agreement, or is it only a verbal commitment?
Vendors who have thought seriously about incident response will have clean answers to all three. Vendors who have not will hedge.
Question 2: What Are Your Contractual Obligations to Me During an Incident?
Notification is only the first obligation. Once you know there is a problem, you need to understand what the vendor is required to do – and what they are not.
Many IT service agreements are written to protect the vendor, not the client. They include limitation-of-liability clauses that cap the vendor’s financial exposure at one month’s fees, or exclude liability for “events beyond our reasonable control” – a category some vendors have tried to apply to their own security failures. Read the contract. If you do not have a lawyer who understands technology contracts, find one before you sign.
Specific things to look for and ask about:
- Is the vendor obligated to provide dedicated incident response support to your business – not just their own recovery – during an event affecting their systems?
- Do they commit to preserving forensic evidence so your own legal team or insurer can conduct an independent investigation?
- Are they required to cooperate with your cyber liability insurer’s investigation, including providing logs and access records?
- If a regulator contacts you because of a breach that originated with your vendor, does the vendor have any obligation to support your response?
If a vendor’s breach triggers your own regulatory reporting obligations – say, under HIPAA because they touched systems containing protected health information – the clock starts on you, not on them. You need to know whether they are a partner in that process or a bystander. Our managed IT services page outlines how we structure these obligations in plain language before any agreement is signed.
Question 3: Does Your Cyber Liability Policy Cover Downstream Client Impact?
This is the question most vendors are least prepared for, and it is arguably the most financially consequential one on the list.
A managed IT firm should carry cyber liability insurance. Most do. But not all cyber liability policies are equal. The critical distinction is whether the policy covers third-party or downstream losses – meaning losses suffered by the vendor’s clients as a result of IT vendor security incidents – or whether it covers only the vendor’s own first-party losses: their remediation costs, their legal fees, their business interruption.
Ask directly: does your cyber liability policy include coverage for client losses that result from a breach of your internal systems? Then ask for the coverage limits and whether the vendor also carries errors and omissions coverage as a separate layer. Errors and omissions insurance – sometimes called professional liability – is the policy most likely to respond to a claim that the vendor’s negligence caused your business harm.
You are not being unreasonable. You are asking whether there is a financial backstop if the worst happens. A vendor who cannot answer this question, or who says “you would need to talk to our insurance broker,” has almost certainly never thought about it from your perspective.
One more thing to ask: what are the sub-limits? A policy with a $2 million aggregate limit may carry a $250,000 sub-limit for third-party claims. That gap matters if your losses exceed it.
Question 4: Can I See Your Incident Response Plan?
An incident response plan is a documented, tested procedure that defines exactly what a company does when a security incident occurs – who is responsible, what steps are taken in what order, how communications are handled, and how recovery is prioritized.
Every serious IT vendor has one. The question is whether it is real or ceremonial.
A real incident response plan is specific. It names roles. It includes decision trees. It has been tested through tabletop exercises – structured walkthroughs where the team simulates an incident and works through the plan step by step. Ask when they last ran one. Ask what scenario they tested. Ask what they changed as a result. The NIST Cybersecurity Framework provides a widely recognized standard for incident response planning that credible vendors will know well.
A ceremonial incident response plan is a PDF in a drawer, written three years ago and untouched since. It covers the vendor’s recovery, not yours. It has never been tested. The person you are speaking with has never read it.
You do not need to read the entire document – though you can request it. What you are really testing is whether the person across from you can talk about it confidently from memory. If they can, it is real. If they have to go look it up, treat that as a signal.
Red Flags That Should End the Conversation
Some answers to these questions are not just weak – they are disqualifying. Here are the responses that should give you serious pause when evaluating a vendor’s readiness for IT vendor security incidents:
- “We have never had a breach, so this has never come up.” This conflates past performance with preparedness. Even the most secure firms plan for incidents – because planning is what keeps a close call from becoming a catastrophe.
- “Our contract limits our liability to one month of fees.” This is a legal exposure question, not a breach question. It tells you the vendor structured their agreements to protect themselves, not you. It is not automatically disqualifying, but it must be weighed against strong insurance coverage and explicit contractual notification obligations.
- “We are SOC 2 certified.” First, clarify whether they have an actual SOC 2 report – an audit of their controls – or simply claim to follow SOC 2 principles. Second, understand that SOC 2 covers a set of trust service criteria; it does not automatically mean their incident response plan meets your requirements or that their insurance covers your losses.
- “We use enterprise-grade security tools.” That is not an answer. Ask what specific controls govern access to client environments, how those controls are audited, and by whom.
- Defensiveness or irritation at the questions themselves. A vendor who treats these questions as an insult has not built a culture of accountability.
What a Trustworthy Answer Actually Looks Like
You are not looking for perfection. You are looking for transparency, preparation, and accountability.
A vendor who handles IT vendor security incidents questions well will give you specific numbers for notification timelines and commit to them in writing. They will walk you through their incident response plan without hesitation. They will know their insurance coverage – including third-party liability limits – and provide a certificate of insurance on request. They will have a named contact responsible for client communications during an incident, and that contact will not be a generic support queue.
They will also be honest about what they cannot guarantee. No vendor can promise they will never be attacked. The honest ones say so upfront, then explain exactly what happens if they are. That honesty is the point – it is the difference between a vendor who has genuinely thought through their obligations to you and one who hopes this conversation never comes up.
At Xact IT Solutions, we hold the GTIA Cybersecurity Trustmark – audited annually by Versprite, a CREST-accredited assessor, against CIS Critical Security Controls and supplementary ISO 27001 controls. That audit covers our own internal security posture, not just the advice we give clients. We have maintained zero client breaches since our founding in 2004. We are prepared to answer every question on this list, in writing, before you sign anything. You can learn more about our approach on our cybersecurity services page.
How to Weigh This When Making Your Decision
These four questions are not a checklist that produces a score. They are a conversation – and the quality of that conversation tells you as much as the content of the answers.
A vendor who takes IT vendor security incidents seriously is a vendor who takes their relationship with you seriously. They understand you are not just buying uptime and helpdesk tickets. You are extending trust, and they are accountable for it. That is a fundamentally different kind of vendor than one who sees the contract as a liability shield and the relationship as transactional.
The best IT vendors operate the way the best law firms and accounting firms do: quietly, carefully, with long-term relationships built on accountability and discretion. They are not trying to impress you with technical jargon. They earn trust by showing you – specifically and concretely – that they have thought through what happens when things go wrong. Because they have, and they are ready.
That is the standard worth holding every vendor to. It is also what separates firms that prevent the chaos from firms that become part of it. If you want to talk through where your current setup stands, Book a Free Strategy Call with our team – it is a 20-minute conversation, no obligation.
Want a Walkthrough of Your Own Setup?
Twenty minutes on the phone with our team gets you specific recommendations you can use immediately — whether you hire us or not. No pitch, no pressure, just an honest read on where your business stands.