Your IT firm has the keys to your business – administrative access to your servers, email, backups, and often your financial systems. If their tooling is compromised, that access becomes the attacker’s access. Yet most contract negotiations never address what happens when the IT vendor itself is the breach vector. No defined notification window. No remediation timeline. No meaningful accountability. These are the five questions you need answered before you sign anything.
- Why the Vendor Side of the Risk Equation Gets Ignored
- Question 1: If Your Tools Are Compromised, How Quickly Will You Tell Me?
- Question 2: What Platforms Do You Use to Access My Environment, and How Are They Secured?
- Question 3: If the Breach Originates in Your Infrastructure, Who Pays for My Remediation?
- Question 4: Has an Independent Third Party Ever Audited Your Own Security Controls?
- Question 5: What Rights Do I Have Under the Contract If You Are the Source of an Incident?
- Red Flags to Watch For in the Answers
- What Good Actually Looks Like
- How to Use These Answers to Make Your Decision
Why IT Vendor Security Incidents Get Ignored in the Risk Equation
There is a well-documented pattern in major cybersecurity incidents over the past decade: the attacker does not break into the target directly. They break into a vendor the target trusts, then use that trusted relationship as a bridge. The SolarWinds incident – where malicious code was introduced into a software update that thousands of organizations then installed – is the most cited example. The Kaseya incident followed the same logic, hitting IT service providers directly through their own management platforms and cascading outward to their clients.
These are not isolated anomalies. CISA has documented supply chain compromise as a primary attack vector and has issued repeated guidance urging organizations to vet not just their own controls but the controls of every vendor with privileged access to their systems. Most business owners never see that guidance. Most IT vendor sales conversations do not bring it up voluntarily.
When you hand an IT firm administrative access to your environment, you are extending your attack surface into theirs. The question is not whether IT vendor security incidents are theoretically possible. The question is what the firm you are evaluating has done to reduce that risk – and what they will do if the worst happens.
Question 1: If Your Tools Are Compromised, How Quickly Will You Tell Me?

This is the most basic question about IT vendor security incidents, and the most frequently dodged. You need a specific, contractually backed answer – not a general reassurance that they “take security seriously” or “communicate proactively with clients.”
Push for actual numbers. Is there a defined maximum window between confirming an incident in their own infrastructure and sending you written notification? Twenty-four hours is a reasonable baseline. Seventy-two hours is the outside edge. No commitment at all is a red flag you cannot overlook.
Also ask what triggers notification. Does it require confirmation that your environment was specifically affected? Or does the firm notify you any time their own tooling is involved in a credible incident, even before client impact is fully assessed? Firms with mature security programs notify proactively and investigate alongside that notification. Firms with immature programs wait until they are certain before saying anything – which can mean days of unnecessary exposure on your end.
Question 2: What Platforms Do You Use to Access My Environment, and How Are They Secured?
This question will tell you more about a firm’s maturity than almost any other. A provider who cannot name the platforms they use to remotely manage your systems, monitor your network, or store your credentials has not thought carefully about their own attack surface. That alone should give you pause.
What you are listening for is specificity. You do not need to understand every technical detail, but the firm should be able to explain, in plain language, how they secure the tools that have access to your environment. Relevant topics include:
- Whether access credentials for client environments are stored in an encrypted, access-controlled credential vault
- Whether multi-factor authentication is required for every technician who can touch your systems remotely
- Whether privileged access is granted only when needed and logged at every step – not left open by default
- Whether their internal platforms receive regular patching and vulnerability scanning
If the answers feel vague, or the person across the table seems caught off guard, that tells you something. This should not be a surprise question to any IT firm worth hiring. Tooling transparency is a baseline expectation, not an advanced ask.
Question 3: If the Breach Originates in Your Infrastructure, Who Pays for My Remediation?
This is where conversations about IT vendor security incidents get uncomfortable fast – which is exactly why you need to have it before the contract is signed, not after an incident has already occurred. Read the master services agreement carefully, and have a lawyer review it if the language is dense. What you are looking for is whether the contract explicitly addresses vendor-side incidents, or whether it only contemplates breach scenarios that originate within your own environment.
Many standard IT service agreements are written to protect the vendor. Liability caps, indemnification clauses, and force majeure language can all be used to argue that the vendor bears no financial responsibility for remediation costs, legal notification expenses, or downtime losses – even if their tooling was the direct cause. That may not be intentionally deceptive, but it is a risk you are accepting without realizing it if you sign without asking.
A firm that has genuinely thought about this will have a clear answer. They may carry professional liability or cyber liability insurance that covers client-side impacts of a vendor-side incident. They may have a defined remediation protocol. Even if they cannot offer unlimited coverage, they should be able to describe what they have put in place to make you whole.
Question 4: Has an Independent Third Party Ever Audited Your Own Security Controls?
Asking a firm whether they are secure is like asking a contractor whether their own work is good. The only answer that matters is what an independent expert found when they looked. Push for documentation of external audits, certifications, or formal security assessments of the firm’s own internal controls – not their clients’ controls, but theirs.
Frameworks like the NIST Cybersecurity Framework or the CIS Critical Security Controls provide structured benchmarks that a qualified external assessor can evaluate a firm against. If the firm holds a recognized security certification or Trustmark that requires annual third-party validation, that is meaningful evidence. An internal review conducted by their own team is not the same thing.
For context: Xact IT has carried the GTIA Cybersecurity Trustmark since 2021, audited annually by Versprite – a CREST-accredited assessor – against the CIS Critical Security Controls at Implementation Group 2 with supplementary ISO 27001 controls. That is the kind of external accountability you should expect from any firm managing your critical systems. Not every firm will hold a Trustmark specifically, but every firm should be able to point to something external and verifiable.
Question 5: What Rights Do I Have Under the Contract If You Are the Source of an Incident?
This question moves the conversation about IT vendor security incidents from hypothetical to contractual. Specifically, you want to know whether the agreement gives you the right to:
- Terminate the relationship without penalty if the vendor’s infrastructure is confirmed as the breach vector
- Request a full incident report – including root cause analysis and a timeline of events – at no additional cost
- Conduct or commission an independent forensic investigation of your own environment following a vendor-side incident
- Receive written confirmation of the remediation steps the vendor took in their own infrastructure after the incident
These are not adversarial asks. A vendor with nothing to hide will have no objection to any of them. The ones who push back – who want to charge for incident documentation, or who resist giving you termination rights in this specific scenario – are telling you something important about how they view the relationship.
Red Flags to Watch For in the Answers
Even when a firm answers every question about IT vendor security incidents, the quality of the answer matters as much as the fact that they gave one. Watch for these patterns:
- Vague reassurances without specifics: “We have strong security” is not an answer to any of these questions
- Shifting the conversation back to your security posture instead of theirs – deflection is a tell
- An inability to name the platforms they use to manage client environments
- Contract language that caps all liability at a single month’s service fees, regardless of the nature of the incident
- No professional liability or cyber liability insurance – or a policy that explicitly excludes vendor-side incidents
- Annoyance or defensiveness at being asked these questions at all
What Good Actually Looks Like
A firm that has built a real security program will welcome these questions. They will have clear answers – often already documented – because they have thought through exactly these scenarios. They will carry appropriate insurance. They will have a written incident response plan that covers their own infrastructure, not just client environments. And that plan will have been reviewed by someone external.
The firms that do this well tend to be the ones that have been at it long enough to have watched what happens when it goes wrong somewhere else. They are not scrambling to build a policy in response to your question. The policy already exists. They are calm about it because they are prepared.
For more on how a well-structured IT and cybersecurity program protects your business from multiple angles, see our overview of cybersecurity services. You may also find it useful to review our managed IT services page for details on how we structure access controls and accountability in every client engagement.
Quiet environments do not happen by accident. They happen because the firm managing them holds their own infrastructure to the same standard they apply to yours.
How to Use These Answers to Make Your Decision
You are not looking for perfection. No firm can guarantee a zero-incident future for themselves any more than they can for you. What you are evaluating is preparation, transparency, and accountability. Does the firm know their own risk surface? Have they done the work to reduce it? Do they have a plan for when something goes wrong? Will they tell you fast, and will they make you whole?
The businesses that get hurt worst by IT vendor security incidents are not always the ones whose vendors had the weakest security. They are often the ones who never asked. They signed the agreement, assumed the firm had everything under control, and found out otherwise only when the damage was already done.
These five questions will not guarantee you never face an IT vendor security incident. But they will tell you – before you are locked into a multi-year agreement – whether the firm sitting across the table has earned the level of access you are about to give them.
If you want to pressure-test how we answer these questions, we are ready for it. Book a Free Cybersecurity Strategy Call and ask us anything on this list.
Want a Walkthrough of Your Own Setup?
Twenty minutes on the phone with our team gets you specific recommendations you can use immediately — whether you hire us or not. No pitch, no pressure, just an honest read on where your business stands.