The real cost of vendor incidents
A vendor breach typically manifests in four ways. First, loss of access. If your vendor's platform goes down or is locked by an attacker, you cannot operate. You cannot process transactions, fulfill orders, or serve customers until they restore service. This creates hard-dollar downtime costs and can break customer commitments.
Second, data exposure. Vendors often hold sensitive customer information, financial records, or intellectual property. They may also hold credentials or API keys that grant access to your internal systems. When vendors are compromised, that data spills. You face notification costs, regulatory fines, and reputational damage.
Third, business interruption. Many vendors integrate deeply into your operations. Payment processors, communication platforms, and identity systems have no straightforward replacement. If a vendor goes down or is compromised, workarounds are expensive and incomplete.
Fourth, liability and contract disputes. When a vendor fails, customers may sue you, not the vendor. Your contracts with customers do not name the vendor as a party. You absorb the liability. Your vendor contract may disclaim responsibility or cap damages at a token amount, leaving you unprotected.
Supply chain attacks are not theoretical
SolarWinds was a watershed moment. In 2020, attackers compromised SolarWinds' Orion software update mechanism and delivered malware to roughly 18,000 organizations. Those organizations did not choose to trust the attacker. They trusted SolarWinds. The vendor trust became a supply chain weapon. The incident exposed Fortune 500 companies, government agencies, and critical infrastructure. No amount of internal security prevented it.
Kaseya faced a similar incident in July 2021. Attackers compromised Kaseya's remote management software, using it to distribute ransomware to over 1,500 managed service providers and their downstream customers. The attack rippled through MSPs to small and mid-size businesses. Victim organizations had no visibility into the supply chain when they wrote their security requirements.
MOVEit Transfer became a focal point in 2023 and 2024. Progress Software's file transfer application contained a critical vulnerability. Attackers exploited it to gain access to organizations using MOVEit for sensitive file exchange. Insurance companies, universities, government agencies, and healthcare providers were exposed. MOVEit is widely embedded in enterprise workflows, making replacement difficult.
These incidents share a pattern. Trusted vendors become attack vectors. Organizations had security policies in place. Those policies did not prevent the incidents because the breach originated outside the organization's direct control.
Smaller businesses face even higher risk. Enterprise organizations often have dedicated vendor security teams, contractual leverage, and audit rights. Small and mid-size companies typically do not. They may not ask security questions at all. A compromised vendor is often their first real incident.