Supply Chain Attacks: Your Vendors Are Your Attack Surface

February 4, 2025 Updated August 15, 2026 By Vulcan365 Team

You can secure your own network well and still be compromised through a company you trusted. Attackers worked out that breaking into one vendor with access to hundreds of businesses is far more efficient than breaking into hundreds of businesses individually.

Why this became the dominant model

Small businesses now run on other people's software and other people's access. Your IT provider has administrative rights across your network. Your accounting platform holds your financial data. Your practice management or ERP vendor connects to your systems for support. Your backup provider can reach everything worth backing up.

Every one of those relationships is a path into your business that doesn't run through your firewall. And each vendor's own security posture is now, functionally, part of yours.

The uncomfortable part: an attacker who compromises a managed service provider inherits privileged access to every client that provider serves. It's the highest-leverage target there is, which is exactly why they're targeted.

The forms this takes

Compromised software updates. An attacker gets into a vendor's build process and ships malicious code inside a legitimate, correctly-signed update. You install it because it's a real update from a real vendor. Nothing you could reasonably have caught.

Compromised service provider access. Attackers breach an IT provider and use its remote management tooling — which is designed to push software silently to every managed machine — to deploy ransomware across all clients at once.

Vendor data breaches. Your data sits in a vendor's system; the vendor gets breached; your customer records are exposed. You did nothing wrong and you still own the notification obligation.

Compromised vendor email. The most common one for small businesses by far. A vendor's mailbox is compromised, and invoices start arriving with changed bank details — from the vendor's real address, referencing real work, in an existing thread. See phishing trends for why this is so effective.

What a small business can realistically do

You cannot audit your vendors' security the way a large enterprise does. You can do these five things, and they cover most of the practical risk.

1. Know who has access to what

Most businesses have never written this down. List every vendor with access to your systems or data, what specifically they can reach, and whether they still need it. You will find accounts belonging to companies you stopped working with years ago — that's the single most common finding, and closing them is free.

2. Limit what vendor access can do

Vendor accounts should follow the same least privilege rules as employees. Support access doesn't need permanent domain administrator rights. Where the vendor supports it, use time-bound access that's enabled when needed and expires automatically, and require MFA on their accounts too.

3. Ask your IT provider hard questions

Because they hold the most access, they warrant the most scrutiny. Reasonable questions any competent provider should answer without defensiveness:

  • Do your technicians use MFA on the tools that reach our systems?
  • Is your remote management platform segmented per client, or could one compromise reach every client?
  • What happens to our access when one of your staff leaves?
  • Do you carry cyber liability insurance, and what does it cover for us?
  • Have you been breached, and what changed afterward?

A provider that treats these as hostile is telling you something useful.

4. Make payment changes require a phone call

This one rule blocks the most common and most expensive version of supply chain attack. Any change to vendor bank details gets verified by voice, on a number you already had on file — never a number from the email requesting the change. No exceptions, including for long-standing vendors and including when the owner is asking.

5. Assume it will happen and plan the response

If your vendor is breached, what do you do? Know in advance how to revoke their access quickly, who decides, and what your notification obligations are if your data was involved. Your incident response plan should cover a vendor incident, not just your own.

The controls that help regardless of source

You can't prevent a vendor compromise, but the same fundamentals limit the damage no matter where an attack originates:

  • Backups isolated from your production network — if an attacker arrives through your management tooling, backups reachable from that tooling are gone too
  • Network segmentation, so a compromise in one area doesn't reach everything
  • EDR that watches behavior rather than trusting signed software — a legitimate update behaving like ransomware still gets flagged
  • Monitoring for unusual activity, especially administrative actions outside business hours

Common questions

Should we stop using an MSP because they're a target?

No — a good provider substantially improves your security overall. The point isn't to avoid the relationship, it's to understand that it's a trust relationship and to ask the questions that let you judge it. Providers who do this well have segmented tooling, MFA throughout, and answer directly when asked.

Isn't this a big-company problem?

It's the opposite. Large companies run formal vendor risk programs. Small businesses often have more vendors with deep access relative to their size, and almost no visibility into what those vendors can reach.

Where do we start with almost no time?

List who has access and close what's stale. Then write down the payment verification rule. Those two take an afternoon between them and cover the majority of realistic exposure.

Want to know who can reach your systems?

Vulcan365 works with businesses across Birmingham and Central Alabama to map vendor access, close what's no longer needed, and tighten what remains — and we're happy to answer the questions above about ourselves.

Request a vendor access review

The Hidden BYOD Risk

Staff expose company data on personal phones without realizing it.

The Domain Controller Backup Challenge

Why bare metal recovery often isn't an option, and what to do instead.

The Principle of Least Privilege

Why over-permissioned accounts turn small incidents into large ones.

Browse all articles · See our managed IT services