News

Data and Confidential Information Security Protections: Are Your Vendor Security Requirements Adequately Protecting Your Business’s Information?

August 5, 2026

Today, nearly all information is stored in the cloud, on servers, or across other digital platforms. As a result, data security has become a fundamental priority for businesses. Many companies have implemented a range of security programs, policies, and procedures, including multi-factor authentication, firewalls, encryption, and more. Unfortunately, despite a company’s diligent efforts regarding its own practices, businesses cannot rely solely on their internal policies when ensuring the protection of their data.

It is common for businesses to share company data with third-party vendors that have been hired to perform certain services for or on behalf of the business. When that information is shared with third-party vendors it is no longer under a company’s internal protection. The disclosed data may not be subject to any confidentiality obligations if not previously established between the parties.

In addition to maintaining and monitoring its internal policies, it is important and necessary for businesses to also have procedures in place for their vendors when ensuring that the company’s shared data is protected. Below is a high-level overview of key considerations that business owners and their privacy officers should keep in mind when evaluating the company’s security protocols with vendors.

1. Due Diligence Prior to Engagement

When considering engaging a third-party vendor, the best practice is always going to be doing your own due diligence first before agreeing to the terms of the engagement and or signing a contract. By doing this, it allows you to conduct an initial assessment of the vendor’s security policies and privacy measures. This can be accomplished in several ways, but it is customary to request copies of written policies regarding data storage, employee training on security measures, and breach response procedures, as well as to inquire whether the vendor has a history of security incidents. By conducting due diligence on your prospective vendors prior to engagement, you can gain confidence in sharing your business information and potentially prevent breaches of your data that might otherwise have arisen due to contracting with a vendor with inadequate, or non-existent, data security protocols.

2. Mandatory Security Requirements

An increasingly common practice amongst companies is mandating that third-party vendors have in place certain security requirements as determined by the company, to be maintained by the vendor while performing the contracted services. These would normally be outlined in a non-disclosure agreement, service agreement, or similar agreement related to the engagement.

Whether your business has a standard vendor agreement or receives a draft agreement from a prospective vendor, it is important to confirm that the agreement includes a list of mandated security requirements for your vendors. This is necessary to ensure that your security expectations are enforceable throughout the course of the engagement.

3. Requiring Regular Risk Assessments

Companies frequently perform internal risk assessments, but if you are sharing information with your vendors, you should also regularly conduct vendor risk assessments to assess those vendors’ security policies, procedures, and safeguards. Similarly to conducting an internal assessment, a vendor risk assessment is intended to identify, validate, and potentially mitigate any risks where through the vendor’s practices, your company’s system and information could be vulnerable to unauthorized access and prone to security risks.

4. Third-Party Audits

Another option that provides a more hands-off approach than the above is requiring your vendors to hire an independent third-party to conduct an in-depth audit of the vendor’s security systems, such as a SOC 2 audit. Following the independent auditor’s review, the vendor shall then be required to provide a copy of the auditor’s final report to you for your review. The parties should also address responsibility for costs associated with conducting the audit, as well as any corrective actions or mitigation measures the vendor must implement following completion of the audit.

5. Mitigation Obligations

For both risk assessments and third-party audits, the agreement may allow negotiation of certain terms, including the frequency, the specific types of assessments or audits, and the individuals or organizations authorized to perform them. However, one essential term that should be used whether requiring a risk assessment or third-party audit is language that obligates the vendor to address and mitigate any security risks identified in the final reports. A vendor agreement must specifically include this obligation or otherwise a final report will provide evidence of the flaws in a vendor’s security measures but will not require that the vendor take all action necessary to correct them.

6. Notice of Breach & Response Protocols

In addition to requiring that your vendors maintain certain security measures, it is also imperative to establish and enforce certain response protocols compelling the vendor to provide prompt notice in the event of an actual or potential security breach. Notice requirements can be implemented in a variety of ways. However, with just having enforceable policies in place, you can reasonably expect vendors to notify you as quickly as possible of any breaches to their systems. The sooner you receive such notice, the more promptly you can assess the status of your own systems and take action to mitigate any issues arising from the vendor’s breach.

If you would like to further discuss any of the information above, or would like to discuss implementing a new vendor agreement and data security policies for your company’s vendors, please reach out to Stephen S. Schmidt at ssschmidt@strausstroy.com or Tara K. Bailey at tkbailey@strausstroy.com.