Magenta light passing through stacked dark panels, vendor contract security obligations flowing down a supply chain
Vendor Evaluation • 7 min read

Vendor Contract Security Obligations and Flow-Down

The Kaseya VSA incident reached roughly 1,500 businesses through 50 to 60 providers, none of whom used the compromised product directly. Vendor contract security obligations are how requirements reach that far.

Vendor contract security obligations are the mechanism that turns your security requirements into someone else's legal duty. Without them, a vendor's security page is marketing and your regulator, your insurer, and your customers are still looking at you. The flow-down is the whole point: obligations you carry should reach every party that touches your data.

I am Amelia S. Gagne, CEO of Kief Studio. This page is about the clauses. The questions you ask before you get there are in what to ask your vendors about security, and the exit side is technology vendor contract exit terms.

Magenta light passing through stacked dark panels, vendor contract security obligations flowing down a supply chain
Obligations that stop at the first vendor do not stop where your data does.

Why do vendor contract security obligations need to be written down?

Because the alternative is an expectation, and expectations are not enforceable.

The joint advisory AA22-131A, issued May 11, 2022 by CISA, the NSA, the FBI, and cyber authorities in the UK, Australia, Canada, and New Zealand, makes the point directly: customers should ensure their contractual arrangements specify that their provider implements the recommended baseline measures and controls. Not that the provider should implement them. That the contract should say so.

That framing is useful because it separates two things buyers conflate. Whether a vendor is competent is a diligence question. Whether you can require, verify, and enforce specific behavior is a contract question. A competent vendor with a thin contract still leaves you without recourse.

Which clauses carry the most weight?

Named controls rather than reasonable measures. "Industry standard security" is unenforceable because there is no agreed standard to point at. Name the controls that matter for your risk: multi-factor authentication on administrative and remote access, encryption in transit and at rest, logging with a stated retention period, and least privilege on accounts that reach your environment.

Breach notification with a clock. Promptly is not a clock. Name the hours, name who is called, and name whether the vendor or you notify affected parties. Your own notification deadlines run from discovery, so a vendor who takes two weeks to tell you has consumed your window.

Sub-processor flow-down. The clause that requires your vendor to bind its own vendors to equivalent terms, plus notice before adding new ones and a right to object. Without it, your requirements stop one layer down while your data keeps going. That is the sub-processor problem in a sentence.

Evidence rights. A right to the current third-party audit report annually is more useful to most buyers than a right to send an auditor, because almost nobody sends an auditor. Ask for the report including its exceptions section, which is the part that carries information.

Incident cooperation. Log access, preservation obligations, and forensic support during an investigation. A vendor that holds the logs holds the narrative, and investigations stall on log access more often than on anything technical.

A liability cap that does not erase the security clause. A cap set at three months of fees means the security obligations are decorative. Carve-outs for breach of data protection obligations are the standard ask.

Magenta-lit fiber optic strands passing through stacked dark panels, the clauses carrying vendor contract security obligations down a chain
Named controls, a notification clock, sub-processor flow-down, evidence rights, incident cooperation, and a liability carve-out.

Why does the flow-down matter more than it used to?

Because the shared-tooling model concentrates risk in a way single-vendor thinking misses.

The Kaseya VSA incident in July 2021 is the clearest case. Attackers exploited vulnerabilities in the VSA remote monitoring product, and roughly 1,500 downstream businesses were affected through approximately 50 to 60 managed service providers. CISA and the FBI addressed it in joint guidance on July 4, 2021.

None of those 1,500 businesses had a relationship with the compromised product. They had a relationship with a provider that used it. The payload arrived through a trusted, authenticated channel rather than a phishing lure, which is what makes this class of exposure different from the one most security awareness training describes. The wider pattern is what supply chain attacks actually are and why it is now a people problem.

A flow-down clause would not have prevented Kaseya. What it would have produced is a named tooling inventory, a notification obligation that ran on a clock, and a contractual basis for demanding cooperation. Those are the things that shorten the response.

How does this connect to your insurance?

Directly, and in both directions.

Your cyber policy asks about third parties, so your vendor register is an underwriting artifact as well as an operational one. That is part of what a renewal application asks.

Going the other way, a vendor's insurance is part of what you are relying on. Ask what they carry, at what limit, and whether it covers losses caused by their own personnel, since cyber liability and fidelity coverage are different products and internal-actor losses are often excluded. A vendor with a $1 million limit serving four hundred clients has a limit that is per-vendor, not per-client.

Where your own coverage responds to a provider outage, the line is dependent business interruption, and it is usually narrower than the first-party equivalent. That is covered in cyber insurance exclusions that decide claims.

A magenta-lit index of dark entries on black, the vendor register behind contract security obligations
The vendor register serves diligence, contracting, and underwriting. Most organizations maintain it three times or not at all.

What if the vendor will not negotiate?

Sometimes that is real. Hyperscale infrastructure providers do not amend their terms for a mid-market buyer, and pretending otherwise wastes a quarter.

The practical response is proportionality. Spend negotiating effort where the vendor is negotiable and the data is sensitive. For non-negotiable providers, the compensating controls are architectural: limit what you put there, encrypt what you control, keep your own backup, and know the exit cost. That is the same reasoning as the cheapest way to protect data is to not keep it.

Where a smaller vendor refuses reasonable terms, the refusal itself is diligence output. Record it, price it, and let it inform how much of the operation sits behind that dependency. A documented refusal is a better file than an unasked question.

Five magenta marks on a single dark page, the minimum vendor contract security obligations worth asking for
Five asks fit on one page and can travel as a rider. Most mid-sized providers have seen them before.

A workable minimum

For a small or mid-sized buyer without legal staff, five asks cover most of the value: named controls, a notification clock in hours, sub-processor flow-down with notice, annual delivery of the current audit report, and a liability carve-out for data protection breaches.

Those five fit on a page and can be sent to a vendor as a rider. Most mid-sized providers will accept some version of all five, because they have been asked before. The buyers who get better terms are usually the ones who asked, which is the unremarkable finding underneath most of partner vetting questions founders skip.

Brian Gagne handles security architecture at Kief Studio and has for the fourteen years we have worked together. For control design rather than contract language, briansgagne.com goes deeper. kief.dev publishes Vekt, a lockfile scanner, because dependency files are where a lot of unexamined third-party risk sits, and the longer version is your lockfile is a threat surface.

Related reading

Frequently Asked Questions

What security obligations should a vendor contract include?

Named controls rather than "reasonable measures", breach notification stated in hours, sub-processor flow-down with notice and a right to object, annual delivery of the current third-party audit report, incident cooperation including log access, and a liability carve-out so the cap does not nullify the security clause.

What does CISA say about vendor contracts?

Joint advisory AA22-131A, issued May 11, 2022 with the NSA, FBI, and partner authorities in four other countries, recommends that customers ensure their contractual arrangements specify that their provider implements the advisory's baseline security measures and operational controls.

What is sub-processor flow-down?

A clause requiring your vendor to bind its own vendors to equivalent security terms, notify you before adding new ones, and give you a right to object. Without it, your requirements stop one layer down while your data continues through the chain.

What if a vendor refuses to change its contract?

Large infrastructure providers generally will not amend standard terms, so respond architecturally: limit what you store there, hold your own encryption keys and backups where possible, and know the exit cost. For smaller vendors, a refusal is diligence output worth recording and pricing.

Should I ask about a vendor's insurance?

Yes, including the limit and whether it covers losses caused by their own personnel, since cyber liability and fidelity are separate products. Remember the limit is per vendor, not per client, so a shared limit spread across hundreds of customers is thinner than it looks.

Cybersecurity Sep 15, 2026 • 7 min

Vendor Security Questions for Mixed Data Environments

Vendor security protocol questions for mixed data environments come down to who owns each control across your estate and theirs. CSA added Shared Security Responsibility Model columns to CAIQ v4 because unassigned controls are a leading source of cloud risk.

Operations Sep 13, 2026 • 8 min

Cybersecurity Questions for 401(k) Technology Vendors

Cybersecurity questions for 401(k) technology vendors start with the DOL's six hiring tips. Since Compliance Assistance Release 2024-01 they cover health and welfare plans too, and EBSA named cybersecurity a FY2026 national enforcement project.

Work With Us

Need help building this into your operations?

Kief Studio builds, protects, automates, and supports full-stack systems for businesses up to $50M ARR.

Newsletter

New writing, straight to your inbox.

Strategy, psychology, AI adoption, and the patterns that actually compound. No spam, easy to leave.

Subscribe