Securing the Third-Party Vendor Supply Chain

You can outsource the work, but not the responsibility.

Law Firm Cybersecurity · Chapter 9~6 min read

Your firm can do everything right and still be breached through a company you've barely thought about. The document-management platform. The e-discovery vendor. The cloud backup service. The outsourced IT provider. The e-signature tool. Each one holds, touches, or can reach your client data — and each one's security is now part of yours.

Attackers know this. Compromising one vendor that serves fifty firms is far more efficient than attacking fifty firms individually. And there are signs they've noticed the legal sector specifically: security researchers have flagged clusters of law-firm victims appearing together in short windows — a pattern that points toward a shared upstream provider being breached rather than each firm being hit on its own.1

The firm's perimeter isn't the firm's perimeter anymore

The 2023 compromise of a widely used file-transfer tool cascaded into breaches at organizations that used it — law firms among them — none of whom were individually targeted; they were simply downstream of one vendor's flaw.2 That's the shape of supply-chain risk: your exposure includes every system your data passes through, whether you administer it or not.

Your vendor relationships are often more discoverable than you'd expect, which means the path through a vendor is something an attacker can plan for.

FIGURE 1 — WHO CAN REACH YOUR CLIENT DATA
Document management
E-discovery
Cloud backup
Outsourced IT
E-signature
Payment processor
Website host
Each holds, touches, or can reach client data. An attacker doesn't need the firm at the center — compromising any spoke can reach it, and a spoke that serves many firms reaches all of them. The firm's real attack surface is this whole diagram.

Why this is hard for firms

Vendor risk is uncomfortable because it feels out of your hands — and to a degree it is. But "out of our hands" has quietly become the reason a lot of firms do nothing: no inventory of who holds their data, no idea what those vendors' security looks like, no contract terms about breach notification, no plan for when a vendor is the one that gets hit. The MOVEit-style events land hardest on firms that didn't even have a list of which vendors touched what.

What actually fixes this

1. Inventory who touches your data. You cannot manage a supply chain you haven't listed. Start with the simple question: which outside companies hold, process, or can reach our client data? Most firms have never written this down.

2. Ask vendors the right questions. Do they encrypt at rest and in transit? Do they have MFA? Do they have an incident response plan? Will they notify you of a breach, and how fast? The firm should be able to pass the questions upstream.

3. Put breach notification in the contract. A vendor's obligation to tell you promptly when they're breached shouldn't be a hope. It should be a term.

4. Right-size access. A vendor should reach only the data it actually needs, for as long as it needs it — not standing access to everything.

5. Include vendors in your incident plan. When the breach is a vendor's, your response clock still starts. Know in advance who you'd call and what you'd need from them. (This connects directly to Chapter 13, where a vendor breach can trigger the firm's own notification duties.)

6. Reassess periodically. Vendors change, get acquired, and add subprocessors. A one-time check isn't a program.

Free vendor-inventory starter kit

A vendor-inventory worksheet and a short security-questionnaire template you can send — plus, if you'd like, a review of your web and hosting-side vendor exposure directly.

Your firm's vendor / supply-chain checklist

Spencer McLennan
Spencer McLennan is the founder and lead webmaster of LegalWebmasters, and has handled websites, hosting, and security for law firms and professional practices across the United States and Canada since 2007. He holds an MBA, a PCM from the American Marketing Association, and is a graduate student in intelligence studies. He writes the Law Firm Cybersecurity and Law Firm SEO & Design guides. Connect on LinkedIn.

Footnotes

  1. INC Ransom Group Mounts Rapid Campaign Against Law Firms, Halcyon (Mar. 11, 2026).
  2. The Top Cybersecurity Threats Law Firms Face, ArmorPoint (Dec. 11, 2025).

Trusted by professionals like you.

Crease Harman LLP Borders Law Group David Aujla, Immigration Lawyer