Securing the Third-Party Vendor Supply Chain
You can outsource the work, but not the responsibility.
Your firm can do everything right and still be breached through a company you've barely thought about. The document-management platform. The e-discovery vendor. The cloud backup service. The outsourced IT provider. The e-signature tool. Each one holds, touches, or can reach your client data — and each one's security is now part of yours.
Attackers know this. Compromising one vendor that serves fifty firms is far more efficient than attacking fifty firms individually. And there are signs they've noticed the legal sector specifically: security researchers have flagged clusters of law-firm victims appearing together in short windows — a pattern that points toward a shared upstream provider being breached rather than each firm being hit on its own.1
The firm's perimeter isn't the firm's perimeter anymore
The 2023 compromise of a widely used file-transfer tool cascaded into breaches at organizations that used it — law firms among them — none of whom were individually targeted; they were simply downstream of one vendor's flaw.2 That's the shape of supply-chain risk: your exposure includes every system your data passes through, whether you administer it or not.
Your vendor relationships are often more discoverable than you'd expect, which means the path through a vendor is something an attacker can plan for.
Why this is hard for firms
Vendor risk is uncomfortable because it feels out of your hands — and to a degree it is. But "out of our hands" has quietly become the reason a lot of firms do nothing: no inventory of who holds their data, no idea what those vendors' security looks like, no contract terms about breach notification, no plan for when a vendor is the one that gets hit. The MOVEit-style events land hardest on firms that didn't even have a list of which vendors touched what.
What actually fixes this
1. Inventory who touches your data. You cannot manage a supply chain you haven't listed. Start with the simple question: which outside companies hold, process, or can reach our client data? Most firms have never written this down.
2. Ask vendors the right questions. Do they encrypt at rest and in transit? Do they have MFA? Do they have an incident response plan? Will they notify you of a breach, and how fast? The firm should be able to pass the questions upstream.
3. Put breach notification in the contract. A vendor's obligation to tell you promptly when they're breached shouldn't be a hope. It should be a term.
4. Right-size access. A vendor should reach only the data it actually needs, for as long as it needs it — not standing access to everything.
5. Include vendors in your incident plan. When the breach is a vendor's, your response clock still starts. Know in advance who you'd call and what you'd need from them. (This connects directly to Chapter 13, where a vendor breach can trigger the firm's own notification duties.)
6. Reassess periodically. Vendors change, get acquired, and add subprocessors. A one-time check isn't a program.
A vendor-inventory worksheet and a short security-questionnaire template you can send — plus, if you'd like, a review of your web and hosting-side vendor exposure directly.
Your firm's vendor / supply-chain checklist
