How Much Do You Really Know About the Companies Holding Your Data?
Click here to view/listen to our blogcast.
Most businesses spend a lot of time thinking about their own cybersecurity. Firewalls, endpoint protection, multi-factor authentication, backups, email security and employee training all matter.
But what happens after you hand sensitive information to somebody else?
That question became very real in September when compliance technology provider RelyComply disclosed a cybersecurity incident affecting part of the environment where it processes customer data. RelyComply says the attacker exploited a previously unknown, or zero-day, vulnerability in a third-party application it used.
The bigger lesson is not that another technology company was breached, but that your organization can have excellent internal security and still be exposed because of a company you trusted with your data.
How Big Is Your Vendor Blast Radius?
Think about the outside companies your organization uses.
Your payroll company may have Social Security numbers and bank information. Your accounting platform contains financial records. Your backup provider may have copies of nearly everything. A CRM can contain years of customer correspondence. A compliance or identity-verification company may process identification documents and financial information.
Now ask a different question:
If this company were breached tomorrow, how badly could it hurt us?
This is what we classify as a vendor’s blast radius.
In the RelyComply incident, ransomware group Dire Wolf claimed it stole approximately 200 GB of data. That figure remains an attacker claim and should not be treated as independently confirmed. Standard Bank has, however, confirmed that some of its client data was present in the affected RelyComply environment while stating that its own banking systems were not compromised.
That’s an important distinction. Your business does not have to be directly hacked for your data to be exposed.
Your Vendor Has Vendors Too
There is another important detail in this incident. According to RelyComply, the attackers exploited a zero-day flaw in a third-party application used by RelyComply itself.
The chain may look like this: Your organization → your vendor → your vendor’s vendor → vulnerability → attacker
You might carefully evaluate the company you hired, but how much do you know about the companies they depend upon?
Modern cloud providers use hosting companies, payment processors, identity services, development tools, analytics platforms and other technology suppliers. Each relationship potentially expands the blast radius.
That doesn’t mean you should stop using cloud services. Modern businesses could hardly function without them. It means that vendor selection cannot end with, “They’re a big company, so I’m sure they’re secure.”
How Much Do You Actually Know?
For your important vendors, you should be able to answer some basic questions:
- What information are we giving them?
- Do they actually need all of it?
- Where is that information stored?
- How long do they keep it?
- Who can access it?
- Do their subcontractors receive our information?
- What systems can they access in our environment?
- Do they have API keys, service accounts or Microsoft 365 permissions?
- How quickly are they required to notify us of a breach?
- Can our information really be deleted when we stop using the service?
The level of investigation should match the risk. The company supplying printer toner probably doesn’t require the same scrutiny as the company storing patient records.
What You Can Do
Start with your most important vendors and ask three questions:
- What do they have?
Customer information, financial records, medical data, credentials, email, documents or backups? - What can they reach?
Microsoft 365, accounting systems, cloud storage, customer portals or internal applications? - What happens if they fail?
Can you continue operating? Could regulated information be exposed? Would customers need to be notified? Could an attacker use the vendor’s access to reach something else?
Then reduce the blast radius wherever possible. Remove old accounts and unused integrations. Restrict permissions. Stop sending vendors information they do not need.
Remember: data you never gave a vendor cannot be stolen from that vendor.
How CDML Can Help
Third-party risk is increasingly part of normal IT management.
CDML can help organizations inventory cloud services, review Microsoft 365 permissions and integrations, identify unnecessary access, document important technology vendors and evaluate what could happen if one of those providers were compromised.
The goal isn’t to eliminate vendors. It is to understand where your information is going and reduce how much damage one compromised provider could cause.
Final Thoughts
You probably know who protects your network. But do you know everyone who holds your data?
The RelyComply incident is another reminder that cybersecurity does not stop at your firewall. Your vendors, their vendors and the connections between them are all part of your risk.
If you are not sure which third parties have access to your organization’s sensitive information, contact CDML Computer Services. A vendor and cloud-access review may reveal more than you expect.
Stay safe. Stay informed. Stay compliant.

📞 Contact us here: https://cdml.com/contact/
📚 Read more on our blog: https://cdml.com/blog-2
📺 Listen to our blogcasts: https://www.youtube.com/@CDMLComputerServices


