VenDefend Third-Party Risk Management
Book A Demo
← All posts

What if your suppliers won't answer your risk assessments?

Imagine you have sent a security questionnaire to a supplier that handles part of your customer service. You have followed up twice and explained why the answers matter. Months later, the responses are still incomplete, or the supplier has politely declined to take part. Your business still relies on that supplier every day, and you have to decide what to do next.

Risk Management Guru·

Imagine you have sent a security questionnaire to a supplier that handles part of your customer service. You have followed up twice and explained why the answers matter. Months later, the responses are still incomplete, or the supplier has politely declined to take part. Your business still relies on that supplier every day, and you have to decide what to do next. Many organisations find themselves here. A supplier may be too small to complete a long questionnaire, or too large to share more than a standard summary. In either case, the question is how to manage the risk when the information you need does not arrive.

Supplier assessments are valuable. They help you understand how a supplier protects its systems and make informed decisions about the relationship. But your ability to protect your business should not stop when a supplier chooses not to participate.

The question should be, if this supplier had a serious problem tomorrow, what would happen to our business, and what can we do today to reduce the impact?

Not knowing is different from knowing there is a problem

When a supplier does not answer your questionnaire, you have not learned that its protections are weak. You have also not learned that they are strong. You have simply been left with uncertainty. There are two sensible responses. You can reduce the uncertainty where possible, and you can prepare the business for the consequences where it is not.

The second response is the focus of this article. It is a practical, tested ability to respond when a supplier has an incident, even when you hold limited information about that supplier. It works alongside sensible supplier due diligence and does not replace it. It also means you can strengthen your resilience now, without waiting for every supplier to complete a questionnaire.

How outside monitoring can help

One useful tool is third-party threat intelligence. In plain terms, this is a service that watches public and underground sources for warning signs about the companies you rely on. It might pick up a reported data breach, a criminal group claiming to have attacked a supplier, or staff passwords from a supplier that have been exposed online. This is especially useful for cyber incidents, where speed matters.

An early signal gives you time to act. You can contact the supplier sooner, review what access they have to your systems, think about what information you share with them and check whether your continuity arrangements are ready. A warning still needs checking before you act on it. Some claims turn out to be unconfirmed. Others describe an event from years ago, or concern a different company with a similar name. A warning is a good reason to investigate and to understand your exposure. It does not prove that your organisation has been harmed.

Where monitoring falls short

It is worth being clear about what this kind of monitoring cannot do. The first limit is coverage. A breach at a smaller or lesser-known supplier may never appear in the sources being watched. Coverage also varies between regions, languages and suppliers, and incidents that nobody has detected or disclosed remain hidden. Cost matters too, because broader coverage usually means a higher price. For this reason, a quiet report should not be read as good news. No alert does not mean no incident, and a clean report does not show that a supplier manages its risks well.

The second limit is scope. Most monitoring is designed to spot cyber incidents. Suppliers can let you down in many other ways. They can run into financial trouble, lose power for several days, struggle to keep key staff, suffer equipment failure or have their premises damaged. Some broader services may catch a few of these events, but you cannot assume they will catch all of them. Threat intelligence is best treated as one extra source of awareness. It sits alongside reports from the supplier and what your own people notice. The rest of your preparation matters just as much, because it prepares the business for the impact of a problem whatever the cause, and whether or not anyone outside spots it first.

Start by understanding where you depend on the supplier

The best place to begin is with your own business. Ask which of your services the supplier supports. Then ask which systems, processes and information depend on those services. What would stop working if the supplier became unavailable? Who else, further along the chain, would feel the effect?

This exercise is called dependency mapping. It links the supplier to everyday work in a way that people across the business can follow. A platform outage might first stop one team from reaching its information. Soon after, customer transactions may be delayed, a backlog may build and other departments may come under pressure. Seeing these connections helps you decide where preparation will make the biggest difference.

Talk through a realistic scenario

Once you understand the dependencies, bring the right people into the same room to work through a believable situation. Picture a critical supplier hit by ransomware, which is a type of attack that locks an organisation out of its own systems. The service is down. The supplier cannot say when it will be restored. It has not yet confirmed whether your information was affected.

This kind of guided conversation is often called a tabletop exercise, and nothing needs to be switched off or disrupted. Business owners, operations, IT and management talk through what they would do. Which activities must continue? How long can the business cope with the disruption? Who has the authority to approve a workaround? What information would you need and from whom? What changes if the outage lasts five days instead of five hours?

These discussions often reveal assumptions that nobody had questioned. A team may believe it can switch to manual work, then realise that its instructions and customer records are stored on the very platform that is down. An alternative supplier may exist, but it could take weeks to bring into service. Each finding should lead to a clear decision or action.

You might keep an independent copy of essential information, limit what the supplier can access, arrange an alternative or clarify who is responsible for what. When a gap cannot be closed, you record it so that management can decide how to deal with it.

Turn what you learn into a plan, and then test it

A business continuity plan takes these decisions and turns them into clear instructions. A good plan explains when to act, who is responsible, what resources are needed and how essential work will carry on. It should also be linked to the dependencies and risks it covers, so that anyone responding can find the right guidance quickly.

A plan on paper is only a starting point, because it still has to be tested. Can the manual process cope with the number of transactions you handle? Can the information you need actually be retrieved? Can an alternative service be switched on within the time the business can afford? A discussion helps people understand their roles, while a practical test shows what the arrangement can really deliver. Testing works best when it is organised. A structured approach lets you schedule tests, record the results, keep the evidence and track improvements. When a test fails or only partly succeeds, you have found a weakness while there is still time to fix it. You can then test again. The result is a clear picture of what is ready, what is still uncertain and what needs attention.

Make it easy for suppliers to tell you when something goes wrong

Preparation also needs to connect to how incidents are reported. A supplier that will not complete a long assessment may still be willing to follow a simple process for reporting an incident. You can make this easier by setting clear reporting expectations in your contract and offering a straightforward, central place to report. The first report can be short. The supplier shares what it knows about the affected service and names a contact person for the response. More detail can follow as its investigation progresses.

Your own team should be able to log incidents they spot themselves, and to look into warnings from threat intelligence through the same process. It helps to keep unconfirmed signals separate from confirmed incidents, and to record where each report came from and how reliable it is. When an incident is reported, the dependency map shows which parts of the business may be affected, and the team can confirm the real impact. Continuity plans can be put into action. The related risks are recorded or linked to existing entries. Urgent actions should begin straight away, without waiting for the paperwork to be finished.

Follow the response through to the end

A clear follow-up process keeps the response organised. Every action has a named owner, a deadline and a record of progress. Updates and escalation are built in, and evidence is kept. This helps the team track what is happening, deal with weaknesses and confirm that things have recovered.

An incident should be closed only when the recovery outcomes have been confirmed. Some risk may remain, such as continued reliance on a single supplier. That may need further work, or a separate decision by management to accept it. The lessons from each incident then feed back into the dependency map, the plans and the next round of tests.

What this approach can and cannot do

This approach works alongside supplier due diligence. It cannot verify controls you know nothing about, guarantee a full recovery or reverse an exposure of information that has already happened. What it offers is practical value. It gives the business concrete ways to limit its exposure and improve its response while the gaps in supplier information are being worked on.

Our proposed offering brings together dependency mapping, guided scenario exercises, continuity planning and testing, incident reporting and risk follow-up. These run through one central platform with supporting services, and third-party threat intelligence adds a further source of awareness for cyber incidents. It helps organisations see where a supplier problem could hurt them, prepare responses that will work and follow each improvement through to completion.

You may never be able to make every supplier answer every question. You can still take meaningful steps to protect the business that depends on them.