A hand touches a digital icon with lines connecting to multiple avatar icons, symbolizing data sharing or network communication on a blue background.

The Vendor Nobody Owns: Why IT Vendor Management Belongs With Your IT Provider

By Jason Russell · August 17, 2026

Here is a conversation I have heard some version of hundreds of times over the past 25 years. The phone system stops ringing through to the front desk. The office manager calls the phone vendor. The phone vendor says it is a network problem and to call IT. IT looks at the switch, sees nothing wrong, and says to call the phone vendor. Two days later, the phones still do not work, three people have spent a combined six hours on hold, and the owner is asking why she pays two companies to point at each other.

That is not a technology failure. It is an ownership failure. Nobody in that chain was responsible for the outcome, only for their own slice of the stack. IT vendor management is the fix for that problem, and it is one of the least glamorous and most valuable things a managed IT provider can do for a small business.

This post explains what vendor management actually means, why it has become a security issue rather than just a convenience issue, what Harmony MSP does when we take it on for a client, and, in the interest of honesty, what we cannot do.

What IT vendor management actually is

Strip away the jargon and vendor management is four things:

  • Knowing who your vendors are. Every company that touches your technology: internet provider, phone system, line-of-business software, payroll platform, copier company, website host, security camera installer, cloud backup, email marketing tool, and the dozen subscriptions someone signed up for with a company card.
  • Knowing what each one can reach. Which vendors have logins to your systems, remote access to your network, API connections into your data, or standing admin accounts that nobody has reviewed since installation.
  • Having a single point of contact. One party who opens the ticket, stays on the call, escalates when needed, and owns the outcome regardless of whose fault the problem is.
  • Managing the lifecycle. Contract terms, renewal dates, price increases, security reviews, and, critically, offboarding when the relationship ends.

Most small businesses do some of this informally. The office manager has a spreadsheet, or the owner has it in his head. What almost none of them have is someone with the technical background to evaluate what a vendor is asking for, push back when the request is unreasonable, and recognize when a vendor is the actual cause of a problem it is blaming on someone else. If that sounds like the documentation problem we described in IT Asset and Documentation Management, it is. Vendor management is the same discipline applied to the people outside your walls.

Why this stopped being a convenience issue

For most of my career, vendor management was sold as a time saver. It still is one. But the numbers over the last three years have turned it into a security control.

Verizon publishes the Data Breach Investigations Report every year, built on tens of thousands of real incidents contributed by law enforcement, forensic firms, and insurers. It is the closest thing our industry has to an unbiased scoreboard. In the 2024 edition, roughly 15 percent of breaches involved a third party. The 2025 edition reported that figure had doubled to 30 percent. The 2026 edition, published in May, reports that third-party involvement jumped another 60 percent and now appears in 48 percent of all breaches.

Read that trajectory again: 15 percent, then 30, then 48, in three consecutive reports. Nearly half of the breaches Verizon analyzed involved a vendor, a supplier, a software platform, or a service provider somewhere in the chain.

What “third-party involvement” means in practice: The DBIR counts a breach as third-party involved when a vendor, partner, or supplier played a role in how it happened. That includes a software vulnerability in a product you bought, a compromised vendor account that had access to your environment, a misconfigured cloud platform, and stolen credentials that were reused across a supplier relationship. It does not require the vendor to be the target. Attackers frequently compromise the vendor to reach the customers behind it, because one successful intrusion opens the door to dozens or hundreds of downstream businesses.

The 2026 report also digs into why vendors keep showing up in the data. According to the report, only 23 percent of third-party organizations fully remediated missing or misconfigured multi-factor authentication on cloud accounts, and weak password and permission problems in third-party cloud environments took a median of roughly eight months to reach 50 percent remediation. In plain terms: the companies you hand your data to are, on average, slow to fix basic account security, and they are slow for months at a time.

I want to be careful here. Verizon’s dataset skews toward organizations large enough to have incident response firms involved, and the report does not break the third-party figure out by victim size. I am not going to tell you that 48 percent of small business breaches come through vendors, because the report does not say that. What it does say is that the direction of the trend is unmistakable, and small businesses depend on outside vendors more heavily than large ones, not less.

What goes wrong when nobody owns it

These are patterns I have seen repeatedly at businesses in Central Florida. None of them are exotic.

The orphaned admin account

A software vendor installs a system in 2021 and creates an administrator account to do it. The install technician leaves the vendor in 2023. The account is still there in 2026 with the same password, no MFA, and full access. Nobody at the client knows it exists because nobody was tracking what the vendor was given. This is not hypothetical; it is the single most common finding when we onboard a new client and audit their user directory.

The bounce

The phone scenario from the opening. Two vendors, each technically correct that the problem is not in their system, and a client eating the cost of the gap between them. The most expensive part is not the outage. It is that the office manager now spends part of every week acting as an unpaid technical project manager for a problem she is not equipped to diagnose.

The renewal nobody saw coming

A three-year software contract auto-renews at a 22 percent increase because the cancellation window was 90 days before term end and nobody had the date on a calendar. The vendor is within its rights. The client is stuck. This one is not a security problem, but it is a real dollar problem, and it comes from the same root cause: no one owned the relationship.

The temporary access that became permanent

A vendor needs remote access to fix something on a Friday afternoon. Someone opens a firewall rule, or installs a remote access tool, or shares a credential over text. The fix works. The access stays. Six months later that same remote access path is how ransomware gets in, and the vendor says, correctly, that it never asked for the access to be left open.

The offboarding that never happened

You switch payroll providers, marketing agencies, or IT companies. The old vendor still has an email account, a VPN certificate, a shared drive link, or an API token. Sometimes for years. Every one of those is a standing entry point held by an organization that no longer has any obligation to protect it.

What Harmony MSP does when we manage your vendors

When vendor management is part of our agreement, here is what that covers. I am listing it specifically because “we manage your vendors” can mean almost anything, and I would rather you hold us to a written standard.

  • Vendor inventory. We build and maintain a list of every technology vendor, what they provide, what they can access, who the account contacts are, and what the contract terms are. This lives in our documentation system, and you get a copy.
  • Single point of contact. When something breaks, you call us. We call the vendor, stay on the ticket, and escalate. If the vendor says it is a network problem, we check the network before we call you back. If it is their problem, we say so and stay on them until it is fixed.
  • Access control. Vendor accounts are documented, scoped to what the vendor actually needs, protected with MFA where the platform supports it, and reviewed on a schedule. Temporary access gets an expiration date before it gets turned on.
  • Security due diligence. Before a new vendor connects to your environment, we ask the questions CISA recommends small businesses ask: how they handle authentication, how they respond to incidents, whether they have had a breach, and how they will notify you if they do. We do not pretend a questionnaire makes a vendor safe, but it does surface the ones who cannot answer.
  • Renewal and contract calendar. Every contract end date and cancellation window goes on a calendar we watch. You hear from us before the deadline, not after.
  • Offboarding. When a vendor relationship ends, every credential, certificate, remote access path, and integration that vendor held gets removed, and we confirm in writing that it is done.

That last point deserves emphasis. If you take one thing from this post and do nothing else, go find out what your previous IT company, previous payroll provider, and previous website developer can still log into. The answer is almost never “nothing.”

What we cannot do, and where our interest lies

Two things I want to be plain about.

First, managing a vendor does not make the vendor competent. If your practice management software has a bug, we cannot write the patch. If your ISP has a regional outage, we cannot fix the fiber. What we can do is stay on it so you do not have to, tell you the truth about whose problem it is, and, when a vendor is repeatedly the source of your pain, give you a documented case for replacing them.

Second, we are a third party too. Every argument in this post about vendor access applies to Harmony MSP. That is why our own access to your environment is documented in your vendor inventory, protected with MFA and dedicated accounts, and reviewed on the same schedule as everyone else. If an IT provider is not willing to be held to the standard it applies to your other vendors, that tells you something.

A note on self-interest: vendor management serves our interests as well as yours. A client with a clean vendor inventory, tight access control, and no orphaned accounts is a client we spend fewer hours firefighting and fewer weekends recovering. We charge for this work because it is real work, and we are motivated to do it well because it makes every other part of our job easier. I do not think that undercuts the value. I think it explains why we take it seriously.

The compliance angle

If your business handles protected data, vendor oversight is not optional, it is a requirement you already have.

  • Healthcare. HIPAA requires covered entities to have Business Associate Agreements with vendors that handle protected health information, and to take reasonable steps to ensure those vendors protect it. A vendor list you cannot produce is a finding waiting to happen. (We covered the broader program in HIPAA Compliance Is Not a Binder.)
  • Financial and professional services. The FTC Safeguards Rule, which reaches tax preparers, mortgage brokers, auto dealers with financing, and other non-bank financial institutions, requires you to oversee service providers and periodically assess them.
  • Everyone else. CIS Control 15, Service Provider Management, is part of the CIS Critical Security Controls that most cyber insurance questionnaires are quietly built around. The first safeguard in that control is simply “establish and maintain an inventory of service providers.” If you cannot check that box, expect it to show up in your renewal. (See How to Answer Cyber Insurance Renewal Questions Without Voiding Your Policy.)

CISA has published free guidance specifically for small and medium businesses on this, including a vendor assessment template and a resource handbook. They are worth reading even if you never hire anyone to do this for you.

A quick self-check

Answer these honestly for your own business. Every “no” is a gap someone should own.

Question Why it matters
Can you produce a complete list of your technology vendors in under ten minutes? If it takes longer, the list does not exist in any usable form. That is the starting point for everything else.
Do you know which vendors have admin access or remote access to your systems? Vendor accounts with standing access are the most common path from “their breach” to “your breach.”
Has anyone reviewed vendor accounts in the last 12 months? Access accumulates. Accounts created for installs, migrations, or troubleshooting tend to outlive their purpose by years.
When your last IT provider, payroll company, or web developer left, did someone confirm their access was removed? Former vendors have no obligation to protect credentials they still hold. Many do not even know they still hold them.
Is there one person who owns a multi-vendor problem end to end? Without an owner, outages get longer and your staff becomes the unpaid coordinator.
Do you know your next three contract renewal dates and cancellation windows? Auto-renewals at higher rates are a recurring, avoidable cost that comes from nobody tracking the calendar.

Where to start

You do not need to hire anyone to take the first step. Sit down with whoever handles your invoices and list every company you pay for technology. Then, next to each one, write down what it can reach. Most owners are surprised by the length of the first list and unsettled by how many blanks are in the second column.

That exercise usually makes the case for itself. If you would like a second set of eyes on it, or you would rather have someone build and maintain it for you, we are happy to talk through what that looks like for a business your size. No pressure and no pitch deck. Call Harmony MSP at (407) 720-6540.

Frequently asked questions

What is IT vendor management?

It is the practice of keeping an accurate inventory of every technology vendor your business uses, knowing what each one can access, having a single point of contact who owns multi-vendor problems end to end, and managing contracts, security reviews, and offboarding over the life of the relationship.

Why is vendor management a security issue and not just an administrative one?

Because vendor accounts, remote access paths, and integrations are entry points into your environment. Verizon’s 2026 Data Breach Investigations Report found third-party involvement in 48 percent of breaches, up from 30 percent the prior year and roughly 15 percent the year before that.

Does Harmony MSP charge separately for vendor management?

It is included in our managed services agreements rather than sold as an add-on, for the same reason we do not sell security as an add-on: the work makes everything else we do for you cheaper and more reliable, and splitting it out would create an incentive to skip it.

What should I do about vendors that no longer work with us?

Confirm, in writing, that every credential, remote access tool, certificate, and integration they held has been removed. If you cannot get that confirmation from the old vendor, have your current IT provider audit for it directly. Former vendors are the most common source of forgotten access.

Sources

A note on statistics: The 23 percent MFA remediation figure and the eight-month remediation median are reported in the 2026 DBIR and were confirmed across multiple independent summaries of the report. Figures on SaaS application counts per business were considered for this post and excluded because the available numbers come from vendor surveys with inconsistent methodologies.

Our latest posts