Free course · Module 2 · Lesson 4 of 4
Who holds your stuff, and what matters most
What you'll decide
Which outside companies hold your data or run your systems, how you reach them when something goes wrong, and which of everything on your list is a top system, an everyday one, or a low one.
Your business runs on other people's computers. That's the normal way a small business works, and those companies are usually better at security than you could be on your own. But it means that when something goes wrong, you'll often hear about it in an email from a vendor, and what you do in the next hour depends on knowing what they hold and how to reach a human.
Plain-English terms
Vendor. An outside company that runs something for you or holds something of yours: your IT provider, website host, payroll company, card processor, backup service, alarm company, accountant.
Incident notice. The email a vendor sends when they've had a breach. Often vague on purpose, always worth a phone call.
Level. How much a system matters to your business: Top, Everyday or Low. It's the column that connects this inventory to Module 1's rules.
Ask your vendors three questions
Three answers per vendor, written down before anything goes wrong, do more for you than a security questionnaire would.
What of ours do you hold?
Customer records, card details, payroll data, your files, your email, your passwords. The payroll company holds bank details and Social Security numbers. That's a different vendor from the one that hosts your brochure site.
If you have a breach, how and how fast will you tell us?
It should be in the agreement. If they can't say, assume you'll find out from a customer.
Who do we call at 6 pm on a Friday?
A phone number that reaches a person, not the support form. Write it in the file. When you need it, you won't have time to look for it.
Your IT provider gets one more question, from Lesson 3: which of our devices can be reached from outside, and why? They should also be the first vendor on the list, because they hold the most: admin access to everything.
Mark what matters most
Every row on the Apps and Devices tabs now gets a level. Three choices:
- Top. The three to five systems from Module 1: money that moves, email, customer data, and the thing you can't open without. If you skipped Module 1, that's the test.
- Everyday. The business runs better with it and would be annoyed without it. Most things.
- Low. Nice to have. Holds nothing sensitive. The meeting-room TV.
This is the column that makes Module 1's rules work. A problem on a Top system moves up one deadline level. When your IT provider asks which of six things to do first, the answer comes from this column and Module 1's boxes, in about a minute.
If you ever grow into a security team, these three levels map onto the four tiers security programs use: Top is Tier 0 and 1, Everyday is Tier 2, Low is Tier 3.
Keep it alive
An inventory that's six months old is a story about the past. Two habits keep it true:
- Twice a year, read it through. The same rhythm as Module 1's review and Step 18 of the Security Starter. Thirty minutes.
- Four events update it the same day. Someone joins or leaves (Tab 1). A new app or device arrives (Tabs 2 and 3). A vendor changes (Tab 4).
The Read me tab shows the numbers to watch: people who left with access still in place, apps holding money or customer data without two-step login, devices a stranger can reach, devices out of support. Every one of those should be zero or explained by an exception in your Module 1 file.
Scenario
The vendor's email
Your payroll provider emails all customers: they've had a security incident, some customer data may have been accessed, they're investigating, and more information will follow. Nothing more specific.
What do you do in the next hour?
Pick the one you would choose. It opens with the reasoning, then you can compare the rest.
AWait for the follow-up email.
The follow-up may take days and will be written by lawyers. Meanwhile, the people whose data was in there are your staff, and the first scam emails pretending to be from the payroll company will arrive before the follow-up does.
BOpen your file. Check what they hold and who can log in, call the emergency number in your Vendors tab, then act on what you learn.
The Vendors tab says they hold bank details and Social Security numbers for every employee. The Apps tab says three people can log in. You call, and a person tells you whether your account was among those affected. Either way: confirm two-step login is on for all three users, change the passwords, and tell staff to expect scam emails and texts claiming to be from payroll. Then write the date and what you did in the Read me tab's review log.
CCancel the payroll service immediately.
You still have to pay people on Friday, and switching payroll providers takes weeks. Cancelling doesn't get your data back out of their systems either. Find out what happened first. Move providers later, on purpose, if the answers are bad.
DForward the email to all staff.
Telling staff is right, but forwarding a vague vendor email without context starts a panic and, worse, teaches people that emails about payroll security are normal, which is exactly what the scammers are about to send. Tell them yourself, in your own words, with what to watch for.
Remember
- Every vendor gets three answers written down: what they hold, how they'll tell you about a breach, and who to call at 6 pm on a Friday.
- Every app and device gets a level: Top, Everyday or Low. That column is what makes Module 1's rules work.
- Twice a year, read it through. Four events update it the same day: someone joins or leaves, a new app or device, a vendor change.
Build your file
Tab 4: Vendors, then the Level column
Open the Vendors tab. Add one row per outside company that runs something for you or holds your data. For each: what they do for you, what of yours they hold, the emergency phone number, and what their agreement says about telling you about a breach. Where you don't know, that's this month's phone calls.
Then go back to the Apps and services and Devices tabs and fill in the Level column for every row: Top, Everyday or Low. If you did Module 1, your Top rows should match the top systems in your Fix-First Rules file. If they don't, one of the two files is wrong; decide which.
Last, open the Read me tab. Read the numbers to watch; every one that isn't zero is a job or an exception. Fill in the review date, six months out, and put it in your calendar.
That's the file finished. Share it with your IT provider the same way as your Module 1 file: a view-only link to named people, not an attachment. It's the list they've probably been asking you for.
Where this goes next
Steps 13 and 14 of the Security Starter use this tab directly: the one-page "if it goes wrong" plan needs the vendor phone numbers, and the cyber-insurance application asks for exactly this inventory. In the VM Program Kit, the Level column is the asset tier in the VM Policy and on the Prioritization Model's Assets tab.