What do they receive?
Which log sources, endpoints, identities, and networks are actually in scope, and which parts of the estate send them nothing.
Research pillar · Zero Security Theatre
Other organisations hold much of a company's security in their hands: managed providers, cloud platforms, software vendors, clinical systems, contractors, open-source maintainers, and AI providers. This pillar asks what those parties actually do when trouble starts.
The question
When something goes wrong at three in the morning, what does the vendor do, and when was that last tested?
Active · since 2026 · Zero Security Theatre
observation
The phrase our vendor handles that often ends the inquiry too soon. The vendor handles a defined set of events, sees a defined set of data, and can take only the actions the contract and customer permit.
recommendation
These questions are deliberately operational. A questionnaire response cannot answer most of them.
Which log sources, endpoints, identities, and networks are actually in scope, and which parts of the estate send them nothing.
The specific detections in place, rather than a category name like twenty-four seven monitoring.
Named roles on both sides, with an out-of-hours path that has been dialled at least once.
Whether they can isolate a host, disable an account, or block traffic without waiting, and what requires your approval.
Contracted times, and the observed times from the last several events.
The most under-examined question. Their access to your estate is a blast radius you own.
inference
A vendor's certification report describes their control environment at a point in time against their own scope definition. It is evidence about their program, not about your configuration of their product, which is where a large share of incidents originate.
Shared-responsibility boundaries therefore need direct testing. Published incident reports support that view, but the claim should keep being checked against new cases.
unknown
The pillar assumes tested vendor workflows predict outcomes better than vendor attestations.
Put this to work
Use the question “When something goes wrong at three in the morning, what does the vendor do, and when was that last tested?” on a real case and produce a record another person can challenge.
The result is a working analysis. Check it against source evidence and qualified judgment.
Nothing entered here is stored or sent. Review the prompt before sharing confidential, personal, patient, or privileged information.
You can leave any field blank. The prompt will mark it as not provided.
If the record survives your review, send the question, evidence, unknowns, and requested next step.
What does the provider actually do when called at three in the morning?
Pattern
Rehearse the out-of-hours call
Exercise every critical vendor escalation path on a schedule and record who answered and how long it took. An unexercised path is unknown, and unknown is red.
Anti-pattern
Our vendor handles that
This answer leaves out what the vendor sees and what it may do. Ask for the data received, the detections in place, the permitted actions, and the date the response path was last tested.
Third-party practice guidance. The gap this area studies is between its practices and the tested escalation path.
Places responsibility for safe defaults with the supplier, which is the vendor-side form of this area's design argument.
Annual incident pattern data. Useful for base rates, with the usual caution that the sample is not a population.
Design Patterns
Contacts leave, numbers change, portals replace phone trees, and contracts renew with different terms. An untested escalation path is an assumption with a date on it.
2026-09-15
Operating Theorys
Third-party risk programs assess whether a vendor protects your data. They rarely assess the blast radius of the vendor's own access to your systems.
2026-09-15