Research pillar · Zero Security Theatre

Vendor and supply-chain resilience

Other organisations hold much of a company's security in their hands: managed providers, cloud platforms, software vendors, clinical systems, contractors, open-source maintainers, and AI providers. This pillar asks what those parties actually do when trouble starts.

The question

When something goes wrong at three in the morning, what does the vendor do, and when was that last tested?

Active · since 2026 · Zero Security Theatre

Replacing the sentence that ends the conversation

observation

The phrase our vendor handles that often ends the inquiry too soon. The vendor handles a defined set of events, sees a defined set of data, and can take only the actions the contract and customer permit.

What actually happens when a vendor is involvedAn event travels from telemetry the vendor receives, through their detection and named escalation, to the actions they may take and the approvals those require.Telemetrywhat they receiveDetectionwhat they watchEscalationwho is calledActionwhat they may doApprovalwhat waits on youTestwhen last rehearsed
Record when this path was last tested and what happened.

The questions that replace it

recommendation

These questions are deliberately operational. A questionnaire response cannot answer most of them.

What do they receive?

Which log sources, endpoints, identities, and networks are actually in scope, and which parts of the estate send them nothing.

What do they watch for?

The specific detections in place, rather than a category name like twenty-four seven monitoring.

Who is called?

Named roles on both sides, with an out-of-hours path that has been dialled at least once.

What may they do?

Whether they can isolate a host, disable an account, or block traffic without waiting, and what requires your approval.

What is the response commitment?

Contracted times, and the observed times from the last several events.

What if the vendor is compromised?

The most under-examined question. Their access to your estate is a blast radius you own.

What a vendor certificate leaves out

inference

A vendor's certification report describes their control environment at a point in time against their own scope definition. It is evidence about their program, not about your configuration of their product, which is where a large share of incidents originate.

Shared-responsibility boundaries therefore need direct testing. Published incident reports support that view, but the claim should keep being checked against new cases.

What would prove us wrong?

unknown

The pillar assumes tested vendor workflows predict outcomes better than vendor attestations.

  • Incident data showing that vendor certification status correlates with client outcomes as strongly as rehearsed escalation does.
  • Evidence that joint exercises are so costly or disruptive that they are only feasible for the largest clients, making the recommendation impractical rather than wrong.
  • Findings that most third-party loss originates in software supply chain compromise, where escalation testing changes little.

Put this to work

Research decision record

Use the question “When something goes wrong at three in the morning, what does the vendor do, and when was that last tested?” on a real case and produce a record another person can challenge.

For
Practitioners, researchers, founders, and operating leaders.
What you keep
A research decision record you can review, revise, and send.
What counts as sound
  • Answers a named decision
  • Separates evidence from assumptions
  • Includes the strongest contrary case
  • Names missing evidence
  • Ends with a test, owner, and date

The result is a working analysis. Check it against source evidence and qualified judgment.

Nothing entered here is stored or sent. Review the prompt before sharing confidential, personal, patient, or privileged information.

Review the prompt

You can leave any field blank. The prompt will mark it as not provided.

If the record survives your review, send the question, evidence, unknowns, and requested next step.

Experiments for this pillar

Patterns and anti-patterns

  • Pattern

    Rehearse the out-of-hours call

    Exercise every critical vendor escalation path on a schedule and record who answered and how long it took. An unexercised path is unknown, and unknown is red.

  • Anti-pattern

    Our vendor handles that

    This answer leaves out what the vendor sees and what it may do. Ask for the data received, the detections in place, the permitted actions, and the date the response path was last tested.

See the full patterns register

Evidence for this pillar

Read the full evidence library

Notes under this pillar

Design Patterns

  • Escalation paths decay quietly

    Contacts leave, numbers change, portals replace phone trees, and contracts renew with different terms. An untested escalation path is an assumption with a date on it.

    2026-09-15

Operating Theorys