Some years ago I left a spare key with a neighbour before a holiday. Lovely man. Retired, punctual, owned a cardigan for every occasion. I asked him to water the plants and take in the post. I asked him nothing else, because he was not the sort of person you interrogate.
I came home to living plants, a neat stack of post, and a fresh dent in the skirting board. His grandson had helped. His grandson had a bicycle. I had never met the grandson.
Nobody had done anything wrong, which is what makes it worth telling. I had made an arrangement with one person, and the arrangement had quietly grown to include somebody else, who had his own views about where a bicycle lives.
I think about that hallway most weeks, because I read supplier contracts for a living and the same shape turns up in nearly all of them.
Security teams do serious work. Controls mapped, standards certified, tests booked, findings chased down to the last stubborn medium nobody can reproduce. Then the organisation signs a document handing a third party the keys, and that one gets reviewed by different people, at a different moment, against different risks. In most of the incidents I have been called into, the controls were not the weak point. The arrangement about the keys was.
He seems very reliable
Ask a contract what security your supplier owes you and it answers with a shrug in legal costume. Appropriate technical and organisational measures. Commercially reasonable security. Industry standard practices.
None of those is a standard. They are compliments. A character reference is not a service level, and after an incident that language means whatever the supplier can persuade somebody it means.
Name the thing instead. ISO 27001, SOC 2 Type II, a specific NIST profile, whatever matches the risk you are running. Then write down what happens when certification lapses, because a great many contracts ask for the certificate on day one and say nothing for the next three years. That is the approach of a man who shows you his driving licence and then borrows the car until 2029.
More and more often the promise is not in the contract at all. It points at a trust centre, a security page, a policy living at a URL.
That is a note on the fridge, in the supplier’s handwriting, in pencil. They can rewrite it on a Tuesday afternoon. Your security commitments update themselves, in their favour, and nobody signs anything. If the schedule matters, attach it. If it must live online, insist that material changes need your agreement, a sentence suppliers dislike precisely because it works.
The grandson
You ran diligence on your supplier. You almost certainly did not run diligence on the four companies it leans on to deliver the service, nor the two it added in the spring.
Most agreements let new sub-processors in on notice, with an objection right that sounds generous and does nothing. Thirty days to object. If you object, your remedy is to terminate. For a platform already welded into your operations, that is not a remedy. It is a ceremony.
Get the current list into the contract. Ask what happens to data location when somebody new joins. Then push on the question worth more than the rest combined: when a sub-processor fails, does the supplier stay fully liable to you, or has it merely promised to pass equivalent terms down the chain and wish you luck? Plenty of contracts do the second while sounding like the first.
You may inspect the premises, in daylight, having written ahead
Almost every enterprise agreement has an audit clause. Very few have a usable one.
The standard build allows one audit a year, on ninety days’ notice, in business hours, at your cost, subject to the supplier’s confidentiality requirements, and satisfied at its election by sending you a questionnaire or its most recent third-party report. Every qualifier is defensible alone. Stacked up, they mean you will never look at anything, and both sides know it.
Two edits make it real. A right to audit on reasonable notice after an incident affecting your data, rather than once a year on a calendar that suits nobody. And a right to the whole report, exceptions and management responses included, not the summary letter written to be forwarded.
He will ring if there is a problem
Your supplier undertakes to tell you about incidents without undue delay. Regulators are less relaxed. In Europe the personal data breach clock runs to 72 hours from awareness, US state regimes keep their own time, and your customer contracts may demand notice faster than any of them.
If the chain does not line up you will be late having done nothing wrong operationally, which is a miserable way to spend a Friday. Fix a number of hours. Define what starts the clock. Say what the notice must contain. A message saying the supplier is looking into an issue is not a notification. It is a feeling.
Insured for the value of the housesitting
Liability is capped, usually at the fees paid over the previous twelve months. Breach costs have never scaled that way. Forensics, notification, customer credits, remediation, regulatory exposure, all of it arrives on a different order of magnitude to your annual subscription.
You will not always win a higher general cap. You can very often win a separate, higher figure for security and data protection failures, which is a smaller ask and a better trade. Then ask the question people forget: does the indemnity for third-party claims sit inside that cap, or outside it? That answer changes what the clause is worth, and it is usually one word.
Four questions, before anyone signs
None of this asks a security leader to retrain as a lawyer, which would waste a good security leader. It asks four questions.
What has the supplier actually promised, and can that promise change without my agreement? Who else holds a key? What may they do with my data for their own purposes, and where is that written down? When it goes wrong, when do I hear, what may I look at, and what do I get back?
I never asked my neighbour about his grandson because it had not occurred to me that there was one. That is the whole problem in a sentence. Security functions are formidable against the threats they can picture. Contracts are where the ones nobody pictured get agreed to, in the passive voice, by people solving a different problem that afternoon.
Somewhere in your supply chain, right now, there is a bicycle in the hall.

