forumNew topic

How to check security of vendors (hosting, software)

EElif K***Member
Job title
Customer Relations Manager
Sector
Logistics
Organization type
20-person company
Joined
Feb 2023
Message
74
#1

I use vendors. Should I check their security?

Should I ask for SOC 2, ISO 27001?

What should I write in the contract?

BBarış B***Member
Job title
Project manager
Sector
Cosmetics
Organization type
regional distributor
Joined
Aug 2024
Message
77
Most Helpful#2

Vendor matrix: criticality vs risk. High = ask for SOC 2. Contract: encryption, audit right.

BBeyza B***Member
Job title
Front office accounting
Sector
Automotive aftermarket
Organization type
medium-sized business
Joined
Mar 2022
Message
170
#3

i'd apprecite it if you shared the outcome.

AAycan D***MemberCommunity member
Joined
Oct 2024
Message
240
#4

Let me summarize what's been said so far. The harder it is to reverse a decision, the slower you should make it.

Solutions that work at a small scale collapse when you grow; I learned this late.

TTuğçe Y***Expert
Job title
Content Editor
Sector
E-commerce
Organization type
20-person company
Joined
Oct 2025
Message
215
#5

I feel the same way. Everything goes well for the first three months; problems arise in the fourth.

Hope this helps.

MMerve K***Member
Job title
Supply chain manager
Sector
Retail
Organization type
a company within a holding
Joined
Apr 2025
Message
328

Doki · Infrastructure migration · 2026

#6

If you're going this route, sort this out first. When making a decision first look at what data you have on hand.

Having backups accessible on the same network and with the same identity makes them part of the target... If I were you, Id go this route.

FFiliz Ö***Member
Job title
Operations manager
Sector
Seafood
Organization type
8-person team
Joined
Sep 2024
Message
383
#7

ill try it. an untested backup is not a backup.

if you have questions write them; I'll answer as best I can.

PPerihan Ş***MemberCommunity member
Joined
Apr 2024
Message
1
#8

Correct in theory, but it doesn't work that way in practice. Most time waste accumulates in tasks waiting for approval.

Processes without records never improve, because you don't know what to fix. If you post the result here, it will help others too.

RRecep K***MemberCommunity member
Joined
Mar 2023
Message
41
#9

Thanks a lot, I'll try it today. An automated scan report is not the same as a penetration test.

Of course, it varies if your situation is different.

UUğur A***MemberCommunity member
Joined
Jun 2023
Message
222
#10

This thread is archived. Hasty decisions become decisions you have to fix six months later.

If 2FA is on, a stolen password alone is useless. If I were you, I'd go this route.

MMehmet B***Member
Job title
Customer service representative
Sector
Construction
Organization type
120-person company
Joined
Nov 2023
Message
7

Doki · Vulnerability scanning · 2023

#11

I think differently. If the notification path is long, notifications don't arrive; missing notifications mean delayed incident detection.

Solutions that work at a small scale collapse when you grow; I learned this late.

ZZehra T***Member
Job title
Operations manager
Sector
Freight
Organization type
early-stage startup
Joined
Apr 2026
Message
68

Doki · Penetration test · 2025

#12

Same here.

TTaner V***MemberCommunity member
Joined
Jan 2023
Message
307
#13

My perspective changed after experiencing that. Everything goes well for the first three months; problems arise in the fourth.

The biggest time-waster for us was not knowing who had the final say. Hope this helps.

İİbrahim O***Expert
Job title
Software developer
Sector
Consulting
Organization type
300-person organization
Joined
Nov 2025
Message
278
#14

we've heard this a lot, but it never happened like that for us and honestly having backups accessible on the same network and with the same identity makes them part of the target.

thats all, sorry if I went on too long.

İİbrahim S***Expert
Job title
Store Manager
Sector
Printing
Organization type
20-person company
Joined
Nov 2022
Message
1
#15

I felt relieved reading this answer, so it's not just me. An untested backup is not a backup.

Just leaving this note, it might be useful.

GGürkan B***MemberCommunity member
Joined
Oct 2024
Message
407
#16

I'm in the same situation, that's why I'm asking. Start with a small trial; don't commit to everything at once.

Hope this helps.

GGizem D***ExpertCommunity member
Joined
Feb 2024
Message
1
#17

Looking at it as a process the picture changes. Mistakes made on the vendor security audit side are usually reversible but expensive.

Hope this helps.

FFeyza K***Expert
Job title
Clinic manager
Sector
Catering
Organization type
regional distributor
Joined
May 2022
Message
302

Doki · Interface design · 2024

#18

Let me share my experience. When making decisions, write down the worst-case scenario too, not just the best.

Forgotten test environments are more often the entry point than live systems. This is my opinion, I'm not claiming it's absolute truth.

TTolga K***Member
Job title
IT manager
Sector
E-commerce
Organization type
a company within a holding
Joined
Jul 2024
Message
76
#19

Three different views emerged, they all complement each other. When you try to change everything at once, nothing settles.

VVahide U***MemberCommunity member
Joined
Jan 2024
Message
139
#20

The answer above hits the nail on the head. anyway an untested backup is not a backup.

Most incidents start with a leaked password not a vulnerability.

Reply