Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

When an IT vendor repeatedly misses commitments, withholds security information, or makes it hard to retrieve your data, respond with documented facts and a corrective plan—not a vague complaint. Prioritize the few issues that could cause the greatest harm, compare performance with your agreement, assign owners and deadlines, and prepare a transition if the risk remains unacceptable.

Which vendor behaviors deserve attention first?

“Bad habits” is a conversational label, not a formal vendor-risk category. Focus on observable behavior and its consequences. A single late response may be an exception; repeated missed deadlines, unresolved incidents, or absent evidence can indicate a pattern that needs formal attention.

Start with the issues that could threaten sensitive information, service continuity, or your ability to change providers. CISA advises leaders to focus on the “critical few” risks rather than trying to address everything at once (CISA Bad Practices). That is a prioritization principle, not a universal ranking of vendor problems.

  • Security exposure: unexplained vulnerabilities, delayed fixes, unclear incident notification, or refusal to provide relevant security evidence.
  • Operational disruption: recurring outages, missed service commitments, or unclear ownership during an incident.
  • Loss of visibility: missing reports, undisclosed subcontractors, or no access to records needed to understand a security event.
  • Blocked exit: data that cannot be exported in a usable form, undocumented integrations, or dependencies that make a transition impractical.

For each concern, record dates, commitments, impact, and what remains unresolved. “The vendor is unresponsive” is difficult to act on; “the incident update due Tuesday was not delivered, and the issue remains open” gives both parties something verifiable to address.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

How should you assess what the vendor owes you?

Before escalating, compare actual performance with the service description and commitments already agreed. Review the relevant provisions and supporting records rather than assuming every desirable practice is contractually required.

  • What service, deliverable, or security measure was promised?
  • What response, escalation, or reporting process applies?
  • Who is responsible on each side, including during an incident?
  • What does the agreement say about subcontractors, data access, and transition assistance?
  • What evidence shows whether the commitment was met?

For a repeatable supplier review, CISA’s small- and medium-sized business fact sheet covers topics including security and privacy policies, asset management, network access, contractual obligations, incident detection, and recovery (CISA supplier assessment fact sheet). Use questions that fit the service and the sensitivity of the data involved; an assessment is useful only if answers are reviewed and acted on.

What evidence should you request?

Ask for information that addresses the specific risk, not a broad assurance that the vendor is “secure” or “working on it.” For a software supplier, relevant questions may cover vulnerability handling, patching, incident notification, and information about software components. NIST’s guidance discusses acquisition, use, and maintenance of third-party software, including component inventories, vendor assessments, and vulnerability management. Its stated audience is federal agencies, so it is useful as a risk-management reference, not a universal legal mandate (NIST software supply-chain guidance).

If the vendor is a managed service provider (MSP), make oversight specific. CISA’s guidance for MSP customers highlights areas such as security requirements, subcontractor vetting, and access to relevant security logs and telemetry (CISA MSP customer guidance). Agree in advance on what information you can receive, who can provide it, and how it will be shared when an incident occurs.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

How do you ask for a credible corrective plan?

Describe the gap, its impact, and the commitment or evidence you need. Ask the vendor to respond in writing with a plan that can be checked, not just a reassurance.

  1. State the facts: list the relevant dates, missed commitments, open issues, and business or security impact.
  2. Name the required outcome: specify what must change or what evidence is needed to verify progress.
  3. Assign owners: identify a vendor lead and a buyer-side contact for each action.
  4. Set milestones: ask for dated steps and a completion target proportionate to the risk and any applicable agreement.
  5. Agree on proof and review: define what will demonstrate completion and schedule a date to assess it.

Keep meeting notes, written requests, responses, incident records, and evidence of completed or missed actions together. Involve security, procurement, operations, and legal owners as appropriate; a vendor issue may affect more than the team that manages the day-to-day relationship.

How do you reduce the risk of getting stuck?

Integration can improve agility, productivity, and operations, but dependence on a provider can make change difficult. Gartner’s public abstract frames cloud lock-in as a risk to assess alongside those benefits; it does not prescribe specific contract wording (Gartner cloud lock-in abstract).

Map the dependencies that would matter if the service ended or became unavailable:

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
  • Data stored by the vendor and whether it can be exported in a usable format.
  • Proprietary tools, integrations, credentials, and configurations needed to run the service.
  • Downstream providers or subcontractors involved in delivering it.
  • People and processes that would need to take over, and the time required to do so.
  • How operations would continue during an incident, ownership change, or transition.

Use that map to identify missing documentation and test whether an exit is workable before a crisis. Check the agreement for applicable data-return, transition, and termination provisions. Do not assume that a preferred exit term already exists or that a vendor can provide transition support beyond what was agreed.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

When should you escalate or change vendors?

Use the escalation route in your agreement and bring in the people who own the affected risks. A missed service commitment may require operational escalation; a security exposure may also require security leadership and a defined incident process. For possible contractual remedies or termination, review the agreement and applicable law with qualified counsel rather than ending the relationship unilaterally.

Consider a managed transition when the vendor cannot or will not correct a material risk, when repeated failures continue despite agreed actions, or when you cannot obtain the visibility needed to manage exposure. Before moving, confirm how to preserve service continuity, retrieve required data and records, transfer responsibilities, and address dependencies. The decision should weigh the risk of staying against the practical risks of leaving.

How should you compare a replacement vendor?

Use the same criteria to compare candidates, tailored to the service and the information or operations at stake. These are practical comparison axes, not a universal scoring model.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Area Questions to ask
Security evidence Can the provider explain its vulnerability disclosure and patch process, incident handling, and relevant audit evidence? Can it provide information about software components where relevant?
Operational accountability Is the service scope clear? Are commitments measurable, with named escalation contacts and a reporting cadence?
Dependencies and exit Can you retrieve data in a usable form? What proprietary components and integrations would affect a transition, and what transition support is agreed?
Supplier visibility Are subcontractors disclosed and assessed? Can you obtain the records or telemetry needed to oversee the service?

Set expectations at onboarding and revisit them on a recurring schedule. Supplier oversight depends on buyer follow-through as well as provider performance: responsibilities, evidence, owners, and review dates need to be clear on both sides.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.