Ernst & Young, one of the biggest accounting firms alive, lost clients’ tax records through its own help desk. You hand your crown jewels to outside vendors every day. Here is why their weak door is your problem, and what to do about it.
See Where Your Business Stands →
A plain-English computer security scan. No card needed to see your results.
The problem: Vendor data breach risk is the exposure most owners never think about, because it is not your computer that gets hit. It is your accountant’s, your payroll company’s, your website host’s. Their break-in becomes your problem: your customers’ information, your liability, your apology to make.
The straight answer: You cannot personally guard every vendor’s systems. But “we use a reputable vendor” is not a security plan, it is a hope with a logo on it. Let me show you how a firm with every resource in the world still got hit, what it actually costs you when a vendor fails, and how to stop hoping and start knowing.
Hey folks! This one is worth your time because the lesson in it is the one most business owners have never had spelled out.
Ernst & Young is one of the biggest accounting firms on the planet. This month it started telling clients some bad news. A criminal got into the system its own IT staff use for support tickets, and quietly downloaded documents. Tax filings. Financial account information. Social Security numbers. The kind of paperwork clients handed over trusting it would be guarded.
Here is how it played out. The intruder was inside from late March into April. The firm did not notice until April 23. The stolen files were sitting in ordinary help-desk tickets, the kind where someone staples a sensitive attachment on so support can “just take a look.” A side door, in a system nobody thought of as the front door.
Sit with the size of that for a second. EY has money, staff, and security experts most of us can only dream of. It still got robbed through a quiet side door nobody was watching closely enough. If that can happen to them, the comfortable idea that your business is too small, or too careful, to worry about this does not really hold up.
Source: BleepingComputer, July 2026.
The reason I am writing a whole article about somebody else’s breach is that it is not really about somebody else. It is about a risk sitting quietly in your own business right now.
Think about how many outsiders hold your crown jewels. Your accountant has your financials. Your payroll company has your employees’ Social Security numbers and bank details. Your IT vendor has the keys to everything. The company hosting your website has your customer list. You handed each of them something valuable and, quite reasonably, assumed they were guarding it, the same way EY’s clients assumed the help desk was fine.
Here is the hard truth underneath all of it. You are only as safe as the least careful company you do business with. Every vendor you trust is another door into your data, and you did not get to inspect the lock. When one of them gets breached, it does not stay their problem. Your customers’ information is what walks out, your name is on the notification letter, and you are the one making the apology. Their weak door, your consequences.
I am not telling you to fire your accountant or to become a security auditor in your spare time. Checking every vendor yourself was never your job, and you do not have the time or the tools for it. But somebody should be asking the question on your behalf, and in most small businesses, nobody is. That silence is the whole risk.
When a vendor loses your data, the bill lands on your desk, not theirs. Let me walk you through what that bill looks like, because this is a business problem first and a tech problem a distant second.
That is the real exposure, and the ugly part is that you can do everything right on your own computers and still get hurt through a door you do not even own. That is exactly why watching stops being a one-machine job and becomes a job about the whole picture of who touches your business.
My own father fell for a phishing email. That is a fake message built to trick you into giving up a password or your money. More than three decades in this field, and it still reached the person I most wanted to protect. Scammers got into his computer from far away and started hunting for his financial papers. My step-mother noticed something was wrong and called me. I stopped them before they reached his bank logins. We were lucky. We caught it in time. A day slower and it would have been a very different phone call.
That is what an unwatched door feels like when it is your family, and it is why I do this the way I do. More than 35 years at this, since 1991. FBI InfraGard trainer. Not one client I manage has ever been hit by ransomware, which is software that locks up your files and holds them for money. That is not luck. It is a real person watching the doors, including the ones your vendors hold, instead of assuming everyone else has it covered.
EY is about as big and reputable as a vendor gets, and it still happened. Reputable means they are good at their business, not that they are flawless at guarding yours, and it does not change who eats the consequences when they slip. Yes, security is partly their job. But making sure someone is actually watching the doors between you and the people who hold your data, that part has always been yours, whether anyone told you or not.
So the honest question is not “are my vendors reputable.” It is “does anyone actually know how exposed I am through the companies I trust, or am I just hoping, the way EY’s clients were?” If the answer is hope, that is the open door.
Let me ask you a few plain questions, and just answer them in your head. You picked your vendors carefully, right? You went with names you trusted so you would not have to worry about this. You are a careful owner, the kind who reads a warning like this all the way down. And you also just watched a firm with every advantage lose client tax records through a side door, which means careful vendor choices and real exposure can live in the same business at the same time. Those two truths sitting together is an uncomfortable feeling.
That discomfort is not you having failed. It is the gap between the careful owner you are and a set of doors, held by other people, that nobody was watching on your behalf. That gap is not a knock on you. It opened because vendor risk is invisible from where you sit, and because no one ever made it somebody’s job to keep an eye on it for you.
Here is the thing about that gap. You close it one of two ways. You can tell yourself your vendors have surely got it handled, and carry that quiet question into the next breach headline. Or you can take a few minutes, get a clear picture of where you actually stand, and put it to bed. One of those roads ends the worry. The other just reschedules it. Acting is not the risky move. Acting is what makes the worry stop.
You cannot audit every vendor yourself, and you should not have to. What you can do is have someone watching the whole picture of who touches your business, so their weak door does not become your bad week. You do not have to do it alone.
Book a call, on us. We scan your business and fix the three things most likely to hurt you right now. You will not pay a dime, and you decide what happens next.
Not one client we manage has ever been hit by ransomware. That is not luck. That is someone actually watching the doors.
You run your business. We keep it running.
Book My Call →
A few minutes with a real person, straight talk on where your business stands. No pressure.
Want this kind of plain-English security news every week? Sign up for Craig’s Insider Notes at CraigPeterson.com.
#VendorRisk #SmallBusinessCybersecurity #DataBreach #ForwardToSafety
Join thousands of security professionals who receive Craig Peterson's Insider Show Notes and cybersecurity updates.
Tagged with: