This website uses cookies

Read our Privacy policy and Terms of use for more information.

Bayou Bytes  //  Issue #04  //  Vendor Risk Week

Come, Take Your First Byte.

Three sections, about twelve minutes. Starting now.
 
New this week — a free tool
Gatorbyte #006 — free public Notion template
📥 The Vendor-Risk 3-Question Tracker (Notion) →

The Pulse

Welcome to Bayou Bytes. Here’s the deal, in one breath: most cybersecurity writing tells you the sky is falling and stops there. This doesn’t. Every Tuesday you get three things — the threats that actually moved, one copy-paste fix you can ship before lunch, and the plain-English version your non-technical CEO needs to hear. Three sections, about twelve minutes. That’s the whole contract.

You’re getting this because you run security for a living — for a company, for clients, for an engagement, or as the senior tech everyone messages when something breaks. That’s exactly who this is for: in-house security and IT leads, compliance and risk owners, vCISOs, MSPs and MSSPs, consultants, SMB owners, and founders prepping for their first audit.

Now, this week:

More than half of 2026’s breach notices trace to ONE vendor.

The KEV list grew again yesterday. CISA added two actively exploited bugs Monday: an information-exposure flaw in Fortinet FortiOS (CVE-2025-68686) and an OS command injection in Arista’s VeloCloud Orchestrator (CVE-2026-16812). Both sit at the network edge you — or your MSP — manage. A KEV listing means exploitation is confirmed in the wild: treat the patch as scheduled, not optional.

One vendor, ~58% of the year’s breach notices. ITRC’s H1 2026 report counts 471 million breach notices from 1,029 compromises — and roughly 275 million of them trace to a single supply-chain breach: Instructure’s Canvas. Supply-chain attacks overall: 38 incidents touching 206 organizations in six months. The math is the message — your riskiest system may be somebody else’s.

The Canvas cleanup lands this week. Instructure is running incident webcasts for institutional customers July 29–31 and still updating its incident pages. If Canvas sits anywhere in your stack — or a client’s — that calendar slot is your evidence-gathering window. Show up holding the three questions below.

Last week’s poll — do you bill compliance separately? — is still open; votes keep steering the playbooks.

 

The Hardened Stack

Deep Dive: the vendor register you can build in an afternoon.

The Canvas/Instructure story is the whole category in one sentence: a reported ~9,000 schools breached through a single vendor — and not one of them ran a vulnerable server. You can do everything right and still own the consequences of a vendor’s mistake. NIST CSF 2.0 made supply chain a first-class category (GV.SC) for exactly this reason.

Three questions per vendor. That’s the register:

For EVERY vendor that touches client data:
1 — WHAT DO THEY HOLD?     data classes: PII / PHI / PCI / creds / backups
2 — WHAT DID WE AGREE?     security terms in the contract: breach notice
                            window, MFA/encryption commitments, sub-processors
3 — HOW WOULD WE KNOW?     their status page? our log visibility? or…
                            we’d find out from the news?

Scoring is brutal on purpose:
🟢 = answered from a document, in under a minute
🟡 = answered from memory (“pretty sure it’s in the MSA…”)
🔴 = can’t answer / the answer is “the news”

An afternoon per client gets every vendor rowed and scored. Most first passes come back roughly one-third 🔴 — that’s normal, and it’s also the project pipeline (remediation = change orders, per last week). The free tracker below has the database, the scoring, and the contract-clause checklist — you’re locating and summarizing what’s already in the contract, not giving legal advice.

📥 GB006: the Vendor-Risk 3-Question Tracker (free) →
 

The Boardroom Bridge

Explaining vendor risk without it sounding like someone else’s problem.

When a vendor holding your data gets breached, NIST CSF 2.0 puts the responsibility for that relationship squarely on you — that’s the point of Govern → Supply Chain Risk Management (GV.SC). Here’s how to put it in front of a board without it sounding like someone else’s problem.

The talking point (a literal script for non-technical execs — steal it)

“When a vendor holding our data gets breached, our customers don’t experience it as the vendor’s breach — they experience it as ours. Same phone calls, same trust damage, same regulator questions. So I track three things for every vendor that touches our data: what they hold, what they’ve committed to in writing, and how we’d find out if they failed. Right now we can fully answer that for [X] of [Y] vendors. Closing the gap costs contract-review time, not new software. I’d rather buy that time now than explain the gap during an incident.”

Ownership framing (“their breach is our breach”), a countable metric (X of Y), and a cheap ask. Boards fund cheap asks with countable metrics — and turning a headline into three concrete questions and an honest gap assessment is exactly what a good security lead, vCISO, or compliance owner gets paid for.

 
The Security Gator  //  Quick Poll
30 Seconds
For your top 5 vendors — could you produce the breach-notification window from each contract today?

Pick the one that stings most. Answers shape the next round of playbooks — anonymous, aggregated, no list-building tricks.

All 5 Some I'd be reading contracts at midnight What notification window 😅 Cast Vote →
Anonymous · aggregated   —   thesecuritygator.com
Next week’s Reader Q&A answers the winning option.
 

This week’s tool — AxiomLens

Vendor rows are one slice of the bigger picture — the register, the evidence, the controls, the quarterly story for leadership. AxiomLens holds the whole picture locally: 106 NIST CSF 2.0 subcategories, computed coverage as a number, evidence tied to controls, and a board-ready report written on your machine. Built to be owned, not rented — one-time license, per named user, node-locked, and after a one-time activation it runs fully offline. Nothing phones home. Supports compliance documentation and audit-prep workflows; a tool, not a certification — not legal, compliance, or audit advice.

One-time license — founding pricing while it lasts. Check the store for current numbers.

Watch the walkthrough → youtu.be/namYnNbox4k
Sources: NIST Cybersecurity Framework 2.0 (GV.SC)  |  CISA KEV alert (Jul 27)  |  ITRC H1 2026 Data Breach Report  |  GovTech on the Instructure numbers  |  Instructure incident updates
 
THE SECURITY GATOR  //  BAYOU BYTES  //  EVERY TUESDAY

Reply

Avatar

or to participate

Keep Reading