Vendor and Third-Party Risk Management for Startups
You inherit your vendors' security whether you assess it or not. Here's how a small team builds a vendor register, tiers suppliers by what they can actually reach, asks for evidence that means something, and keeps the whole thing reviewable — mapped to ISO 27001 A.5.19–A.5.23 and SOC 2 CC9.