After a vendor risk assessment, the critical next step is testing whether the assumptions behind each vendor rating hold for the access the vendor actually receives. Most teams skip this. They treat the rating as a settled input and move straight to access provisioning.
In November 2013, Target Corporation learned what that skip costs. An HVAC contractor rated "low risk" became the entry point for attackers who stole 40 million payment card records. The assessment was right about the contractor's business reliability. It was wrong about what "low risk" meant once the contractor had network access to Target's payment systems.
Vendor risk assessment is the process of evaluating whether a third-party supplier introduces risks that could affect an organisation's operations, data or obligations.
Target, Fazio Mechanical and the assumption nobody checked
Fazio Mechanical Services was an HVAC and refrigeration contractor based in Sharpsburg, Pennsylvania. It serviced Target stores and had been granted network credentials for electronic billing, contract submission and project management.
By the standards of a typical vendor risk assessment, Fazio was unremarkable: a small regional contractor with a limited scope of work and no direct involvement in Target's core retail or payment operations.

The assessment classified Fazio according to business criteria: financial stability, contractual reliability, scope of services rendered. What it did not classify was whether the network access granted to a "low-risk" vendor was itself low risk.
That distinction mattered. Fazio's credentials did not just connect to a billing portal. They opened a path into Target's broader network, including systems adjacent to the point-of-sale environment where payment card data was processed.
In September 2013, attackers sent a phishing email to Fazio Mechanical. Fazio's systems were compromised. Using Fazio's stolen credentials, the attackers moved laterally through Target's network, eventually installing malware on point-of-sale terminals across nearly 1,800 stores.
Between 27 November and 15 December 2013, the 40 million payment card records were exfiltrated. A subsequent investigation revealed that 70 million additional customer records, including names, addresses and phone numbers, were also stolen.
The breach did not originate from a failure of vendor selection or due diligence in the conventional sense. Fazio was a legitimate vendor performing legitimate work. The failure lay in the assumption that a vendor's risk category, based on business attributes, also described the risk created by that vendor's technical access. The vendor risk assessment answered the question it was designed to answer: is this vendor reliable? It did not answer the question that mattered: does this vendor's access create exposure that the assumptions behind the assessment never tested?
The consequences were immediate and severe. Target's CIO Beth Jacob resigned in March 2014. CEO Gregg Steinhafel resigned in May 2014.
The Senate Commerce Committee investigation found that Target had received alerts from its FireEye security monitoring system but had not acted on them. Krebs on Security reporting confirmed that the initial vector was a third-party contractor. Total breach-related costs exceeded $200 million, including settlements, legal fees and system remediation.
The vendor risk assessment had done what vendor risk assessments do. It evaluated the vendor. It did not evaluate the assumptions embedded in the access the vendor was given.
Write down the assumption your highest-rated vendor's network access depends on and ask whether anyone tested it before the credentials were provisioned. Start the Walk →
What vendor risk assessment gets right, and where it stops
Vendor risk assessment is not a broken process. It creates a structured way to evaluate third-party relationships before contracts are signed. It forces procurement and security teams to ask questions about a vendor's financial health, operational history, regulatory compliance and insurance coverage.
For organisations managing hundreds or thousands of vendor relationships, the assessment provides a triage layer that would not otherwise exist.
It also establishes a record. When a vendor relationship deteriorates, the organisation has documented what it evaluated and when. This matters for regulatory obligations, for governance and compliance requirements, and for any post-incident review.
The limitation is not in what vendor risk assessment does. It is in what gets carried forward from its outputs. The assessment produces a rating. That rating becomes a label. The label travels through the organisation without the assumptions behind it.
A vendor rated "low risk" based on financial stability and contractual scope may still hold credentials that, if compromised, give an attacker lateral movement into critical systems. A vendor rated "medium risk" for regulatory exposure may have robust security controls. The rating collapses multiple dimensions into a single category, and the assumptions embedded in that collapse rarely get tested downstream.
Frameworks like NIST SP 800-161 have expanded the scope of third-party evaluation to include supply chain cybersecurity. But even within a broader risk assessment framework, vendor evaluation follows the same pattern: evaluate, rate, classify.
An expanded risk assessment process still produces ratings. Most vendor risk assessments answer the question about the vendor and assume the answer about the organisation's own exposure. The output looks definitive. The assumptions behind it remain invisible until something breaks.
The checkpoint between assessment and action
The gap between a completed vendor risk assessment and whatever action follows is where assumptions go unexamined. The assessment produces its output. Procurement uses the rating to approve, condition or reject the vendor relationship. Security teams set access controls based on the tier. Nowhere in this sequence is there a step that asks: what is being assumed about this rating that has not been verified?
Standard vendor risk assessment
- Evaluates vendor attributes: financial, compliance, operational
- Assigns a risk tier that follows the vendor through procurement
- Reviews on a fixed schedule, typically annual or biennial
- Treats the rating as a settled input to access decisions
With assumption testing
- Tests whether the vendor's access matches the exposure implied by their tier
- Names the assumptions the rating depends on before access is provisioned
- Triggers review when the vendor's integration pattern changes
- Monitors the assumptions behind the rating, not just the vendor's attributes
The five-step Universal Decision-Making Method that Roger Estall and I set out in Deciding provides a practical checkpoint for exactly this gap. The third step, surfacing assumptions, is the one most vendor risk processes skip. It asks the decision-maker to name the specific assumptions the current plan depends on and to test whether each one holds.
Applied to vendor risk assessment, this means pausing after the rating is assigned and before access is provisioned. The questions are concrete: does the vendor's risk tier accurately describe the exposure created by the access they will receive? Does the assessment's scope match the actual integration pattern? Are there assumptions about network segmentation, credential management or monitoring that the assessment did not test?
This is not a second assessment. It is a checkpoint. Five to ten minutes of structured questioning applied to the assumptions that sit between the assessment's output and the organisation's action.
The method's fourth step, determining sufficient certainty, sets a threshold: enough confidence in those assumptions to proceed, not maximum confidence. The fifth step builds monitoring into the decision, so that if an assumption fails, the organisation detects it before the consequences compound.
Target's vendor risk assessment was thorough on its own terms. The missing step was not another assessment. It was the question nobody asked about the assumptions the assessment left embedded in the access decision. That question takes minutes. Its absence cost $200 million.
Due diligence reviews face the same structural gap. So do workplace risk assessments. The assessment does its job. The assumptions behind it need a separate step.
You could rate every vendor and still leave the assumption behind the access exposure each rating depends on untested.
Work through your decisionNo sign-up. Just pick your decision and start.
Grant Purdy is the co-author, with Roger Estall, of Deciding (2020), and the architect of the Universal Decision-Making Method.