Pairs with Gatorbyte #006 (the Vendor Risk 3-Question Tracker) — run this deck against a real vendor row if you have one.
Inject 1 (0:05)
"Your vendor emails: 'We are investigating a security incident. Details to follow.'"
- Who owns this vendor relationship — by name?
- Where is the vendor's register row — what did we answer for Q2 (contract clauses) and Q3 (data touched)?
- What's our first question back to the vendor, and who asks it?
Inject 2 (0:20)
"The news reports it's client data. Your register says this vendor touches three clients."
- What breach-notice window did we agree to in each client contract — where do those contracts live?
- Who tells the clients — and does it happen before or after the vendor confirms scope?
- The PTO test: the vendor relationship owner is unreachable. Proceed.
Inject 3 (0:35)
"Clients start asking: 'Were we affected?' One CCs their lawyer."
- Who owns client comms when it's not our breach but IS our problem?
- What can we say honestly right now — and who approved that language?
- When does OUR counsel get engaged?