If you’ve worked in IT for more than a few years, you’ve probably noticed that vendor conversations have changed.
There was a time when choosing a vendor mostly came down to whether they could solve the problem, fit the budget, and provide good support. Security was certainly part of the conversation, but not always.
Today, it’s hard to imagine signing a contract without discussing security.
Organizations ask about independent audits, cyber insurance, data protection practices, incident response plans, and the standards a vendor follows. Procurement teams, legal departments, compliance officers, and IT all have a seat at the table.
Personally, I think that’s a healthy change.
One thing the last decade has taught us is that organizations don’t operate in isolation anymore. Very few companies build every application they use, host every workload themselves, or manage every aspect of their technology internally. Modern IT depends on partnerships, and that’s unlikely to change anytime soon.
Vendor Risk Looks Different Than It Used To
One thing I’ve found interesting is how our definition of a “critical vendor” has expanded.
Years ago, most conversations centered around the companies that connected directly to your environment. Cloud providers, managed service providers, software vendors, and anyone with remote access naturally received the most attention.
Those companies still deserve that scrutiny. At the same time, organizations are beginning to ask similar questions of vendors that aren’t traditionally viewed as cybersecurity companies. Security isn’t determined solely by who can log into your network. It’s also influenced by who handles your information, your equipment, and your business processes.
That’s a much broader way of looking at risk than many of us were talking about ten years ago.
Every Step of the Technology Lifecycle Matters
One example that doesn’t get discussed as often as it should is what happens after equipment is retired.
Replacing hardware is a routine part of IT. Every organization eventually upgrades laptops, replaces servers, refreshes storage, and decommissions networking equipment.
From an operational standpoint, that project feels complete once the new equipment is installed. From a governance and security perspective, however, there’s still work to do.
Equipment still has to be inventoried, transported securely, sanitized, documented, and ultimately reused or responsibly recycled. Those responsibilities don’t disappear simply because a device has been unplugged. If anything, they’re simply transitioning to another phase of the technology lifecycle.
In many organizations, those activities are handled by another vendor. Like any other business relationship, that comes with its own processes, expectations, and level of accountability.
The Bigger Picture
I don’t think the lesson is that organizations should become skeptical of every vendor they work with. If anything, I think the opposite is true.
Organizations have become much better at building strong partnerships with companies they trust. The difference today is that trust is supported by better questions, better documentation, and better processes than it was a decade ago.
That’s good for everyone involved. As technology continues to evolve, I expect those conversations will continue evolving too. Vendor management is no longer just about finding someone who can do the job. It’s about finding partners who can earn and maintain your trust.
As organizations continue strengthening their vendor management programs, it’s worth taking a fresh look at every company that handles your technology—not just the ones that connect to your network. If you’re evaluating your IT asset disposition process, ask the same questions you would ask any other critical vendor. How is equipment tracked? How is data sanitized? What certifications do they maintain? Can they provide documented chain of custody and audit-ready reporting?
Those are conversations we have every day at SEAM. Whether you’re reviewing your current ITAD provider or simply looking to strengthen your existing process, we’re always happy to share what we’ve learned and help organizations understand what good looks like.
Clint Parsons is the Director of Strategy and Information at SEAM, specializing in building partnerships with businesses of all sizes. He ensures clients effectively navigate secure data destruction, responsible recycling, and maximize the resale value of their IT equipment while staying compliant with evolving regulations.