Slide 22 of 28
Part 4 · PreventionSlide 22
Slide 22 · MIT 04
Security due diligence — evaluate a vendor’s security before integrating.
A vendor breach becomes your breach. Evaluate their security as part of every integration decision.
What to evaluate

Before integrating a third-party API, evaluate the vendor’s security posture: their disclosure and incident response history, whether they have published SOC 2 Type II or ISO 27001 certifications, how they handle CDN file integrity, and their data handling practices. This due diligence is not a guarantee — it’s a baseline that filters out vendors with known poor practices.

📄
Review security certifications and attestations
Ask vendors for SOC 2 Type II reports, ISO 27001 certifications, or penetration test summaries. A vendor who refuses to share any security documentation is a red flag. SOC 2 Type II in particular attests to security controls over a period of time — not just a point-in-time assessment.
🔍
Research public incident history
Search for past security incidents involving the vendor: breaches, CVEs, or CDN compromises. Inbenta had not published a security breach prior to the Ticketmaster incident — but researching their CDN hosting, script integrity practices, and security controls would have revealed gaps. Public bug bounty programs are a positive signal: vendors who run bug bounty programs are more likely to have a mature security response process.
📋
Include third-party security in vendor contracts
Contracts with third-party API vendors should include: security requirements (encryption, access controls), incident notification timelines (notification within 24-72 hours of a suspected breach), and right-to-audit clauses. A contract doesn’t prevent breaches — but it creates accountability and ensures timely notification so you can respond before the impact expands.
💼 Business takeaway

Before signing a contract with a third-party API vendor, ask them for a SOC 2 Type II report or equivalent security certification. Also ask how they would notify you if their service was breached — and how quickly. Ticketmaster ran a compromised script for four months before a bank spotted the fraud.

← Back MIT 05: Subresource Integrity →