When you outsource, your data travels with the work. Regulators and customers won't distinguish between your breach and your vendor's breach — so due diligence isn't optional.
Start with certifications: ISO 27001 for information security management, SOC 2 Type II for operational controls, plus domain-specific frameworks — HIPAA for healthcare data, PCI DSS for payments, GDPR for EU personal data. Certifications aren't everything, but their absence is disqualifying.
Then dig into practice: How is access controlled and logged? Are workstations locked down (no USB, no personal devices, clean-desk policies)? Is data encrypted in transit and at rest? How are staff screened and trained? What's the incident response plan, and when was it last tested?
Finally, get it in writing: data processing agreements, breach notification timelines, audit rights, and clear data ownership clauses. A serious provider will welcome the scrutiny — the ones who bristle are telling you everything you need to know.
