The exposure analysis is done. The number is 18%. The expected loss if exposed is $400K. Total risk exposure: $72K. The CISO walks into the room and says: "OK, what do we do?"
This is where most vendor incident response programs collapse. The exposure analysis produces a number; the response decision is then made by the most senior person in the room, based on judgment, with rationale that may or may not survive Monday morning. Two decision-makers facing the same exposure number reach different conclusions because there's no framework that translates the number into an action — and neither can defend the choice in audit.
This piece is that framework. Four response options, evaluated against a single risk-adjusted cost criterion, producing a defensible recommendation rather than a judgment call. Plus the decision anti-patterns that derail otherwise-good processes when the pressure is on.
The four response options
Every vendor incident response decision lives in one of four buckets. The names matter; the boundaries matter; the cost structure of each matters.
The four-option framing forces consideration of the middle options. Most ad-hoc decisions default to "Accept" or "Exit" — the two endpoints. The interesting decisions for most vendor incidents live in the middle, in Mitigate and Reduce, where the cost-and-residual-risk math actually produces the lowest risk-adjusted total.
The decision rule — risk-adjusted cost
The decision criterion is simple: pick the option that minimizes risk-adjusted cost.
RiskAdjustedCost(option) = DirectCost(option) + λ · ExpectedResidualRisk(option)
Where:
• DirectCost is the cost of implementing the option
• ExpectedResidualRisk is the residual exposure expressed in dollar terms
• λ is the organization's risk aversion coefficient (derived from stated risk tolerance)
For most mid-market organizations, λ ≈ 1 (you treat $1 of residual risk as roughly equivalent to $1 of direct cost). Risk-averse organizations use λ > 1 (you'd pay $1.50 to avoid $1 of residual risk). The right λ for your organization comes from your stated risk tolerance, not from a default.
Worked through on the Okta example from the exposure analysis (P(Exposed) = 0.18, E[LM] = $400K, so risk exposure = $72K):
Recommendation: Mitigate. Lowest risk-adjusted total. Direct cost $30K for credential rotation and enhanced monitoring. Residual risk $25K. Total $55K — meaningfully better than Accept's $72K and dramatically better than Reduce ($236K) or Exit ($800K).
The tolerance gap — when "lowest risk-adjusted cost" isn't the only criterion
Risk-adjusted cost is the primary criterion. But it's not the only one. The organization's stated risk tolerance for vendor-related exposure sets a ceiling that the chosen option's residual risk must respect.
If the chosen option's residual risk exceeds the organization's stated tolerance for vendor exposure, the option fails the tolerance test regardless of its risk-adjusted-cost ranking. Example: if your stated tolerance is "no single vendor incident should produce >$50K residual exposure" and Mitigate's residual is $25K, Mitigate passes. If your tolerance is "no residual >$20K" and Mitigate's residual is $25K, Mitigate fails — and Reduce or Exit becomes the right choice even at higher direct cost.
The tolerance gap is what prevents the framework from producing decisions that are mathematically optimal but strategically unacceptable. The CFO might tolerate $72K of residual risk for an Accept; the board might not. The board's tolerance is the binding constraint, not the CFO's.
When the numbers don't decide for you
Three classes of situation where the math is close enough that judgment matters:
Two options are within 15% of each other on risk-adjusted total
The math says they're roughly equivalent. Use secondary criteria: vendor relationship quality, exit cost trajectory if you delay, regulatory disclosure implications, customer-facing communication implications. The framework didn't fail — it correctly identified that the choice is between near-equivalents, which is information you needed.
The exposure estimate has wide uncertainty bounds
If the confidence interval on exposure spans 5% to 35%, the risk-adjusted-cost calculations are themselves uncertain. The choice between options may flip depending on which end of the interval you operate from. The right response is usually to delay the decision 24–48 hours for new information, or to choose the option whose ranking is robust across the interval.
The vendor's incident response quality is itself a factor
A vendor that's communicating well, providing IOCs, narrowing scope quickly, and engaging substantively with customers earns a lower implicit risk premium for Accept and Mitigate. A vendor that's stonewalling or obviously trying to minimize the incident earns a higher one — and may push the decision toward Reduce or Exit even when the immediate math doesn't quite get there.
Documenting the decision — what survives the audit
The decision rationale is what makes the recommendation auditable. Five elements, captured in one page or less:
Exposure assessment summary
The exposure probability, expected loss if exposed, and risk exposure number from the conditional analysis. Reference to the analysis worksheet, not duplication of it.
Risk tolerance comparison
The organization's stated tolerance threshold, the residual risk of the chosen option, and whether the option passes or has an explicit tolerance gap that requires acceptance at a specific level.
Cost-benefit comparison
The risk-adjusted cost for each of the four options, the chosen option, and a one-line rationale per non-chosen option ("Reduce was not chosen because…"). The rejected options need named reasons.
Committed mitigations
If Mitigate, the specific controls being implemented, owners, due dates, completion criteria. If Reduce or Exit, the migration milestones and rough timeline.
Review triggers
What conditions cause the decision to be revisited: next vendor incident, completion of committed mitigations, expiry of a defined timeframe (e.g., "reassess in 6 months"), or specific external events (regulatory change, new IOCs).
The decision anti-patterns to avoid
Even with the framework, certain failure modes recur. Recognizing them in real time is the difference between a defensible decision and one that gets reversed under scrutiny.
The second-incident test — does the decision survive history?
One useful test for the chosen option: does this decision survive comparison against past decisions at the same vendor?
If you chose Accept for the same vendor's prior incident six months ago, and you're now choosing Mitigate for a comparable incident, the change requires explicit justification. Either the vendor's pattern has shifted (new failure mode, escalating severity, prior mitigations incomplete) or your tolerance has shifted (new regulatory pressure, changed business context) — but one of those should be true. If neither is true, the framework is flagging an inconsistency that needs to be resolved before the decision is finalized.
The consistency check requires institutional memory — the prior decision record retained, queryable at the time of the next incident. Without that memory, the consistency check can't run; the second incident is decided in isolation; the pattern across incidents at the same vendor is invisible. The institutional memory dimension is what makes the second-incident test possible, and what makes the next incident at the same vendor easier rather than harder.
Putting it together — the one-page decision brief
1. INCIDENT SUMMARY — vendor, incident type, disclosure date, current status.
2. EXPOSURE ASSESSMENT — P(Exposed) with confidence interval, expected loss if exposed, risk exposure, comparison to tolerance ceiling.
3. DECISION OPTIONS — table of four options with cost, residual risk, risk-adjusted total, fit to tolerance.
4. RECOMMENDATION — chosen option, one-paragraph rationale, named reasons for not choosing each other option.
5. MITIGATIONS (if applicable) — immediate, near-term, long-term actions with owners and dates.
6. REVIEW TRIGGERS — next assessment condition or date; escalation criteria; what would cause reversal.
One page. Goes to the CISO, GC, and (for material incidents) the board. Becomes the audit trail for SEC examiner, regulator, customer trust review, and the decision-history record that informs the next incident at this vendor.
The bottom line
Four options. One decision criterion. Five anti-patterns to avoid. The framework converts vendor incident response from a judgment call by the most senior person in the room into a defensible recommendation grounded in the organization's own risk tolerance, comparable across incidents, and capable of surviving both Day-1 stakeholder pressure and Year-3 regulator review. The math is straightforward once the exposure analysis is done; the discipline is the framework itself.
Run the decision framework on real incidents, with real institutional memory
vCISO Lite operationalizes the four-option vendor incident decision framework — pre-computing risk-adjusted cost across Accept, Mitigate, Reduce, and Exit based on your stated risk tolerance, surfacing the named comparison against prior decisions at the same vendor, tracking committed mitigations to completion, and producing the one-page decision brief in the format the CISO and the board need. Built for the 33 million US small and mid-sized businesses that don't have a CISO yet, and for the enterprises whose CISOs are tired of defending vendor incident decisions on judgment alone.
If your team makes vendor incident decisions from gut feel and you want the next one to survive the audit, visit vcisolite.com to learn more and get started.
Where this matters next
Someone else's breach: why vendor IR is its own discipline — the strategic context for why the decision framework exists as a distinct methodology rather than as a TPRM addendum.
Conditional exposure analysis: why your risk isn't what the vendor reported — the upstream analysis that produces the exposure number the decision framework consumes.
Mitigation debt: the silent risk that accumulates between vendor incidents — the downstream institutional-memory dimension that determines whether the mitigations chosen by this framework actually ship and reduce risk over time.
Are we affected? The sixty-minute triage for vendor incidents — the fast-path through the three questions that produces the exposure number the decision framework consumes.
Vendor concentration risk: the dimension per-vendor TPRM misses — the standing-program lens that informs the Exit option. An Exit decision is materially harder when the alternative vendors share the same upstream as the one you're leaving.
Third-party risk management: the complete guide — the standing TPRM program companion. The vendor tier and assessment depth recorded by the standing program determine how much friction an Exit decision will actually carry through procurement and integration.
Where this matters next
Someone Else's Breach: Why Vendor Incident Response Is Its Own Discipline — Traditional risk assessment asks what might happen
Mitigation Debt: The Silent Risk That Accumulates Between Vendor Incidents — Eighteen months ago you committed to controls after a vendor incident. Today the same vendor has another one
Conditional Exposure Analysis: Why Your Risk Isn't What the Vendor Reported — FAIR estimates whether a loss event will occur. Vendor incidents: the loss event already occurred
Third-Party Risk Management for Growing Companies — Your vendors are your risk. Here's how to assess, tier, and manage third-party security without drowning in questionnaires