October DealsAmazon USOctober deal check: compare before you payAmazon US: current deals, useful picks and tech finds.Check DealsWindows FixRecommendedWindows errors stealing your time? Find the fix fastScan stability, cleanup and performance issues.Fix NowOctober DealsAmazon USDeal season is back - check today's better picksAmazon US: current deals, useful picks and tech finds.See Picks×
Skip to content
The Finance Base
The Money Desk · Blog
Re:

How to Handle IT Vendors’ Worst Bad Habits

A practical process for addressing IT vendor failures: document the pattern, prioritize its impact, seek verifiable remediation, and plan an orderly exit if needed.
From TheFinanceBase Team5 min to read

What’s actually slowing this PC down?

Pick the symptom - the matching free tool is one click away.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

When an IT vendor repeatedly misses commitments, obscures security information, or makes it hard to retrieve your data, treat the behavior as a business risk—not just a frustrating service problem. Record what happened, rank the potential harm, compare performance with your agreement, and ask for a corrective plan with named owners and verifiable milestones. If the risk remains unacceptable, prepare a controlled transition rather than making a rushed exit.

Which vendor problems deserve attention first?

“Worst bad habits” is a conversational label, not a formal industry taxonomy. Focus on observable patterns rather than assuming every vendor behaves badly. A missed call is different from a recurring failure to report a security incident or provide records your business needs.

Prioritize by potential impact and urgency. CISA advises leaders to focus on the “critical few” risks instead of trying to remediate everything at once. That is a useful way to organize your response, not a universal ranking of vendor problems. See CISA’s guidance on bad practices.

  • Security or privacy exposure: unexplained access, unresolved vulnerabilities, missing incident information, or uncertainty about how sensitive data is handled.
  • Service continuity: outages, repeated missed service commitments, or a failure that could interrupt essential operations.
  • Loss of visibility or control: inaccessible records, unclear responsibility for a task, or missing information about subcontractors and system access.
  • Exit barriers: data, credentials, integrations, or essential processes that cannot readily be moved or maintained elsewhere.

For each concern, note dates, commitments, outcomes, and business effects. A short record of repeated missed deadlines is more actionable than a general complaint that a vendor is “unresponsive.”

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

How should you assess the vendor’s performance?

Start with the agreement and the evidence

Compare what happened with the service description and commitments already agreed. Check the relevant terms for scope, response and escalation processes, security commitments, reporting, subcontractors, and transition duties. These are review prompts, not a universal list of contractual requirements or legal advice.

Separate facts you can verify from assumptions. For example, record the date you requested an incident update and what information was supplied; do not conclude that a vendor concealed an incident unless evidence supports that claim.

Use repeatable questions

A consistent assessment makes it easier to identify gaps and compare vendors. CISA’s small- and medium-sized business supplier-assessment fact sheet offers sample topics including security and privacy policies, asset management, network access, contractual obligations, incident detection, and recovery. Use its supplier assessment fact sheet to shape questions appropriate to your service and risk.

For a managed service provider (MSP), ask what security requirements apply, how subcontractors are vetted, and whether you can access relevant security logs and telemetry. CISA identifies these as visibility areas for MSP customers in its guidance on risks for MSP customers.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Ask security questions across the software lifecycle

Software risk does not end at purchase. Ask how the vendor handles vulnerabilities and patches, what incident-notification process applies, and whether it can provide relevant information about software components. NIST’s guidance discusses acquisition, use, and maintenance of third-party software, including component inventories, vendor assessments, and vulnerability management. Its stated audience and scope are federal agencies; it is not a universal legal mandate for all buyers. Read NIST’s software supply-chain guidance.

What should a corrective plan include?

Describe the gap in concrete terms, refer to the applicable commitment where relevant, and ask the vendor to respond in writing. A workable plan should make responsibility and progress checkable.

  • Issue and impact: the specific missed deliverable, unresolved concern, or information gap, with dates and business consequences.
  • Owner: a named person on each side who is responsible for next steps.
  • Actions and milestones: what will change and when, including interim safeguards if needed.
  • Evidence: how completion will be demonstrated, such as a report, updated procedure, or agreed service record.
  • Review date: when both sides will assess progress and decide whether further escalation is necessary.

For a security issue, tailor the requested evidence to the risk: vulnerability handling, patch progress, incident updates, or relevant component information. Avoid asking for sensitive records without considering how they can be shared and protected.

How can you reduce dependence on a difficult vendor?

Integration can improve agility, productivity, operations, and management, but it can also make a service harder to replace. Gartner’s public abstract on cloud lock-in frames this as a risk to assess alongside those benefits; it does not prescribe specific contract terms. See Gartner’s cloud lock-in abstract.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Map the practical dependencies before a dispute becomes urgent:

  • Which systems, business processes, and integrations rely on the vendor?
  • Where is your data, and what export formats and access methods are available?
  • Who controls administrator credentials, encryption keys, and service accounts?
  • Which proprietary components or subcontractors could complicate a replacement?
  • What would operations need to continue during an outage or transition?

Review any existing data-portability, access, and transition provisions, and identify what would need to be arranged if service ends. The goal is to understand the effort and continuity risks of a change; integration alone does not mean a service is harmful.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

When and how should you escalate or switch?

Escalate in proportion to the risk. Use the agreement’s escalation process and involve the people responsible for security, procurement, operations, or legal review as appropriate. Keep a dated record of communications, decisions, and promised actions.

If the vendor does not remediate the issue or the remaining risk is unacceptable, evaluate a managed transition. Confirm what data and records must be retrieved, who will maintain critical operations, and how access will be handled during the change. Do not terminate unilaterally without reviewing the agreement and applicable law; a qualified adviser can assess legal remedies and notice requirements.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

How to compare a replacement vendor

Use the same practical criteria for each candidate, tailored to the service and the consequences of failure. These dimensions synthesize the cited guidance; they are not a universal scoring model.

Dimension Questions to ask
Security evidence Can the vendor explain its vulnerability disclosure and patch process, incident handling, relevant audit evidence, and availability of software component information?
Operational accountability Is the service scope clear? Are commitments measurable, escalation contacts identified, reporting cadence defined, and responsibility boundaries understood?
Dependency and exit Can you export data in a usable form? What proprietary components or integrations could complicate a move, and what transition support is available?
Supplier visibility Will the vendor disclose relevant subcontractors and provide access to records or telemetry needed to oversee the service?

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

Leave a Reply

Your email address will not be published. Required fields are marked *

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

More post from the Money Desk

  1. The Money DeskBlogTheFinanceBase09 OCT 267 minMortgage Escrow FAQs: Taxes, Insurance, Shortages, and Refunds
  2. The Money DeskBlogTheFinanceBase09 OCT 265 minHow Mortgage Escrow Accounts Work and What Homeowners Pay For
  3. The Money DeskBlogTheFinanceBase09 OCT 265 minHow to Read a Stock Chart, Volume and Market-Cap Data
Recommended PC Tool
Recommended PC Tool
PC Slower Than It Used to Be?Free scan - under a minute
Outdated Drivers Are Slowing You DownFree scan - exact matches

Two free Windows tools

One Free Minute Could Fix That PC

Before you go - each of these free tools takes about a minute and tackles what quietly slows a Windows PC down.

Special offer. View Outbyte info, uninstall instructions, EULA, and Privacy Policy.