{"id":11258,"date":"2026-08-07T08:35:34","date_gmt":"2026-08-07T14:35:34","guid":{"rendered":"https:\/\/attentionmedia.io\/?p=11258"},"modified":"2026-08-07T08:35:34","modified_gmt":"2026-08-07T14:35:34","slug":"6-steps-to-protect-your-data-from-being-stolen-by-vendors","status":"publish","type":"post","link":"https:\/\/attentionmedia.io\/?p=11258","title":{"rendered":"6 steps to protect your data from being stolen by vendors"},"content":{"rendered":"<div><img fetchpriority=\"high\" decoding=\"async\" width=\"800\" height=\"450\" src=\"https:\/\/martech.org\/wp-content\/uploads\/2026\/08\/Data-security-padlock-800x450.png\" class=\"attachment-large size-large wp-post-image\" alt=\"A large, shiny silver padlock with red glowing highlights sits in the center, surrounded by a background grid of various smaller blue data and technology icons on a dark blue surface.\" \/><\/div>\n<p class=\"wp-block-paragraph\">Marketers have spent years defending against hackers, but the bigger risk may come from the software marketers use. Now that research has found <a href=\"https:\/\/martech.org\/is-your-intent-data-being-sold-to-your-competitors\/\" target=\"_blank\" rel=\"noopener\">martech vendors routinely taking companies\u2019 customer data<\/a>, marketers must put an end to it.<\/p>\n<p class=\"wp-block-paragraph\">That will require a sea change in how marketers think about vendors and solutions. It starts with understanding that every new integration is a security issue \u2014 not simply a software purchase. They need to apply the same discipline to approving software that they apply to approving campaigns: know what it\u2019s supposed to do, verify that it does only that, and review it regularly.<\/p>\n<p class=\"wp-block-paragraph\">Here are six steps to make that happen.<\/p>\n<h2 class=\"wp-block-heading\">Step 1: Understand what you\u2019re authorizing<\/h2>\n<p class=\"wp-block-paragraph\">Most marketers don\u2019t think of clicking \u201cauthorize\u201d as a security issue. But it is, and it\u2019s a big one. The failure to do that is where the problem begins.<\/p>\n<p class=\"wp-block-paragraph\">\u201cWhen we\u2019re talking about marketers and sales professionals, they \u2026 are not technical enough to know that there are red flags even happening that they should be aware of,\u201d said Clark Barron, founder of Blackout.<\/p>\n<p class=\"wp-block-paragraph\">Most marketers don\u2019t fully understand what they\u2019re approving when they connect a new application. The vendors pitch themselves as partners and, as long as the solution worked, marketers had no reason to question that.<\/p>\n<p class=\"wp-block-paragraph\">Depending on the permissions granted, a vendor may gain access to CRM records, sales pipelines, customer support tickets, internal emails, and other sensitive business information. It\u2019s also common to store employee and executive contacts in the same systems, so a single authorization can expose enterprise-scale amounts of information.<\/p>\n<p class=\"wp-block-paragraph\">And adding AI makes those problems bigger and faster.\u00a0<\/p>\n<p class=\"wp-block-paragraph\">Connecting an MCP server isn\u2019t just adding another tool \u2014 it\u2019s giving an external system access to work alongside your AI environment. Before approving that connection, marketers should understand what instructions the integration gives the AI model, what information it can access, and what actions it can take. The answers to those questions are rarely visible by default, so vendors must be required to disclose them as part of the approval process. If you don\u2019t know what\u2019s \u201cin the box,\u201d you can\u2019t know what the AI is being told to do.<\/p>\n<h2 class=\"wp-block-heading\">Step 2: Inventory every integration<\/h2>\n<p class=\"wp-block-paragraph\">Before reviewing permissions, organizations should know which applications are connected to their marketing stack, who approved them, why they were installed, and which systems they can access. Get rid of old integrations, abandoned applications, and duplicated tools before they become security liabilities.<\/p>\n<p><a href=\"https:\/\/www.semrush.com\/enterprise\/seo\/?utm_campaign=ic_mt_0101enterprise&amp;utm_source=martech.org&amp;utm_medium=referral\" target=\"_blank\"><\/a><\/p>\n<div>\n<div>\n<div class=\"headline-responsive\">\n        10X your SEO with <span>Semrush for Enterprise<\/span>.\n      <\/div>\n<p>\n        The world\u2019s most powerful SEO platform, purpose-built for Enterprise.\n      <\/p>\n<\/div>\n<div>\n      <span>Request demo<\/span>\n    <\/div>\n<\/div>\n<p>    <\/p>\n<h2 class=\"wp-block-heading\">Step 3: Ensure vendors have only the access they need<\/h2>\n<p class=\"wp-block-paragraph\">Marketers must learn to ask vendors hard questions and adopt an adversarial mindset.\u00a0<\/p>\n<p class=\"wp-block-paragraph\">\u201cVerify first, and then trust,\u201d said Barron. \u201cWhen it comes to authorizing connections to your database, all of these vendors that are asking for access to your company\u2019s information ask them. Push them. And actually get it in writing.\u201d<\/p>\n<p class=\"wp-block-paragraph\">Doing that means marketers must learn everything they can about how digital processing agreements are drafted, how they work, and what a sub-processor actually is.\u00a0<\/p>\n<p class=\"wp-block-paragraph\">\u201cLearn about data brokerage practices and how that entire ecosystem works versus how it\u2019s presented,\u201d he said. \u201cBecause how it\u2019s presented is nonsense. It\u2019s just marketing fluff.\u201d<\/p>\n<p class=\"wp-block-paragraph\">Barron recommends starting every vendor review with six practical checks:<\/p>\n<ul class=\"wp-block-list\">\n<li>Restrict read and write access to CRM objects such as pipelines and deals unless absolutely necessary.<\/li>\n<li>Block access to internal employee and executive records.<\/li>\n<li>Review Gmail and Outlook extensions that bridge inboxes and CRM systems.<\/li>\n<li>Monitor persistent access tokens that indicate long-term vendor access.<\/li>\n<li>Restrict access to customer support tickets and internal service records.<\/li>\n<li>Closely examine vendors that bypass official application marketplaces through custom OAuth implementations.<\/li>\n<\/ul>\n<h2 class=\"wp-block-heading\">Step 4: Use AI to audit AI<\/h2>\n<p class=\"wp-block-paragraph\">Marketers don\u2019t need to read source code to perform a first-pass security review. Chris Penn, co-founder and chief data scientist at Trust Insights, says AI can do much of the work before security teams become involved.<\/p>\n<p class=\"wp-block-paragraph\">\u201cSo what companies, marketers, and everybody should be saying is, \u2018What is in the box, and can I get a copy of it?\u2019\u201d he said. [Tell the vendor,] \u201c\u2018You have to send me the prompts for your MCP that you\u2019re running. You just have to.\u2019 It\u2019s part of governance.\u201d<\/p>\n<p class=\"wp-block-paragraph\">He recommends using the <a href=\"https:\/\/owasp.org\/www-project-top-10-for-large-language-model-applications\/\" target=\"_blank\" rel=\"noopener\">OWASP Top 10 for Large Language Model Applications<\/a> as the baseline for evaluating every AI integration. \u201cAsk your security team about it, Google it, and get it off the internet. And that is your checklist for \u2018Is this thing risky?\u2019\u201d<\/p>\n<p class=\"wp-block-paragraph\">Penn says marketers can also use AI to review vendor documentation against security checklists and then forward the results to security teams.<\/p>\n<p class=\"wp-block-paragraph\">\u201cIf you don\u2019t have a security team of any kind, this at least gets you like 70% of the way there. It helps you eliminate the obvious risks.\u201d<\/p>\n<h2 class=\"wp-block-heading\">Step 5: Make security part of every software purchase<\/h2>\n<p class=\"wp-block-paragraph\">Marketing teams can\u2019t evaluate new software on their own because it requires skills and knowledge they don\u2019t have. Every application that connects to CRM systems, AI platforms, or customer data should be reviewed by marketing, information security, procurement, and legal before it\u2019s approved.<\/p>\n<p class=\"wp-block-paragraph\">That review doesn\u2019t need to slow down software adoption, but it should answer a consistent set of questions. What data will the application access? What permissions is it requesting? Does it use subprocessors? If it\u2019s an AI integration, what instructions are built into its MCP server? If those questions can\u2019t be answered, the software shouldn\u2019t be connected until they can.<\/p>\n<p class=\"wp-block-paragraph\">By making security review part of every martech purchase, organizations shift vendor approval from an individual marketing decision to a repeatable governance process. That helps catch unnecessary permissions, undocumented AI behavior, and undisclosed data sharing before a new application ever reaches production.<\/p>\n<h2 class=\"wp-block-heading\">Step 6: Make vendor audits continuous<\/h2>\n<p class=\"wp-block-paragraph\">Installing an application must be the beginning of governance, not the end.<\/p>\n<p class=\"wp-block-paragraph\">Permissions change. Terms of service change. Vendors add new features. MCP servers evolve. Software updates introduce new capabilities and new risks. There must be a system to regularly review every connected application, confirm that its permissions remain appropriate, remove unused integrations, and require vendors to explain any changes before expanding access to company data.<\/p>\n<h2 class=\"wp-block-heading\">The bottom line<\/h2>\n<p class=\"wp-block-paragraph\">Marketing software is a critical part of business infrastructure. It deserves the same level of oversight as finance systems, HR platforms, and enterprise applications.<\/p>\n<p class=\"wp-block-paragraph\">As Clark Barron said, \u201cVerify first, and then trust.\u201d<\/p>\n<p class=\"wp-block-paragraph\">Penn says marketers now have everything they need to follow that advice.<\/p>\n<p class=\"wp-block-paragraph\">\u201cThere is no excuse now, given today\u2019s agentic tools, the smartest models we have, open weights models, and deep research tools. There is no excuse for any marketer to install unsafe software anymore without at least a cursory audit with things like the OWASP Top 10 LLM risks.\u201d<\/p>\n<p>The post <a href=\"https:\/\/martech.org\/6-steps-to-protect-your-data-from-being-stolen-by-vendors\/\">6 steps to protect your data from being stolen by vendors<\/a> appeared first on <a href=\"https:\/\/martech.org\/\">MarTech<\/a>.<\/p>","protected":false},"excerpt":{"rendered":"<p>Marketers have spent years defending against hackers, but the bigger risk may come from the software marketers use. Now that research has found martech vendors routinely taking companies\u2019 customer data, marketers must put an end to it. That will require a sea change in how marketers think about vendors and solutions. It starts with understanding &hellip; <\/p>\n<p class=\"link-more\"><a href=\"https:\/\/attentionmedia.io\/?p=11258\" class=\"more-link\">Read more<span class=\"screen-reader-text\"> &#8220;6 steps to protect your data from being stolen by vendors&#8221;<\/span><\/a><\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[1],"tags":[],"class_list":["post-11258","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-uncategorized"],"featured_media_urls":{"thumbnail":["https:\/\/martech.org\/wp-content\/uploads\/2026\/08\/Data-security-padlock-800x450.png",0,0,false],"medium":["https:\/\/martech.org\/wp-content\/uploads\/2026\/08\/Data-security-padlock-800x450.png",0,0,false],"medium_large":["https:\/\/martech.org\/wp-content\/uploads\/2026\/08\/Data-security-padlock-800x450.png",0,0,false],"large":["https:\/\/martech.org\/wp-content\/uploads\/2026\/08\/Data-security-padlock-800x450.png",0,0,false],"1536x1536":["https:\/\/martech.org\/wp-content\/uploads\/2026\/08\/Data-security-padlock-800x450.png",0,0,false],"2048x2048":["https:\/\/martech.org\/wp-content\/uploads\/2026\/08\/Data-security-padlock-800x450.png",0,0,false],"inspiro-featured-image":["https:\/\/martech.org\/wp-content\/uploads\/2026\/08\/Data-security-padlock-800x450.png",0,0,false],"inspiro-loop":["https:\/\/martech.org\/wp-content\/uploads\/2026\/08\/Data-security-padlock-800x450.png",0,0,false],"inspiro-loop@2x":["https:\/\/martech.org\/wp-content\/uploads\/2026\/08\/Data-security-padlock-800x450.png",0,0,false],"portfolio_item-thumbnail":["https:\/\/martech.org\/wp-content\/uploads\/2026\/08\/Data-security-padlock-800x450.png",0,0,false],"portfolio_item-thumbnail@2x":["https:\/\/martech.org\/wp-content\/uploads\/2026\/08\/Data-security-padlock-800x450.png",0,0,false],"portfolio_item-masonry":["https:\/\/martech.org\/wp-content\/uploads\/2026\/08\/Data-security-padlock-800x450.png",0,0,false],"portfolio_item-masonry@2x":["https:\/\/martech.org\/wp-content\/uploads\/2026\/08\/Data-security-padlock-800x450.png",0,0,false],"portfolio_item-thumbnail_cinema":["https:\/\/martech.org\/wp-content\/uploads\/2026\/08\/Data-security-padlock-800x450.png",0,0,false],"portfolio_item-thumbnail_portrait":["https:\/\/martech.org\/wp-content\/uploads\/2026\/08\/Data-security-padlock-800x450.png",0,0,false],"portfolio_item-thumbnail_portrait@2x":["https:\/\/martech.org\/wp-content\/uploads\/2026\/08\/Data-security-padlock-800x450.png",0,0,false],"portfolio_item-thumbnail_square":["https:\/\/martech.org\/wp-content\/uploads\/2026\/08\/Data-security-padlock-800x450.png",0,0,false]},"_links":{"self":[{"href":"https:\/\/attentionmedia.io\/index.php?rest_route=\/wp\/v2\/posts\/11258","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/attentionmedia.io\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/attentionmedia.io\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/attentionmedia.io\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/attentionmedia.io\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=11258"}],"version-history":[{"count":0,"href":"https:\/\/attentionmedia.io\/index.php?rest_route=\/wp\/v2\/posts\/11258\/revisions"}],"wp:attachment":[{"href":"https:\/\/attentionmedia.io\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=11258"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/attentionmedia.io\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=11258"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/attentionmedia.io\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=11258"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}