The news that a Verizon Communications Inc. vendor exposed millions of customer records has highlighted the serious risks related to trusting third-party vendors with company data.

When there's a breach or data is exposed, no matter where it originates, the responsibility often comes back to the company, said current and former in-house counsel, so legal departments must ensure that they conduct proper third-party vendor due diligence.

On June 8, a cyber risk analyst at cybersecurity company UpGuard Inc. discovered that millions of Verizon customer records were unprotected on a storage server controlled by an employee of third-party vendor NICE Systems. The exposed information—which included customer names, addresses, phone numbers and account personal identification numbers—was generated from customer service calls from January through June of this year and was downloadable by anyone who accessed it. According to UpGuard, Verizon was notified of the exposure on June 13 and the data was secured on June 22.