Key Takeaways
- Third-party involvement in confirmed breaches doubled from 15% to 30% year over year, so a vendor's controls now sit inside your attack surface (Verizon 2025 DBIR).
- The average U.S. breach reached a record $10.22 million in 2025, more than double the $4.44 million global average (IBM Cost of a Data Breach Report 2025).
- Healthcare breaches averaged $7.42 million and took 279 days to identify and contain, the longest of any industry studied (IBM, 2025).
- The median time to remediate leaked secrets discovered in a GitHub repository was 94 days, which makes secrets handling a first-order question for any vendor with repository access (Verizon 2025 DBIR).
- Organizations with high levels of unapproved "shadow AI" paid an average of $670,000 more per breach, and 63% of breached organizations had no finished AI governance policy (IBM, 2025).
- Under HIPAA, a business associate must notify the covered entity of a breach no later than 60 days after discovery, so your contract should set a shorter clock (HHS Breach Notification Rule).
Why vendor security is now a C-Suite question
Your vendor's controls are part of your attack surface. That used to be a theoretical point made in risk workshops. It is now a measured one. Verizon's 2025 report analyzed 22,052 security incidents, 12,195 of them confirmed breaches, and found that third-party involvement doubled from 15% to 30% (Verizon 2025 DBIR). The report's authors describe software vendors shifting over two to three years from an occasional, moderate source of trouble to a widespread one.
The cost side moved in the same direction for U.S. buyers. IBM's 2025 study, conducted by the Ponemon Institute across 600 breached organizations, put the global average cost of a breach at $4.44 million, the first decline in five years. The U.S. average went the other way, to a record $10.22 million (IBM Cost of a Data Breach Report 2025). A CTO signing a vendor agreement is, in effect, underwriting part of that exposure.
The common assumption is that a nearshore team in Latin America adds risk because it sits in another country. Geographical proximity is the wrong variable. A contractor in Ohio with a personal laptop, a shared credential and no offboarding process is a larger risk than a software engineer in Costa Rica on a managed device with scoped, logged access. What matters is whether the controls exist, whether an auditor has tested them over time, and whether the contract makes them enforceable. The same test applies to an offshore development company or a domestic contractor.
That reframe is why the rest of this post is organized as a checklist rather than a comparison of regions. The CFO and COO who sign off on vendor spend need the same answer the security team does: evidence, not assurances. The questions below are the ones that separate a real control from a slide, and they are the same ones our cybersecurity services practice is built around.
Which certifications a nearshore partner should hold
SOC 2 Type II is the baseline. HIPAA and PCI DSS apply by vertical, and ISO 9001 and ISO 42001 are useful signals of quality management and AI governance maturity. None of them replaces the others, and none replaces your own review.
A SOC 2 report is an attestation issued by a licensed CPA firm against the AICPA's Trust Services Criteria, which cover security, availability, processing integrity, confidentiality and privacy. The AICPA positions these reports as the information customers need "to assess and address the risks associated with outsourcing services" (AICPA, SOC suite of services). The distinction that matters is Type I versus Type II. A Type I report describes whether controls were designed properly at one point in time. A Type II report tests whether they operated effectively across a review period. Ask for the Type II.
Read the report, not the badge. The AICPA itself has warned publicly about compliance vendors promising fast and easy SOC engagements, and says SOC services should be thoroughly evaluated by the organizations relying on them (AICPA). So check who the auditor was, the dates of the review period, the scope of systems covered, and every exception the auditor noted. A clean opinion on a scope that excludes the engineering environment tells you very little about the engineering teams writing your code.
For healthcare buyers, the question is whether the vendor will sign a business associate agreement and operate under the HIPAA Security Rule. For fintech and commerce buyers handling card data, the question is how the vendor's work touches your PCI DSS scope. In most staff augmentation arrangements, and in many dedicated teams, the vendor's engineers work inside your environment, so the obligation is to follow your controls rather than hold a separate certification.
Sources: AICPA SOC suite of services; HHS HIPAA Breach Notification Rule.
First Factory is SOC 2 Type II certified, and our SOC 2 Type II announcement explains what the audit covered.
The nearshore software development security checklist
Day-to-day controls matter as much as the certificate. An audit tells you a control operated during a review window. The checklist below tells you whether it will operate on your software development project, during the engagement, with the specific engineers assigned to you. Each area names the evidence to request, because a yes without evidence is an opinion.
The stakes behind each area are measurable. IBM's 2025 figures show what a breach costs once it happens and how long it runs before anyone contains it.
Sources: IBM Cost of a Data Breach Report 2025 press release; Verizon 2025 DBIR Executive Summary.
Access control and devices
Every engineer should work on a company-managed device with disk encryption, remote wipe and a policy that blocks unapproved software. That includes QA engineers, who often get broad access to test environments. The risk is concrete. Verizon found that 46% of compromised systems with corporate logins in infostealer logs were non-managed devices holding both personal and business credentials (Verizon 2025 DBIR). Ask for the device management policy, the access request and approval process, and proof that access is scoped to least privilege. Then ask the question that exposes weak programs: when an engineer rolls off your project, how many hours pass before every credential is revoked, and who confirms it?
Code and data handling
Repositories and cloud services should live in your organization or in vendor accounts you administer, with branch protection and required reviews. Secrets belong in a vault, never in code or chat. For data protection, production data stays out of development and software testing environments unless it has been masked. Ask for the secrets management approach and the process for handling a leaked credential, because that 94-day median remediation time for secrets found in GitHub is the window an attacker gets when nobody owns the fix.
Secure development practices
Code review should be mandatory, not aspirational. The vendor's DevOps engineers should wire dependency scanning and static analysis into the pipeline so they run on every merge. The better vendors name DevOps champions inside each team who own that pipeline and its alerts. Security testing belongs on the same schedule as the rest of quality assurance, not triggered by an incident. Ask to see a pipeline configuration and a recent vulnerability report with remediation dates, ideally from a project on a similar tech stack. Our guide to web security testing tools covers the tooling side.
Incident response
A vendor's incident response plan should name who calls you, how fast, and what they hand over. Regulation sets an outer limit. Under HIPAA, a business associate must notify the covered entity no later than 60 days after discovering a breach (HHS). Sixty days is a legal ceiling, not a service level. Ask for the written plan, the date of the last tabletop exercise, and a notification commitment measured in hours.
AI tool governance
AI coding assistants are now standard in application development, and the governance around them often is not. IBM found that 63% of breached organizations either had no AI governance policy or were still developing one, and that incidents involving shadow AI exposed intellectual property 40% of the time against a 33% average (IBM, 2025). Ask which AI tools are approved, whether client code is excluded from model training, and how the vendor enforces the list. The question gets sharper when the engagement includes AI development, where models and training data join the code as assets to protect.
Juan 'JD' Sanchez, VP, Engineering at First Factory, puts the gap between audit and practice this way:
"The certificate tells you our controls held up across an audit period. What protects your code daily is narrower. It is about which laptops can reach your repository, whose access is revoked the day someone rolls off, and whether every engineer knows which AI tools are approved for your codebase. Ask to see those answers in writing before the first commit."
Turn each area into an RFP question with a required attachment, and score vendors on the evidence rather than the prose. Our white paper, Infosecurity and SOC 2 at First Factory, shows how those controls work in practice.
How to protect IP in a nearshore contract
IP assignment, confidentiality, work-product ownership and exit terms should be explicit in the master services agreement. Buyers often assume IP ownership transfers automatically because they paid for the code. That assumption fails more often across borders, where local law may treat the individual developer as the default owner unless an assignment chain says otherwise. The fix is contractual, and it is cheap to get right before signing.
The section below is informational, not legal advice. Involve your own counsel, and ask them to review the clauses against the laws of both your jurisdiction and the vendor's.
Clause checklist compiled from the controls discussed above. Not legal advice.
Employee status deserves attention because it determines whether the assignment chain holds on custom software development work. When a vendor staffs your project with skilled software developers it employs full time, all of whom have signed confidentiality agreements, the chain runs from engineer to vendor to you. When the vendor subcontracts through a marketplace, it may not run at all.
Exit terms are where a good relationship proves itself. First Factory's contracts require 60 days' written notice to ramp down a resource, which gives both sides time for an orderly handover, and our 30-day satisfaction guarantee applies to every resource we place. Our service contracts page explains how support and maintenance terms work after launch.
Regulated industries raise the bar on every clause above, and on the industry expertise you should expect from the vendor. A fintech buyer will want audit rights and data residency terms. A healthcare buyer will want the business associate agreement signed before any engineer sees patient data. See how we approach FinTech software development in regulated environments.
How to run a nearshore security review
Request documents, interview the security lead and test the answers against your checklist before signing. The review takes days, not months, if you run it in order.
- Request the evidence package. Ask for the SOC 2 Type II report, the device management and access control policies, the incident response plan, the AI tool policy and the draft master services agreement. A vendor that needs weeks to assemble these documents is telling you something about how often anyone asks.
- Interview the people who run the controls. Put your security lead in a room with the vendor's security officer and the tech lead who would run your team. Ask them to walk through an offboarding, a leaked credential and an incident notification using real tools, not policy language. Real technical expertise shows up as specific names, systems and timelines.
- Score and negotiate. Compare the answers against the checklist, flag every gap, and write the fixes into the contract as named obligations. A gap the vendor agrees to close in writing is manageable. A gap it declines to put in the contract is your answer.
The review also shows you the vendor's communication culture. A partner that answers precisely during diligence tends to communicate the same way when something breaks at 2 a.m. Time zone alignment matters here too: a team working your hours can join an incident call in real time instead of reading about it the next morning.
First Factory has delivered nearshore engineering for U.S. clients for more than 25 years, and we are SOC 2 Type II certified. Request our SOC 2 Type II documentation and walk through your security questionnaire with an engineering lead: schedule a call.
How region, team model and project type change the risk
Region
Region changes three things that bear on security: the hours your vendor keeps, the law its engineers work under and how deep the local hiring market runs. It does not decide whether the controls exist. Offshore outsourcing to South or Southeast Asia usually means little or no overlap with the U.S. workday, so an incident found at 2 p.m. Eastern lands in the middle of the vendor's night. Eastern Europe overlaps with East Coast mornings and barely at all with the West Coast. A nearshore team on your hours turns incident response into real-time collaboration instead of a handoff note read the next day. Cultural fit matters here more than buyers expect. An engineer who will tell your tech lead that a release is unsafe protects you better than one who ships quietly to avoid friction, and that kind of cultural alignment is worth testing in the security interview.
Cost
Cost differences between regions matter, and they push buyers to compare hourly rates first. That is the wrong starting line. A low hourly rate built on contractors, personal laptops and no audit trail does not lower development costs; it moves them into your breach exposure, where the U.S. average already sits above $10 million. The cost savings worth keeping are the ones that survive the checklist above. Talent depth matters for a similar reason. A vendor drawing on a deep IT talent pool can hire full-time employees and replace someone who rolls off without reaching for freelancers. In Costa Rica, decades of multinational engineering operations have built a mature ICT market. Universities and technical institutes add a new class of IT graduates every year, and that intake, backed by long public investment in technology education, is what lets a vendor staff with employees rather than contractors. For scaling businesses, that depth decides whether the team you vetted in month one is still the team on your code in month twelve.
Project Type
The type of work changes the exposure as well. Software modernization usually puts engineers inside legacy systems full of old service accounts and undocumented access, so inventory those credentials before the first sprint. Larger digital transformation programs repeat that problem across many systems at once, which is why access reviews should run on a schedule rather than at the end.
- Mobile app development adds signing keys and app store credentials that belong in your vault, not on a developer's machine.
- Web development exposes public endpoints that need scanning before every release.
- SaaS applications raise the stakes again, because one tenant's leak can become every customer's problem.
- UI/UX design work rarely needs production data at all, so designers should get prototypes and synthetic records.
- AI innovation projects add a new asset class: the training data. The vendor's AI engineers need a written rule on which datasets may leave your environment.
Engagement Model
The engagement model decides whose controls apply. In staff augmentation, engineers join your software teams and work under your policies. In a dedicated team or fixed-scope project, the vendor's own program carries more of the load, so its project management should include security checkpoints alongside delivery milestones. Team size changes the math, since every engineer added is another device, another credential and another offboarding. Even a narrow QA and testing engagement needs scoped access, because test environments often hold copies of real data. Be wary of vendors selling broad IT outsourcing solutions that bundle help desk, infrastructure and development, and ask which security program actually covers the engineers with repository access. Then check the record. Ask for the vendor's client satisfaction score and two references, and ask those references how the vendor handled its last security issue. Customer satisfaction that holds up through an incident is the evidence that counts.
When a nearshore arrangement is the wrong fit
Some work should stay in-house or move to onshore development regardless of the vendor's controls. If a contract or regulator requires that only U.S. persons touch a system, such as certain defense or government workloads, a nearshore team cannot staff it, and no certification changes that. If your own security program has no device management, no access reviews and no incident plan, adding any external team multiplies risk you have not yet measured. Fix the foundation first.
Timing matters as well. A vendor brought in during an active incident or an audit remediation inherits undocumented systems under pressure, and the review in the previous section gets skipped. Finally, if the vendor cannot name the engineers, their employer and their devices, you are buying access from people you cannot identify. That is a marketplace, not a partner, and the checklist above will not rescue the arrangement.
FAQs about nearshore software development security
Who owns the code written by nearshore developers?
You should, but only if the contract says so and the vendor holds IP assignment agreements from its own employees. Local law in the vendor's country may otherwise treat the developer as the default owner. Ask for the assignment clause and confirmation that every assigned engineer has signed one, and have your counsel review both.
Is SOC 2 Type II enough for a fintech or healthcare vendor?
SOC 2 Type II is the baseline for any nearshore software development company, not the finish line. Healthcare work also requires a signed business associate agreement and HIPAA safeguards, and card data work must fit inside your PCI DSS scope. Read the SOC 2 report's scope and exceptions to confirm the engineering environment is covered.
How do nearshore partners handle HIPAA and PCI requirements?
In most staff augmentation arrangements the engineers work inside your environment and follow your controls, so the vendor's job is to sign the right agreements and enforce your policies on its people and devices. For projects the vendor hosts, ask for its own compliance evidence and a clear map of where regulated data lives.
What happens to our data and access when a nearshore engagement ends?
A sound contract requires the vendor to revoke all access, return or destroy your data, certify the destruction in writing, and hand over documentation and credentials. Ask how many hours offboarding takes and who confirms it. Build the notice period and knowledge transfer into the master services agreement before you sign.
Can we add custom security clauses to a nearshore contract?
Yes, and you should for anything your risk team considers material, such as incident notification in hours, audit rights or data residency. A vendor that treats its paper as non-negotiable on security terms is signaling how it will respond when an issue arises. Put every agreed control in the contract as a named obligation.
Is First Factory SOC 2 Type II compliant?
Yes. First Factory is SOC 2 Type II certified, and prospective clients can request our SOC 2 Type II documentation during security review. You can read what the audit covered in our SOC 2 Type II announcement.
Talk to a SOC 2 Type II nearshore partner
First Factory has delivered nearshore engineering for U.S. clients for more than 25 years, holds SOC 2 Type II certification, and backs every resource with a 30-day satisfaction guarantee. Schedule a call to request our security documentation and walk through your questionnaire with an engineering lead. If you want the detail first, download Infosecurity and SOC 2 at First Factory.



.avif)


