1. Does the vendor support a critical function?
2. Do they hold security certs (ISO 27001 / SOC 2)?
3. Do they have a proven continuity / DR plan?
4. Do they process personal / sensitive data?
5. Security/audit/exit clauses in the contract?
6. Concentration: hard to replace?