Under article 25 of GDPR there are obligations to ensure personal data is adequately protected. Under article 28, as the controller*, you have the obligation to ensure that data processors** (for example subcontractors who may be processing personal data on your behalf) have the right technical measures in place to protect that data.