Risk Management

Your Supplier’s Security Is Your Security: Managing Third-Party Risk

The supplier with access to your systems is part of your attack surface, whatever the contract says about liability.

Reviewing third-party access arrangements

Attackers go where the defences are thinner. For a well-defended organisation, that is frequently the managed service provider with remote access, the software vendor whose update you install automatically, or the contractor with a login nobody has reviewed since onboarding.

Where the exposure comes from

  • Direct access. Suppliers with VPN, remote support or administrative accounts in your environment.
  • Software supply chain. Code and updates you trust and install, including the dependency tree underneath them.
  • Data processors. Anyone holding your data on their infrastructure — their breach is your notification obligation.
  • Shared infrastructure. Cloud tenancy, shared platforms and integrations connecting your systems to theirs.

Why questionnaires alone do not work

Most third-party programmes send a spreadsheet at onboarding and file the answers. The answers are self-reported, often completed by someone in sales, and describe a point in time that has since passed. They provide evidence of due diligence; they provide very little assurance.

Proportionate assurance

Not every supplier warrants deep scrutiny. Tier them by what they can actually reach:

  • Critical: administrative access to your systems, or processing sensitive data at volume. Independent assurance, right-to-audit, contractual breach notification with a defined deadline.
  • Important: some access or data. Evidence of certification, reviewed annually.
  • Low: no access, no data. Standard terms are sufficient.

Tier by access, not by invoice value. Your most dangerous supplier is often a small one with a domain administrator account.

Controls that survive a supplier breach

Assume one of your suppliers will be compromised, then limit what that costs you:

  • Named accounts, never shared. You need to know which individual did what.
  • Just-in-time access. Supplier accounts enabled for the work, then disabled. Standing access is standing risk.
  • MFA, no exceptions. "Our tooling does not support it" is a reason to change the tooling.
  • Segmented reach. The air-conditioning vendor does not need to reach the finance network.
  • Dedicated monitoring. Alert on supplier account activity outside expected hours or scope.
  • A documented offboarding step. Contract ends, access ends, same day. This is the control most commonly missing.

Put it in the contract

Breach notification within a defined period. Right to audit or to receive independent assurance. Requirements that flow down to their subcontractors. Clear data-handling and deletion terms at termination. Negotiate these at procurement, when you have leverage — not during an incident, when you have none.