Attackers go where the defences are thinner. For a well-defended organisation, that is frequently the managed service provider with remote access, the software vendor whose update you install automatically, or the contractor with a login nobody has reviewed since onboarding.
Where the exposure comes from
- Direct access. Suppliers with VPN, remote support or administrative accounts in your environment.
- Software supply chain. Code and updates you trust and install, including the dependency tree underneath them.
- Data processors. Anyone holding your data on their infrastructure — their breach is your notification obligation.
- Shared infrastructure. Cloud tenancy, shared platforms and integrations connecting your systems to theirs.
Why questionnaires alone do not work
Most third-party programmes send a spreadsheet at onboarding and file the answers. The answers are self-reported, often completed by someone in sales, and describe a point in time that has since passed. They provide evidence of due diligence; they provide very little assurance.
Proportionate assurance
Not every supplier warrants deep scrutiny. Tier them by what they can actually reach:
- Critical: administrative access to your systems, or processing sensitive data at volume. Independent assurance, right-to-audit, contractual breach notification with a defined deadline.
- Important: some access or data. Evidence of certification, reviewed annually.
- Low: no access, no data. Standard terms are sufficient.
Tier by access, not by invoice value. Your most dangerous supplier is often a small one with a domain administrator account.
Controls that survive a supplier breach
Assume one of your suppliers will be compromised, then limit what that costs you:
- Named accounts, never shared. You need to know which individual did what.
- Just-in-time access. Supplier accounts enabled for the work, then disabled. Standing access is standing risk.
- MFA, no exceptions. "Our tooling does not support it" is a reason to change the tooling.
- Segmented reach. The air-conditioning vendor does not need to reach the finance network.
- Dedicated monitoring. Alert on supplier account activity outside expected hours or scope.
- A documented offboarding step. Contract ends, access ends, same day. This is the control most commonly missing.
Put it in the contract
Breach notification within a defined period. Right to audit or to receive independent assurance. Requirements that flow down to their subcontractors. Clear data-handling and deletion terms at termination. Negotiate these at procurement, when you have leverage — not during an incident, when you have none.
