The increasing reliance of modern businesses on third-party suppliers and vendors has created a significant cybersecurity risk, experts warn. According to US tech research firm Gartner, third-party and supply chain compromise is a growing concern, with organisations exposed to risks through vendors and technology partners outside their direct security controls. This highlights the need for businesses to look beyond their own perimeter when assessing security.
The World Economic Forum's 2026 "Global Cybersecurity Outlook" also identifies supply chain vulnerabilities as a significant cyber risk. Businesses can control their own security, but not how securely every third party operates. If a third-party supplier is compromised, the business can become the victim. Cybersecurity expert John Mc Loughlin, CEO of J2 Software, notes that sending suppliers a security questionnaire and filing it away is not sufficient security.
Mc Loughlin stresses the importance of understanding who has access to a business and why. A third party may have access to sensitive data, endpoints, or administrative systems, which can accumulate over years. To mitigate this risk, businesses should give people and suppliers the access they need, rather than the access they might possibly need, and remove access when it is no longer required.
The reality is that businesses do not control the security of their suppliers, and their employees can be phished, their passwords stolen, or their laptops infected. Cybercriminals do not care whether the compromised person works for the business or a contracted supplier. If that identity has access to the business, it becomes a problem.
To manage third-party risk, businesses should monitor the activity of supplier accounts within their systems. Unusual login times, access to systems not normally used, or large data downloads are signals that can indicate potential security breaches. By identifying these signals, businesses can turn third-party risk from an unknown into something manageable.
Prioritising risk based on access and potential impact is crucial. Many organisations focus on whether a supplier has the right policies and certificates rather than asking what would happen if that supplier were compromised. Outsourcing a service does not outsource the consequences, and businesses will be held accountable if a supplier is compromised.
To mitigate third-party risk, businesses should know who has access, understand what they can reach, reduce unnecessary privileges, protect identities, monitor activity, and have a plan to disable access quickly. By taking these steps, businesses can make themselves harder to compromise, easier to monitor, and better able to respond when something goes wrong.
Key points
- Businesses should prioritise third-party risk based on access and potential impact.