Cybersecurity / Source date:

Third-Party Risk: The Cybersecurity Lesson Everyone Ignored Until Target

Why vendor access is your biggest vulnerability—third-party risk management essentials.

Illustration of a maintenance technician using a dedicated service connection beside closed plant-controls cabinets.

Third-party risk was not a new idea in 2013. Outsourcing governance frameworks existed. Financial regulators had published vendor management guidance. Audit firms sold supplier assurance services. The discipline had a name, a body of literature and a professional community. It also had almost no organizational authority, because until a retailer's payment environment was reached through a refrigeration contractor's credentials during the 2013 holiday season, third-party risk was a theoretical concern with no memorable example attached. After that, it had one, and the conversation changed permanently. The interesting question is not why it changed. It is why the warning had been available for years and was ignored.

The Warnings That Preceded It

The evidence was not subtle. Payment industry standards had required segmentation for years. The cardholder data environment was supposed to be isolated from general corporate networks, and assessors had been documenting inadequate segmentation as a finding for the better part of a decade. Breach investigation reports consistently identified third-party involvement. Annual industry analyses of incident data had repeatedly flagged partner and supplier connections as a meaningful intrusion vector, well before the retail breach made the point vividly. Regulators had published explicit outsourcing guidance. Financial services supervisors in several jurisdictions had issued requirements covering due diligence, ongoing monitoring, contractual protections and exit planning for outsourced arrangements. The principles were available to anyone who wanted them. And individual organizations had experienced smaller versions. Vendor-attributed incidents happened regularly. They were handled quietly, attributed to the supplier, and produced no structural change because they were not large enough to force one. The warnings were ignored for reasons that are worth stating plainly, because they have not gone away. The risk was diffuse and the cost was immediate. Reducing vendor access costs money and slows down business activity now, to avoid a probabilistic harm later. That is the hardest trade to fund. Nobody owned the aggregate. Procurement owned contracts. IT owned connections. Business units owned relationships. Security owned the perimeter. No single function owned the question "what can our suppliers collectively reach?", so nobody answered it. Existing processes created false assurance. Vendor questionnaires were being completed and filed. That felt like third-party risk management and was not — a completed questionnaire is a statement of intent by the party with the least incentive to disclose problems. And the framing was wrong. "Vendor risk" sounded like a procurement matter — will they deliver, will they stay solvent — rather than what it was: an extension of the organization's own attack surface to parties it did not control.

What Actually Reduces the Exposure

The practices that work were known before 2013 and remain the ones organizations skip. Build the inventory from identity, not from contracts. The register of suppliers and the register of parties who can authenticate into your systems are different lists, and only the second one describes your exposure. Deriving it requires examining directories, VPN configurations, application accounts and integration credentials rather than asking procurement. Tier by access, not by spend. This is the single highest-value change and almost every procurement process gets it wrong, because review thresholds are triggered by contract value. A small maintenance contractor with a remote connection into building systems presents more risk than a large supplier with no access at all. Replace network access with application access. Most vendor remote access exists because it was the fastest solution at the time. Brokered access to specific applications, with no general network reachability, eliminates the lateral movement path that makes vendor compromise dangerous. Constrain what a compromised vendor identity can reach. Segmentation is the control that converts a vendor breach into a contained incident. The test is practical: assume the credential is in hostile hands and establish what it touches. Verify rather than survey, for the tier that matters. For the small number of suppliers with privileged access to critical systems, a questionnaire is inadequate. Independent assurance reports, technical validation, penetration test summaries and evidence of actual control operation are what constitute due diligence. Monitor external sessions as a distinct category. Vendor access has narrow legitimate patterns — known hours, known systems, known activities. That makes deviation unusually informative and makes vendor access one of the best returns available on detection investment. Reconcile access against active engagements quarterly. Orphaned vendor accounts belonging to companies no longer engaged are among the most reliable findings in any access review. And write proportionate obligations into contracts. Notification timelines, audit rights, control requirements, subcontractor restrictions and liability allocation, scaled to what the vendor can reach rather than applied uniformly.

Review the access, not only the contractQualitative review sequence assembled from the article's control guidance. A diagram does not establish that segmentation is effective.
  1. Discover external identities

    Inspect directories, remote-access configuration and integration credentials.

  2. Tier by reachable assets

    Prioritise privileged and critical-system access rather than contract value.

  3. Constrain the connection

    Limit application reach and test what a compromised identity can touch.

  4. Verify important controls

    Request independent evidence and technical validation for the high-access tier.

  5. Monitor and reconcile

    Review session patterns, active engagements, exit arrangements and contractual obligations.

Qualitative summary of this article's source text, not a measured outcome or performance estimate.

The Cost Objection

The honest difficulty with supply chain security is that doing it properly is expensive and falls disproportionately on suppliers least able to bear it. A comprehensive security questionnaire sent to a twelve-person contractor produces a refusal, a dishonest response, or a cost passed back in the price. Multiply across a supplier base of two thousand and the programme becomes a substantial function with a review queue that delays legitimate business. The answer is triage rather than retreat. Most suppliers need no security assessment because they have no access. A small number need genuine technical scrutiny. The middle needs a short proportionate set of requirements. The failure mode to avoid is a uniform process, which is simultaneously too burdensome for the harmless majority and far too light for the dangerous few — and which consumes the budget that should have been spent on the suppliers that matter.

Practical Guidance for Supply Chain Security

  • Derive the access inventory from identity systems. The contract register will not tell you who can authenticate into what.
  • Tier by what the supplier can reach, not what you pay them. Value-based review thresholds systematically miss the highest-risk relationships.
  • Eliminate network-level vendor access wherever possible. Brokered application access removes the lateral movement that makes a vendor compromise serious.
  • Assume each vendor credential is compromised and map the blast radius. Segmentation quality is measured by that answer, not by a network diagram.
  • Use evidence rather than questionnaires for privileged suppliers. Assurance reports and technical validation; self-attestation is not due diligence.
  • Monitor vendor sessions against expected patterns. Narrow legitimate behaviour makes anomaly detection unusually effective here.
  • Reconcile external accounts with active engagements every quarter. Access outlives relationships by years unless someone checks.
  • Plan for supplier failure and exit, not just supplier compromise. Concentration risk and the practical ability to move matter as much as controls.

The Regional Dimension

In the Gulf, third-party concentration is structurally higher than in many markets, which raises both the exposure and the value of getting this right. Outsourced IT and managed services are the default operating model. A large share of regional enterprises rely on systems integrators, managed service providers and offshore delivery centres for infrastructure administration, application support and back-office processing. Privileged access sits outside the organization by design. That makes privileged access management, session recording, just-in-time elevation and approval workflows more important here than in an organization with a large internal IT function — and these are precisely the controls most commonly absent. Facilities and operational technology contractors are everywhere. Large developments, hospitality groups, retail and industrial facilities across the region run extensive building management, HVAC, access control and CCTV systems maintained under remote support arrangements. This is the exact pattern from the 2013 retail breach, at unusually high density, and operational technology segmentation typically receives a fraction of the attention that IT segmentation does. Free-zone and multi-entity structures fragment ownership. A group with entities across several GCC jurisdictions frequently shares infrastructure and suppliers while holding separate legal and regulatory obligations per entity. A compromise in one entity can propagate through shared infrastructure, and the incident notification obligations differ by jurisdiction and sector regulator. Regulation has made this an obligation rather than good practice. National cybersecurity authority frameworks in the UAE and Saudi Arabia include third-party and supply chain requirements. Financial services regulators, including those covering DIFC and ADGM entities, impose outsourcing governance with notification duties and in some cases prior approval for material arrangements. Under the UAE data protection framework and Saudi PDPL, a supplier processing personal data requires a written processor arrangement with specified terms and a documented transfer basis where data leaves the jurisdiction. Government relations and PRO services hold sensitive personal data. Intermediaries handling visa processing, Emirates ID applications, labour contracts and licensing hold passport copies, identity documents and employment records for the entire workforce. They are frequently small firms, rarely subject to security review, and hold one of the most sensitive data sets the organization possesses. And local-content requirements shape the supplier base. In-country value and Saudisation requirements direct procurement toward regional suppliers, many of them smaller firms with limited security maturity. That is a legitimate policy objective and it means the assessment approach has to be proportionate and supportive rather than exclusionary — setting requirements small suppliers can actually meet, and helping them meet them, rather than issuing a hundred-question document.

What Came Next

The pattern the 2013 breach demonstrated has scaled rather than diminished. Compromises of software build and update systems, managed service providers, widely deployed file transfer products and open source dependencies have each shown the same principle at greater leverage: compromise one supplier, reach hundreds or thousands of customers. The economics favour the attacker decisively. Regulatory response has followed. Supply chain requirements have been added to major security frameworks. Financial sector resilience regulation in several jurisdictions now imposes specific obligations on critical third-party arrangements, including register maintenance, contractual minimums and exit planning. Software supply chain transparency requirements, including bills of materials, have moved from proposal to procurement condition in several sectors. And the pattern is repeating with AI, faster than the previous cycle and with less scrutiny. Organizations are connecting model providers, AI features inside existing SaaS products, and increasingly autonomous agents to email, documents, code repositories and customer records. The access is broad, the subprocessor chains are opaque, the data retention terms are frequently unread, and the approval path runs through business units enabling a feature in software they already license rather than through any security review. It is the same structural failure. A party with a narrow business purpose obtains broad technical access, nobody owns the aggregate question, and the review threshold is triggered by something other than access. The organizations that will handle this well are the ones that built the access inventory and the tiering discipline the last time round — which is a short list.

Common Questions

Why did third-party risk get ignored before 2013?

The cost of reducing vendor access was immediate while the risk was diffuse, no single function owned the aggregate question of what suppliers could collectively reach, completed questionnaires created false assurance, and the framing as a procurement matter obscured that it was an extension of the attack surface.

What is the single most important change to make?

Tier suppliers by what they can access rather than by contract value. Procurement review thresholds based on spend systematically miss small vendors with privileged access, which is exactly the profile that produced the defining breach of the category.

Are vendor security questionnaires useful?

For low and medium tiers, as a proportionate baseline. For suppliers with privileged access to critical systems they are inadequate — a self-completed questionnaire is a statement of intent by the party with the least incentive to disclose weakness. Independent assurance reports and technical validation are required at that tier.

How does this apply to AI integrations?

Directly. Model providers and AI features are being granted broad access to documents, email and business records through approval paths with minimal security involvement, opaque subprocessor chains and unreviewed data retention terms. It is the same structure with a larger blast radius.


Secure Your Supply Chain — Outpace builds the access inventory nobody owns, tiers your suppliers by what they can actually reach, and closes the routes that matter.

Continue reading

Talk to OPS

Start with the operating problem.