Lesson 1 of 4
Why suppliers are your attack surface
Four distinct kinds of third-party exposure, which need four different answers.
13 min 3-question quiz 3 guides to read next
"Third-party risk" is four different problems that happen to share a procurement process.
Data exposure
A supplier holds your data: a customer platform, a payroll processor, an analytics tool. Their breach is your notification obligation, and your customers will not find the distinction interesting.
Dependence
A supplier's outage stops you operating — authentication, payments, hosting, a logistics platform. Nothing is disclosed, and the cost is still real. This is a resilience question that security teams often leave out of the assessment entirely.
Integration
A supplier has access into your environment: an agent on every endpoint, an OAuth grant over your mail, a VPN tunnel, a privileged API token, code running in your build. Their compromise becomes your compromise directly, and these are the incidents that have hurt most in recent years.
Software supply chain
Code you run that somebody else wrote: dependencies, container images, build tooling, browser extensions, device firmware. Nobody signed a contract and it is still your attack surface.
Assess accordingly
These need different questions. A tool holding no data but integrated deeply is a higher risk than a data-holding tool with a narrow, well-fenced integration — and a standard questionnaire scores them identically, which is one reason the standard questionnaire has such a poor reputation.
Start every assessment by writing one sentence: what could this supplier cost us, and through which of the four routes? That sentence decides how much effort the rest deserves.
Check your understanding
3 questions · pass with 2 correct
Enrol for free to save your progress, unlock every lesson and earn a certificate.
Sign in to enrolFurther reading
Guides that go deeper on this lesson.
-
Evaluating AI Vendors for Security
Questions to ask before adopting third-party AI products and APIs, covering data, security, compliance and resilience.
1 min read
-
AI Supply Chain Security
Managing the risks of third-party models, datasets, libraries and tools in AI systems.
1 min read
-
Security Questionnaires Worth Sending
Third-party assessment that produces information rather than a completed form.
2 min read