Skip to content

Lesson 1 of 4

Free preview

Why suppliers are your attack surface

Four distinct kinds of third-party exposure, which need four different answers.

13 min 3-question quiz 3 guides to read next

On this page
  1. Data exposure
  2. Dependence
  3. Integration
  4. Software supply chain
  5. Assess accordingly

"Third-party risk" is four different problems that happen to share a procurement process.

Data exposure

A supplier holds your data: a customer platform, a payroll processor, an analytics tool. Their breach is your notification obligation, and your customers will not find the distinction interesting.

Dependence

A supplier's outage stops you operating — authentication, payments, hosting, a logistics platform. Nothing is disclosed, and the cost is still real. This is a resilience question that security teams often leave out of the assessment entirely.

Integration

A supplier has access into your environment: an agent on every endpoint, an OAuth grant over your mail, a VPN tunnel, a privileged API token, code running in your build. Their compromise becomes your compromise directly, and these are the incidents that have hurt most in recent years.

Software supply chain

Code you run that somebody else wrote: dependencies, container images, build tooling, browser extensions, device firmware. Nobody signed a contract and it is still your attack surface.

Assess accordingly

These need different questions. A tool holding no data but integrated deeply is a higher risk than a data-holding tool with a narrow, well-fenced integration — and a standard questionnaire scores them identically, which is one reason the standard questionnaire has such a poor reputation.

Start every assessment by writing one sentence: what could this supplier cost us, and through which of the four routes? That sentence decides how much effort the rest deserves.

Check your understanding

3 questions · pass with 2 correct

1. Which third-party exposure do security assessments most often leave out?
2. Why is a deeply integrated tool holding no data sometimes riskier than a data-holding one?
3. What single sentence should start every supplier assessment?

You'll see your score; enrol to have it count towards your certificate.

Enrol for free to save your progress, unlock every lesson and earn a certificate.

Sign in to enrol

Further reading

Guides that go deeper on this lesson.