// third-party risk

Their breach, your incident: managing third-party and vendor risk

Saleem Yousaf 4 Aug 2026 13 min read

Most organisations can tell you more about their software dependencies than about their suppliers. They have a software bill of materials, or at least a dependency tree, but ask which third parties hold their customer data, which ones can reach inside their network, and what would happen if the biggest of them fell over on a Tuesday, and the answers get vague. That gap matters, because the breach that takes you down increasingly is not yours. It is a supplier's, and it becomes your incident the moment it happens.

This is the organisational half of supply chain risk. I have written separately about the technical side, the artefacts and provenance and signing that tell you whether the software you ship is what you think it is. This is the other side: the suppliers, the SaaS platforms, the processors and the sub-processors who hold your data and touch your systems, and the discipline of managing the risk you handed them along with the work.

Part one

You can outsource the service, not the risk

The core principle is one sentence and it is the whole article: you can delegate the work to a third party, but you cannot delegate the consequences. When a supplier who processes your customer data is breached, your customers are affected, your name is in the story, and in most jurisdictions your regulatory obligations apply, because you chose that supplier and remain accountable for the data you entrusted to them. The contract can move liability around at the margins, but it cannot move the incident, the headlines or the loss of trust.

That reframes vendor risk from a procurement checkbox into a real part of your attack surface. Every supplier with access to your data or your systems is a path into your organisation that you do not directly control, and the sum of those paths is often larger and less visible than your own perimeter, which you at least monitor.

// THEIR BREACH, YOUR INCIDENT ACCESSData and access Who holds your data, and whatthey can reach in your estate. CONCENTRATIONShared fate Many services quietly restingon one provider or region. EXITThe way out What happens to your dataand operation when it ends. // WHY THE QUESTIONNAIRE DOES NOT SAVE YOU THEATREA questionnaire is a snapshot A form answered once at onboarding sayslittle about the supplier after a breach. CONCENTRATIONShared fate you did not price When half your suppliers sit on oneplatform, one outage is many at once. // WHAT A REAL PROGRAMME COVERS Inventoryevery supplier with data or access · not just the contracted ones Tieringrisk-rank by data and access · effort follows impact Evidenceindependent assurance · not a self-graded form Contractbreach-notification clock · right to audit · data return Exit and concentrationan exit plan, and a map of who shares one fate
Where the risk lives, why forms miss it, and what a real programme covers. Click to expand.
Part two

Why the security questionnaire does not save you

The dominant tool in third-party risk is the questionnaire: a spreadsheet of security questions sent to a supplier at onboarding, answered by them, filed by you. It is not useless, but it is widely mistaken for assurance when it is closer to theatre, for three reasons worth being honest about.

It is a snapshot, and a self-graded one. The supplier answers once, at the start, describing themselves in the best light, and the form is rarely revisited. The company that answered well at onboarding is a different company six months and one acquisition later, and the form does not know that. It is also self-assessment, which means you are trusting the party with the incentive to look good to mark their own homework, with no independent check.

And it measures the wrong thing. A completed questionnaire tells you a supplier can fill in a questionnaire. It does not tell you whether the controls described are real, operating, and effective, which is what independent assurance, a recognised audit report or certification, actually speaks to. The questionnaire has its place as a first filter, but treating a returned spreadsheet as evidence that a supplier is secure is the third-party equivalent of trusting an unsigned artefact because it arrived with a nice label.

Part three

What a real programme covers

Inventory, because you cannot manage what you cannot see

The foundation is a list of every supplier that holds your data or can reach your systems, and most organisations do not have one. Procurement has a list of who gets paid, which is not the same thing, because it misses the free tools, the departmentally expensed SaaS, the sub-processors your suppliers use, and the integrations someone connected two years ago. The inventory is unglamorous and it is the single highest-value artefact in the whole discipline, because every control downstream depends on knowing who is actually on the list.

Tiering, so effort follows impact

Not every supplier warrants the same scrutiny. A vendor that processes your entire customer database is a different risk from one that supplies office plants, and treating them identically wastes effort on the trivial and under-examines the critical. Risk-rank suppliers by the data they hold and the access they have, and concentrate your real assurance effort on the tier that could actually hurt you. This is how a programme stays proportionate rather than collapsing under the weight of assessing everyone equally.

Evidence, contract, and the exit

For the suppliers that matter, ask for independent assurance rather than a self-assessment, and read it rather than filing it. Put the things you actually need into the contract: a breach-notification clock that obliges them to tell you quickly, a right to audit, and clear terms for the return or destruction of your data when the relationship ends. And plan the exit at the beginning, because the time to work out how you would leave a critical supplier is before you depend on them, not during the crisis that makes you want to.

The risk everyone forgets to price Concentration is the silent one. When many of your suppliers quietly run on the same underlying cloud provider or region, a single outage there is not one vendor failing, it is a dozen of your services failing at once, in a way your per-vendor assessments never showed because each looked fine alone. Map the shared fate, or discover it on the day.
Part four

Delivering it: who, what, when

Who. Third-party risk sits awkwardly between procurement, security, legal and the business owners who actually chose the suppliers. It needs a clear owner, usually in security or risk, with the authority to say no to a supplier and the cooperation of procurement to enforce it at the point of purchase, which is the only point where saying no is cheap.

What. The inventory first, always, because nothing else works without it. Then tiering, then real assurance on the top tier, then the contractual terms, then the concentration map and exit plans for the suppliers you could not easily live without.

When. Assess before you sign, because your bargaining position is strongest before the contract exists and near zero afterwards. Then reassess the critical tier on a cycle, not once, because a supplier's security is a moving state and a point-in-time check ages badly. Build the reassessment into the calendar or it will not happen.

The honest summary

Vendor risk is the part of your attack surface you do not run and cannot see by default, and the tooling most organisations use to manage it, the onboarding questionnaire, is the part most mistaken for assurance. The work that actually reduces the risk is less glamorous and more durable: know who holds your data, rank them by what they could cost you, demand real evidence from the ones that matter, write the clock and the exit into the contract, and map the concentration that your per-vendor view hides.

If you do one thing, build the inventory. Not the procurement list, the real one, every party with your data or access to your systems. Almost no organisation has it, everything else depends on it, and the exercise of building it usually finds two or three suppliers holding far more than anyone remembered granting them.

If you want help building a third-party risk programme that is proportionate rather than performative, that is the kind of work I do through Cyber Spartans.