Third-Party Risk Management: The Threat You Might Be Overlooking
- 12 minutes ago
- 7 min read
Your Security Is Only as Strong as Your Weakest Partner
Third-party risk management has become one of the most pressing challenges in cyber security, and it is easy to see why. You could have robust security controls across your entire organisation, strong access management, regular patching, an engaged and trained workforce, and still suffer a significant breach through a third party.
This is not a theoretical risk. Some of the most high-profile cyber incidents in recent years have originated not within the victim organisation itself, but through a supplier, service provider, or technology partner.
Third-party risk is consistently ranked among the top concerns for security professionals (Protiviti's 2026 Global Top Risks survey ranks third-party risk as the second-highest near-term global risk, just behind cyber threats themselves), yet it remains one of the most underdeveloped areas of many organisations' cybersecurity programmes. The challenge is understandable: you have direct control over your own environment, but limited visibility into the security practices of the organisations you depend on.

How Supply Chain Attacks Work
Supply chain attacks exploit the trust relationships between organisations. Rather than attacking a well-defended target directly, threat actors compromise a supplier or service provider that has access to the target's systems, data, or network. This access might come through software updates, API connections, shared credentials, or data feeds.
The effectiveness of this approach lies in its ability to bypass the target's own defences. If a trusted supplier pushes a compromised software update, or if a managed service provider's credentials are stolen, the attacker gains access through a channel that the target organisation has explicitly allowed.
These attacks can be difficult to detect because the malicious activity originates from a trusted source. The traffic looks legitimate, the access is authorised, and the compromise may not become apparent until significant damage has been done.
These are not hypothetical scenarios:
In 2024, a ransomware attack on a pathology services provider disrupted blood testing and patient care across several NHS trusts in London, a stark illustration of how a single third-party failure can cascade across an entire sector, as confirmed in NHS England's own account of the incident.
In 2025, Reuters reported that Marks & Spencer suffered weeks of operational disruption after attackers used social engineering against a third-party IT contractor to bypass its own defences entirely.
Third-Party Risk Management: Assessing Your Exposure
Effective third-party risk management begins with understanding your relationships. Which third parties have access to your systems or data? What level of access do they have? What would the impact be if that third party were compromised?
These questions help you categorise your relationships by risk and focus your efforts where they matter most.
Which third parties can access your systems, network, or data?
What level of access do they hold, and is it the minimum required?
What would the impact be if that third party were compromised?
Do they hold relevant certifications, such as Cyber Essentials or ISO 27001?
When was their security posture last reviewed, and by whom?
For higher-risk relationships, a structured assessment process is valuable. This typically involves a questionnaire covering the third party's security policies, technical controls, incident response capabilities, and their own supply chain management. The depth and rigour of the assessment should be proportionate to the risk, not every supplier needs the same level of scrutiny.
It is also worth looking beyond the questionnaire. Certifications such as Cyber Essentials or ISO 27001 provide some level of assurance. Independent audit reports, where available, add further confidence. But no assessment process can guarantee that a third party will never be compromised. The goal is to make informed decisions about the risk you are accepting.
Trust Centres: A Faster Way to Assess and Be Assessed
A growing number of vendors now maintain a trust centre: a self-service page publishing their SOC 2 report, ISO 27001 certificate, data processing agreement, subprocessor list, and answers to the security questions buyers ask most often. Rather than waiting for a bespoke questionnaire to land, the vendor makes the evidence available up front, with more sensitive material typically gated behind an access request.
For your own third-party risk management, a trust centre can meaningfully speed up the lower-risk end of your assessment work. Checking a vendor's trust centre before sending a full questionnaire often answers a good proportion of your standard questions immediately, and a vendor's published subprocessor list is frequently the fastest way to see which AI or fourth-party providers actually sit behind their product.
That said, a trust centre supplements judgement rather than replacing it. RiskRecon's State of TPRM research found that only 4% of organisations have high confidence their vendor questionnaires reflect what is actually happening at the vendor, and a published SOC 2 report is only ever a snapshot of a defined audit period, not an ongoing guarantee.
The same logic applies in reverse. If your organisation is regularly asked to complete security questionnaires by your own customers, a trust centre can reduce that burden considerably. Industry estimates from trust centre providers suggest security teams without one can spend 8–12 hours a week answering repetitive questionnaires, time a smaller organisation rarely has spare.
Publishing your own certifications, policies, and standard answers up front means fewer repetitive requests landing on your team, and it signals a level of maturity that can genuinely support new business conversations. It does not remove the need for a robust underlying security programme, though, a trust centre only works if what it publishes is actually true.
AI Supply Chain Risk: The Fourth Party You Cannot See
Third-party risk management has always had to contend with an assessment blind spot: your suppliers' own suppliers, commonly known as fourth-party risk. Artificial intelligence has made this significantly harder to ignore. Vendors are rapidly embedding AI features and large language models into their products, often sourced from a separate AI provider you have never assessed, never contracted with, and may not even know is there.
This is not a distant concern. SecurityScorecard's 2026 Supply Chain Cybersecurity Trends Report found that security leaders now rank AI-driven threats as their single biggest supply chain risk, yet 67% still rely on the same static, point-in-time audits they were using five years ago.
The exposure runs in two directions. On the offensive side, attackers are using AI to accelerate reconnaissance and scale supply chain attacks against vendors faster than an annual review can keep pace with. On the exposure side, a vendor's own use of AI to process, store, or train on your data introduces a new category of fourth-party cyber risk that traditional supplier due diligence rarely asks about.
Questions to Add to Your Vendor Risk Assessment
Your existing third-party risk management questionnaire was probably not designed with AI in mind. A handful of additional questions can close much of that gap:
Does the vendor use AI or large language models to process any of our data?
Is our data used to train or fine-tune third-party AI models, and can this be disabled?
Which AI or model providers sit behind the vendor's product, and have they been assessed?
Is the vendor's use of AI disclosed, governed, and subject to human review?
Does the vendor have visibility into their own AI supply chain — in other words, your fourth parties?
Not every vendor relationship needs this level of scrutiny. But for suppliers handling sensitive data, or those already flagged as higher risk in your existing framework, AI and fourth-party questions belong alongside the standard security, incident response, and certification checks. Governing your own organisation's use of AI is a related but separate discipline, covered in more depth in our companion article, "AI and Cyber Security: Opportunity, Risk, and What You Should Be Thinking About Now."
Contractual and Operational Controls
Assessment is only part of the picture. Contractual controls play an important role in managing third-party risk. Security requirements should be embedded in contracts from the outset, including obligations around data handling, incident notification timescales, audit rights, and compliance with relevant standards.
Operationally, managing third-party access is critical. This includes applying the principle of least privilege, ensuring third parties have only the access they need to perform their function, reviewing and revoking access when relationships change, and monitoring third-party activity within your environment where possible.
These controls are not about distrust. They are about applying the same rigour to external relationships that you would to internal access management. The organisations you work with will generally expect and respect this approach.
Building a Proportionate Framework
One of the biggest barriers to effective third-party risk management is the perception that vendor risk assessment requires an enormous amount of resource. For smaller organisations with limited teams, the prospect of assessing every supplier can feel overwhelming.
The key is proportionality. Not every third-party relationship carries the same risk, and your approach should reflect this. Start by identifying your most critical and highest-risk relationships — those with access to sensitive data, your network, or your core systems. Focus your detailed assessment and monitoring on these relationships first.
Over time, you can extend your programme to cover a broader set of suppliers, using lighter-touch assessments for lower-risk relationships. Technology platforms can help to streamline the process, enabling you to manage assessments, track risk, and maintain an up-to-date view of your third-party landscape without it becoming a full-time job.
The important thing is to start. Even a basic understanding of your critical third-party relationships and their security posture is significantly better than no visibility at all.
If you are unsure where to begin, a structured third-party risk management review, covering vendor risk assessment, contractual controls, and ongoing monitoring, is often the fastest way to close the gap between what you assume is secure and what is actually happening within your supply chain.
How ICA Consultancy Can Help
ICA Consultancy helps UK organisations build proportionate third-party risk management frameworks, from vendor and AI supply chain risk assessment to contractual controls and ongoing monitoring. Whether you are addressing traditional supplier risk or the growing exposure from AI embedded across your fourth-party ecosystem, we can help you focus your effort where it matters most.
Get in touch: info@icaconsultancy.co.uk | 0330 122 7115




Comments