Skip to content

Third-party risk: cheap to manage, ruinous to ignore

Many of the largest breaches of the past decade began not inside the victim but inside a trusted supplier. Third-party risk management is inexpensive to do well and catastrophic to neglect — but only if it covers every touchpoint.

Abazantum 13 July 2026 7 min read

Here is an uncomfortable pattern from the last decade of security: many of the largest, most damaging breaches did not begin with the victim being compromised. They began with a trusted supplier being compromised first. An air-conditioning contractor’s credentials that opened a path into a retailer’s network. A single file-transfer product whose flaw exposed hundreds of organisations at once. A routine software update that quietly carried an implant into thousands of enterprises. In each, the front door held — and the attacker walked in through a supplier’s.

That is the case for third-party risk management (TPRM), and it is a strange one to make, because TPRM is genuinely inexpensive to do well. The asymmetry is the whole story: modest, disciplined effort on one side; some of the most expensive incidents in corporate history on the other.

Your attack surface is not just yours

Every supplier that touches your organisation extends your attack surface. The SaaS tools holding your data, the cloud that runs your systems, the payment processor in your flow, the contractors with a login, the open-source libraries in your build, the professional-services firm with access to your files — each is a door into your business that someone else is responsible for locking.

Attackers understand this perfectly. Why spend weeks breaking a well-defended enterprise when a smaller, softer supplier already has trusted access to it? The supply chain is not a side risk; for many organisations it is now the most likely path to a serious incident.

Cheap to manage well

The good news, and the point worth stressing, is that managing this well is not hard. TPRM is a process discipline, not a technical moonshot. Done properly it comes down to a handful of unglamorous, repeatable steps:

  • Know your suppliers. A complete, current inventory of who they are and — critically — what they touch: your data, your systems, your network, your customers.
  • Tier them by risk. Proportionate effort. The cloud provider and the payment processor are not the office coffee supplier; treat them accordingly and you spend your attention where it matters.
  • Do due diligence at onboarding. Assess security posture before access is granted — certifications like ISO 27001 and SOC 2, data handling, track record — not after something goes wrong.
  • Put it in the contract. Security requirements, breach-notification timelines, a right to audit, rules for their sub-processors, and a clean exit. Leverage is highest before you sign.
  • Monitor continuously. A supplier’s security is not a snapshot; it drifts. A one-time questionnaire at onboarding is not TPRM — ongoing attestation and monitoring is.
  • Plan for their failure. Assume a supplier will be breached one day. Know how you would detect it, respond, and offboard them without taking your own operations down.

None of that is expensive. All of it is cheaper than a single breach, a regulatory penalty, or a critical service going dark because a vendor did.

Ruinous to ignore

The cost of neglect runs in the opposite direction. A supplier-borne breach carries the same price as any other — data loss, remediation, notification, downtime, reputational damage — except you were compromised through a door you did not control and may not even have known was open. In regulated sectors the bill is higher still: regimes such as DORA in the EU now make managing ICT third-party risk an explicit obligation, and operational-resilience rules expect firms to understand and control their dependence on suppliers. “Our vendor was breached” is not a defence; it is a finding.

Cheap to manage, ruinous to ignore. Few risk decisions in a business are so lopsided.

It only delivers value if it covers every touchpoint

Here is where most TPRM programmes quietly fail, and where the value is won or lost: it has to cover every touchpoint. The register that lists your obvious IT vendors but misses the marketing tool with a copy of your customer list, the contractor with standing VPN access, the sub-processor behind your headline supplier, or the open-source dependency deep in your stack — that register does not reduce your risk. It reduces your visible risk while leaving the exact gap an attacker will use.

Third-party risk is only as strong as its completeness. A programme that covers 90% of touchpoints does not remove 90% of the risk, because the breach comes through the 10% you missed. Delivering real business value from TPRM means mapping every point where an outside party touches your data, systems, network or critical services — including the fourth parties your suppliers depend on, and the concentration risk of everyone quietly relying on the same few providers.

Do that, and TPRM stops being a compliance chore and becomes an asset: procurement moves faster, resilience improves, and you can answer your own enterprise customers’ security questionnaires with confidence, because you have already done to your suppliers what they are asking you to prove.

How we help

We help organisations build TPRM that is proportionate and, above all, complete: mapping every third-party touchpoint, tiering by real risk, standing up the due-diligence, contractual and monitoring processes that keep it current, and folding it into broader cyber security and operational-resilience work. It is exactly the kind of discipline that is cheap to build, expensive to skip, and quietly decisive — the sort of unglamorous engineering that turns a security obligation into genuine business value.


Want third-party risk managed properly — every touchpoint, proportionate effort, real resilience? Get in touch.

Have a hard problem in financial technology?

Whether you are shaping a strategy, proving a concept or rescuing a programme, we would like to hear about it.