Menu
Visit COzPro

Third-Party Cyber Risk

14 September 2026

Cyber 5

How Do You Manage Third-Party and Supply Chain Cyber Risk?

Most organisations rely on other businesses to operate. 

Cloud providers, software platforms, managed service providers, consultants, outsourced support and other technology suppliers may access systems, process information or support services that are critical to day-to-day operations. 

Those relationships create dependencies. 

Your organisation may have strong internal cyber controls, but a security weakness, service failure or cyber incident within a critical supplier can still affect your data, customers and operations. 

Third-party cyber risk management is about understanding those dependencies and making informed decisions about which suppliers require greater scrutiny, what assurance you need and how those risks will be managed throughout the relationship. 

Why Does Third-Party Cyber Risk Matter? 

Working with external suppliers often means giving another organisation access to something important. 

That could include: 

  • Personal or customer data 
  • Commercially sensitive information 
  • Internal systems 
  • Cloud environments 
  • User accounts 
  • Software integrations 
  • Operational processes 
  • Critical infrastructure or services 

The level of exposure varies significantly. 

A supplier providing a low-risk standalone service presents a very different risk from a cloud provider hosting a business-critical platform or a managed service provider with privileged access to your systems. 

Good third-party risk management recognises that difference. 

The objective is not to apply the same level of assurance to every supplier. It is to understand which relationships could cause significant harm if something went wrong. 

Do You Know Which Suppliers Are Critical? 

A useful starting point is knowing which third parties the organisation relies on and what role they play. 

A supplier inventory can help identify: 

  • What service the supplier provides 
  • Which business services depend on it 
  • What systems or information it can access 
  • Whether personal or sensitive data is involved 
  • Whether the supplier has privileged access 
  • Where important data is processed or stored 
  • Which other providers the supplier depends on 
  • How difficult the service would be to replace 
  • What would happen if the supplier became unavailable 

This allows organisations to classify suppliers according to risk and criticality. 

Without that visibility, assurance activity can become inconsistent. Low-risk suppliers receive unnecessary scrutiny while important dependencies remain poorly understood. 

What Should You Assess Before Appointing a Supplier? 

Cyber risk should be considered before a critical supplier is embedded into the organisation. 

The level of due diligence should reflect the nature of the relationship. 

For a higher-risk technology supplier, organisations may need to understand areas such as: 

  • Information security governance 
  • Access controls 
  • Data protection arrangements 
  • Vulnerability and patch management 
  • Incident response 
  • Business continuity and disaster recovery 
  • Security testing 
  • Employee security practices 

Support can range from assessing current cyber risk management and priorities, through implementing practical improvements, to ongoing support as the risk environment and business evolve. 

  • Use of subcontractors 
  • Data location and processing 
  • Relevant certifications or independent assurance 
  • Previous significant security incidents 

The aim is not simply to complete a supplier questionnaire. 

It is to understand whether the supplier’s controls are appropriate for the risk the organisation would be accepting by using them. 

Are Security Certifications Enough? 

Certifications can provide useful assurance, but they should be considered in context. 

A recognised standard such as ISO/IEC 27001 may demonstrate that a supplier has established an information security management system and undergone independent assessment. 

That can be valuable evidence. 

But it does not automatically answer every question about the specific service being purchased, the information involved or the risks associated with the relationship. 

Organisations should understand what any certification covers and whether additional assurance is needed for the service being provided. 

The question is not simply, “Does the supplier have a certificate?” 

It is “Do we have enough confidence in this supplier for the role we are asking them to perform?” 

What Should Cyber Security Contracts Cover? 

Due diligence tells you about the supplier before the relationship begins. Contracts help establish what is expected once it does. 

Depending on the service and risk involved, contractual requirements may need to address areas such as: 

  • Information security responsibilities 
  • Data protection and confidentiality 
  • Access to systems and information 
  • Security incident notification 
  • Cooperation during an investigation 
  • Business continuity and recovery 
  • Use of subcontractors 
  • Security assurance requirements 
  • Audit or information rights 
  • Data return or deletion 
  • Requirements when the relationship ends 

Responsibilities need to be clear. 

If a cyber incident occurs, discovering at that point that the customer and supplier had different assumptions about notification, investigation or recovery can significantly increase the impact. 

What About Your Supplier’s Suppliers? 

Third-party risk does not necessarily stop with the organisation you contract with. 

Your supplier may rely on cloud platforms, software providers, data processors, support partners and other subcontractors to deliver its service. 

Those fourth-party dependencies can be difficult to see. 

Organisations do not need to investigate every company within every supplier’s ecosystem. But where a service is particularly critical, it is reasonable to understand significant dependencies and how the primary supplier manages them. 

Questions might include: 

  • Does the supplier use subcontractors to deliver the service? 
  • Do those organisations have access to our information? 
  • Are critical services dependent on another technology provider? 
  • How does the supplier assess its own third parties? 
  • Are we informed when important subcontractors change? 
  • Could a failure elsewhere in the chain interrupt our service? 

The more critical the service, the more important that visibility becomes. 

Does Supplier Assurance Stop Once the Contract Is Signed? 

No. 

A supplier’s risk profile can change throughout the relationship. 

Its technology may change. New subcontractors may be introduced. The service may become more important to your organisation. The supplier may experience a security incident or its financial and operational circumstances may change. 

Assurance therefore needs to continue where the level of risk justifies it. 

That might involve: 

  • Periodic supplier reviews 
  • Updated assurance information 
  • Reviewing significant incidents 
  • Monitoring agreed security actions 
  • Reviewing changes to certifications 
  • Testing continuity arrangements 
  • Reviewing access 
  • Reassessing criticality when services change 
  • Monitoring important contractual obligations 

The frequency and depth should be proportionate to the risk. 

A critical provider may require regular oversight. A low-risk supplier may need very little ongoing activity. 

What Happens If a Supplier Has a Cyber Incident? 

Organisations should consider this before an incident occurs. 

If a critical supplier experiences a cyber attack, you may need to understand: 

  • Whether your systems or information are affected 
  • What information has been compromised 
  • Whether access needs to be restricted 
  • What services may be disrupted 
  • What the supplier is doing to contain the incident 
  • Who needs to be informed 
  • Whether regulatory or contractual obligations apply 
  • What alternative arrangements are available 
  • How recovery will be coordinated 

Clear escalation routes and contractual responsibilities make this easier. 

Supplier incidents should also feed back into the organisation’s own cyber risk management. A significant event may change the risk associated with the relationship or identify controls that need strengthening. 

How Do You Manage Supplier Risk Without Creating Too Much Administration? 

The answer is risk-based segmentation. 

Not every supplier requires a lengthy security assessment, annual review and extensive contractual controls. 

Start by classifying suppliers according to factors such as the service they provide, the information they access, their level of system access, the operational dependency they create and the potential impact of failure. 

Higher-risk relationships receive greater scrutiny. 

Lower-risk suppliers follow a simpler route. 

This makes assurance more manageable and directs effort towards the relationships that could genuinely affect the organisation. 

It also helps prevent third-party risk management becoming a large administrative process that generates questionnaires without materially reducing risk. 

How Does Third-Party Risk Connect With AI? 

AI is adding another dimension to supplier risk. 

Organisations may purchase dedicated AI tools, but AI functionality is also increasingly being incorporated into existing software and cloud platforms. 

That can change how organisational information is processed, where it is sent and what third parties do with it. 

Supplier assessment may therefore need to consider whether AI is being used within a service and what that means for data, confidentiality, intellectual property and decision-making. 

This connects third-party assurance with the wider question of whether the organisation is in control of how AI is being used. 

How Can KA2 Help Manage Third-Party Cyber Risk? 

KA2 helps organisations develop a practical, risk-based approach to supplier assurance. 

We can help identify critical third parties, establish appropriate risk classifications and determine what due diligence and ongoing oversight different supplier relationships require. 

We can also help organisations connect supplier risk with wider cyber governance and risk management so that important third-party dependencies are visible to the people responsible for making decisions. 

The aim is not to create more supplier administration. 

It is to make sure the organisation understands where external dependencies create meaningful risk and has appropriate controls around them. 

Know Who You Depend On 

Modern organisations cannot operate without third parties. 

The objective is therefore not to eliminate supplier risk. It is to understand it. 

Knowing which suppliers matter, what access and dependencies they create and how those relationships would affect the organisation if something went wrong allows cyber assurance to focus where it is needed most. 

Talk to KA2 about strengthening third-party and supply chain cyber risk management. 

Stylisic background graphic of a slanting color block
Stylisic background graphic of a slanting color block