Third-Party Risk
The chance that your data leaks through a supplier, a freelancer or a plugin you trusted, rather than through your own team.
Also known as supplier risk vendor risk supply chain risk
Definition
Third-party risk is the danger that comes from the people and the software you did not build yourself. The accountant with a login to your finance system. The marketing agency that still has an administrator account from a campaign two years ago. The delivery firm that reads your orders through a connection nobody wrote down. The plugin on your website made by a stranger and last touched in 2021.
Most owners guard the front door. The danger rarely comes that way. It comes through a door you opened yourself and forgot to close. The pattern repeats. A supplier is broken into. The attacker finds the login that supplier held for you. He walks in wearing that supplier's name. Your own passwords were never touched, and your records show an ordinary working day.
The cheapest fix is a list. Write down every outside company and every piece of software that can reach your data, who inside your business owns that relationship, and exactly what each one can see. Most owners are surprised by the length of it. Then remove what nobody needs. An account unused for six months is not a convenience. It is a spare key under a mat, and it is usually the way in. When Linkysoft takes over a system somebody else ran, that list is the first thing we ask for, and it is almost never ready.
Before you hand access to a software supplier, ask four plain questions and keep the answers in writing. Who on your team will have a login to my system, and may I see the names? Will you connect anything of your own to it, and where does that thing keep my data? What happens on the day one of your staff leaves? And if you are broken into, how quickly do you tell me, and how? A supplier who answers without stalling has told you a great deal. One who calls the questions unnecessary has told you more.
Linkysoft answers those four in writing before a web application project starts, and every account we hold is named after a real person and closed at handover. If nobody has ever written down who holds keys to your systems, that is the first afternoon of any security review, and it costs almost nothing.
Questions about Third-Party Risk
What counts as a third party?
How do I check a supplier without being rude?
Who is responsible if a supplier loses my customers' data?
What is the fastest thing I can do this week?
Do small companies really need to worry about this?
Still not sure how this applies to your project?
Tell us what you are building and we will answer in plain language.