Third-Party Risk

The chance that your data leaks through a supplier, a freelancer or a plugin you trusted, rather than through your own team.

Also known as supplier risk vendor risk supply chain risk

Definition

Third-party risk is the danger that comes from the people and the software you did not build yourself. The accountant with a login to your finance system. The marketing agency that still has an administrator account from a campaign two years ago. The delivery firm that reads your orders through a connection nobody wrote down. The plugin on your website made by a stranger and last touched in 2021.

Most owners guard the front door. The danger rarely comes that way. It comes through a door you opened yourself and forgot to close. The pattern repeats. A supplier is broken into. The attacker finds the login that supplier held for you. He walks in wearing that supplier's name. Your own passwords were never touched, and your records show an ordinary working day.

The cheapest fix is a list. Write down every outside company and every piece of software that can reach your data, who inside your business owns that relationship, and exactly what each one can see. Most owners are surprised by the length of it. Then remove what nobody needs. An account unused for six months is not a convenience. It is a spare key under a mat, and it is usually the way in. When Linkysoft takes over a system somebody else ran, that list is the first thing we ask for, and it is almost never ready.

Before you hand access to a software supplier, ask four plain questions and keep the answers in writing. Who on your team will have a login to my system, and may I see the names? Will you connect anything of your own to it, and where does that thing keep my data? What happens on the day one of your staff leaves? And if you are broken into, how quickly do you tell me, and how? A supplier who answers without stalling has told you a great deal. One who calls the questions unnecessary has told you more.

Linkysoft answers those four in writing before a web application project starts, and every account we hold is named after a real person and closed at handover. If nobody has ever written down who holds keys to your systems, that is the first afternoon of any security review, and it costs almost nothing.

Questions about Third-Party Risk

What counts as a third party?
Anyone outside your company who can reach your systems or your data. Suppliers, agencies, freelancers and accountants, and also the software they install, including plugins and add-ons.
How do I check a supplier without being rude?
Ask while you are still buying, in writing, next to price and dates. Serious suppliers expect it and answer within a day. It is part of the deal, not an accusation.
Who is responsible if a supplier loses my customers' data?
Usually you are, in the eyes of your customers and often in law as well. A contract can share the cost, but the apology and the damage stay with your name.
What is the fastest thing I can do this week?
List every account that belongs to somebody outside the company, then close the ones nobody has used for six months. One afternoon removes most of the forgotten doors.
Do small companies really need to worry about this?
More than large ones. A small business uses more outside help per person, and one shared agency password often opens the website, the email and the invoices at once.

Still not sure how this applies to your project?

Tell us what you are building and we will answer in plain language.