CYBERPLANZ
  • Home
  • Services
    • 1. Cyber Governance Audit
    • ​2. Cyber Resilience Program
    • 3. Executive Cyber Advisory
    • 4. Staff Engagement & Culture Program
  • Products
  • Resources
    • The Boardroom Guide to Cyber & AI Governance
    • Board Cyber & AI Governance Self-Assessment
    • Cyberplanz Cyber Culture Dashboard
    • Cyberplanz Board Third-Party Cyber & Ai Risk Dashboard
  • About Us
  • Contact Us
  • Blogs
Picture
Picture
“Plans are of little importance, but planning is essential.”
― Winston Churchill

24 August Blog

8/24/2026

0 Comments

 

Third-Party Risk: Your Suppliers Can Become Your Biggest Cyber Vulnerability

Picture
Your organisation may have strong cybersecurity controls.
Your suppliers may not.
And increasingly, that matters.
Modern organisations rarely operate independently.
We depend on cloud providers, software vendors, accountants, payroll providers, marketing agencies, IT companies, contractors, logistics partners, consultants and countless other third parties.
Each relationship creates efficiency and expertise.
But each can also create another pathway into your organisation.
A supplier may have access to your systems.
They may hold your customer information.
They may process confidential data.
They may connect remotely to your network.
And increasingly, they may be using Artificial Intelligence to process information on your behalf.
This creates a fundamental governance challenge for Boards:
You can outsource a service. You can outsource technology. But you cannot outsource accountability for the risk.
Your Security Perimeter Has Changed
There was a time when organisations could think about cybersecurity largely in terms of protecting their own network.
That world has disappeared.
Today's organisation is an interconnected ecosystem.
Data moves between cloud platforms.
Applications communicate through APIs.
Employees collaborate with external partners.
Suppliers access organisational systems remotely.
Information is shared across multiple platforms and jurisdictions.
And AI services are increasingly being incorporated into business processes.
Your cyber environment therefore extends far beyond your own organisation.
Your suppliers have effectively become part of your security perimeter.
The problem is that you don't necessarily control how well they protect it.
Attackers Understand the Supply Chain
Why attack a large organisation directly if one of its smaller suppliers provides an easier route?
Cybercriminals understand this very well.
A major organisation may have sophisticated security controls, dedicated cybersecurity teams and substantial budgets.
One of its suppliers may have:
  • Limited cybersecurity resources.
  • Weak access controls.
  • Poor password practices.
  • Outdated systems.
  • Limited staff awareness.
  • Inadequate incident response processes.
  • Little understanding of AI-related risk.
If that supplier has privileged access, holds sensitive information or connects directly into the larger organisation's systems, it can become an attractive target.
Your cybersecurity may only be as strong as the weakest trusted connection into your organisation.
Third-Party Risk Is More Than Cybersecurity
Boards should resist viewing supplier risk as simply another technical cybersecurity issue.
Consider what happens when a critical supplier experiences a major incident.
Can you continue operating?
Can you access your data?
Can you serve customers?
Can you pay employees?
Can you communicate with stakeholders?
Can you move quickly to another supplier?
Who must notify customers or regulators?
How much reputational damage could flow back to your organisation?
These are questions about business resilience, not simply cybersecurity.
A cyber incident affecting a supplier can quickly become your business interruption.
Not Every Supplier Presents the Same Risk
One of the mistakes organisations make is treating every supplier equally.
The company supplying office furniture clearly does not create the same cyber exposure as the company hosting your customer database.
Boards should expect management to understand which suppliers are critical.
That means asking questions such as:
  • What information does the supplier hold?
  • What systems can they access?
  • How critical are they to our operations?
  • Could we continue operating without them?
  • How quickly could they be replaced?
  • What would happen if their systems were unavailable for a week?
  • Do they use subcontractors?
  • Where is our information stored?
  • What AI systems are they using?
The objective is not to create unnecessary bureaucracy around every supplier.
It is to identify where dependency creates material organisational risk.
The AI Supply Chain Is Creating a New Risk
Artificial Intelligence adds another dimension to third-party governance.
A supplier may be using AI even when your organisation isn't.
Imagine engaging an external marketing agency, legal adviser, recruitment company, software developer or consultant.
Are their employees using public AI tools?
Could your confidential information be entered into those systems?
Are AI-generated outputs being checked?
Does the supplier use AI models or services provided by another organisation?
Where does your information go?
Who retains it?
Could it be used for training?
This creates what we might call an AI supply chain.
Your organisation may therefore have excellent internal AI governance while still being exposed through suppliers with very different practices.
Boards increasingly need visibility not only into their own AI usage, but into how critical third parties are using AI when handling organisational information.
Due Diligence Must Happen Before the Contract Is Signed
Third-party cyber risk is much easier to manage before a supplier becomes embedded within the organisation.
Procurement therefore plays an important role in cyber and AI governance.
Before appointing a critical supplier, organisations should understand:
  • Their cybersecurity practices.
  • How they protect information.
  • Their incident response capability.
  • Their business continuity arrangements.
  • Their use of subcontractors.
  • Their AI governance practices.
  • Their history of significant incidents.
  • Relevant certifications or independent assurance.
The level of due diligence should reflect the level of risk.
A small supplier should not necessarily face an enormous security questionnaire simply because it is company policy.
Equally, a critical technology provider should not be approved solely because they offered the best price.
Good governance should be proportionate to risk.
Contracts Matter—But Contracts Don't Create Resilience
Contracts should clearly define expectations around areas such as:
  • Information security.
  • Privacy.
  • Incident notification.
  • Access control.
  • Data ownership.
  • Data location.
  • AI usage.
  • Subcontractors.
  • Business continuity.
  • Termination and data return.
But having clauses in a contract does not automatically make an organisation resilient.
A contract may tell you that a supplier must notify you of an incident.
It doesn't tell you whether they are capable of detecting one.
A contract may require appropriate security controls.
It doesn't prove those controls are operating effectively.
This is why governance must continue throughout the relationship.
Supplier Risk Doesn't End After Onboarding
Too many organisations assess suppliers once.
The questionnaire is completed.
The contract is signed.
The supplier is approved.
And then everyone moves on.
But organisations change.
Suppliers change.
Technology changes.
Ownership changes.
Subcontractors change.
AI usage changes.
Cyber threats change.
A supplier considered low risk three years ago may now be providing a critical service or processing substantially more information.
Third-party risk therefore requires ongoing review.
The greater the dependency, the greater the need for continuing assurance.
Don't Forget Fourth-Party Risk
There is another question Boards should increasingly ask:
Who do our suppliers depend on?
Your organisation may contract with Supplier A.
Supplier A may rely on a cloud provider, data processor, software platform or AI service.
That organisation may rely on another provider.
Your organisation can therefore become exposed to companies with which you have no direct contractual relationship.
This is sometimes called fourth-party risk.
Boards do not need a detailed map of every company in every supplier's ecosystem.
But for critical services, management should understand significant dependencies and concentrations of risk.
Concentration Risk Deserves Board Attention
Suppose ten of your critical suppliers all rely on the same cloud provider.
Individually, each supplier may appear resilient.
Collectively, the organisation may have a significant concentration risk.
The same issue can arise with:
  • Cloud infrastructure.
  • Identity providers.
  • Telecommunications.
  • Payment platforms.
  • Software providers.
  • Data centres.
  • AI platforms.
This is where individual supplier assessments can miss the bigger picture.
Boards need to understand not only who their critical suppliers are, but also where dependencies overlap.
Incident Response Must Include Suppliers
Imagine one of your critical suppliers calls tomorrow morning and says:
"We've had a cyber incident."
What happens next?
Who receives that call?
Who determines what information may have been compromised?
Who decides whether systems should be disconnected?
Who communicates with customers?
Who considers regulatory notification?
Who communicates with the Board?
And perhaps most importantly:
Have you ever tested this scenario?
Third-party incidents should be included in tabletop exercises and incident response planning.
A plan that assumes every incident originates inside your own organisation is no longer realistic.
Your Suppliers Can Also Strengthen Your Resilience
Third-party risk should not become an exercise in distrust.
Strong supplier relationships can actually improve organisational resilience.
Good suppliers bring expertise.
They identify emerging threats.
They share lessons.
They help organisations recover.
They provide capabilities that would be difficult or expensive to maintain internally.
The objective is therefore not to eliminate third-party relationships.
It is to create trusted, well-governed relationships.
Good governance should strengthen partnerships rather than simply add compliance requirements.
The Human Element Still Matters
Third-party risk ultimately comes back to people.
Someone selects the supplier.
Someone approves access.
Someone shares information.
Someone reviews the contract.
Someone notices unusual behaviour.
Someone receives the incident notification.
Someone makes the decision to continue or suspend the relationship.
Technology can help monitor third-party risk.
But judgement, communication and trust remain essential.
This is why third-party risk fits naturally into a human-centric approach to cybersecurity.
Questions Every Board Should Ask
Boards don't need to review hundreds of supplier security questionnaires.
They do need confidence that management understands the organisation's material third-party dependencies.
Some useful questions include:
Who are our most critical suppliers?
Which suppliers have access to our most sensitive information or systems?
What would happen if one of them became unavailable tomorrow?
How do we assess their cyber and AI governance practices?
How frequently are critical suppliers reassessed?
Do we understand their important subcontractor dependencies?
Are there concentrations of risk across our supplier ecosystem?
Are third-party incidents included in our response exercises?
Could we replace a critical supplier if necessary?
And perhaps most importantly:
Would we know quickly if one of our suppliers had been compromised?
From Supplier Management to Ecosystem Resilience
The language we use matters.
If third-party risk is treated purely as supplier compliance, the objective becomes collecting questionnaires and contracts.
If it is treated as ecosystem resilience, the conversation changes.
Now we ask:
Where are we dependent?
Where could disruption spread?
Where is information flowing?
Where do we have concentration risk?
Which relationships are essential to our ability to operate?
How do we strengthen resilience together?
Those are Board-level questions.
Trust, But Verify
Organisations depend on trust.
We trust employees.
We trust technology.
We trust business partners.
And we trust suppliers.
But good governance does not rely on trust alone.
It creates appropriate assurance.
Not because every supplier should be viewed with suspicion.
But because strong relationships are built on clear expectations, transparency and shared responsibility.
Boards should therefore expect management to know which third parties matter most, understand the risks they create, test critical dependencies and maintain appropriate oversight.
Because your organisation can have excellent cybersecurity controls and still experience a significant cyber incident through someone else's systems.
Your suppliers are part of your resilience.
Treat them that way.
And remember:
You can outsource the service.
You cannot outsource accountability for the risk.
Cyber resilience isn't built by technology. It's built by leadership, enabled by governance, and delivered by people.

0 Comments



Leave a Reply.

    Author

    Patrick – Founder of Cyberplanz | Business Strategist | Cyber Governance Advocate

    Patrick combines deep business experience, including an MBA with up-to-date cybersecurity expertise, including certification as a PECB ISO/IEC 27001 Lead Implementer. He helps businesses grow while staying secure—bridging the gap between cybersecurity and real-world operations with clear, human-centric solutions. Passionate about culture, clarity, and resilience, Patrick champions the belief that cybersecurity is everyone’s business—not just IT’s.

    Archives

    September 2026
    August 2026
    July 2026
    June 2026
    May 2026
    April 2026
    March 2026
    February 2026
    January 2026
    December 2025
    November 2025
    October 2025
    September 2025
    August 2025
    July 2025
    June 2025
    May 2025
    April 2025
    March 2025
    February 2025
    January 2025
    December 2024
    November 2024
    October 2024
    September 2024
    August 2024
    July 2024
    June 2024
    January 2024

    Categories

    All

    RSS Feed

Human-Centric Cyber Governance & AI Security for NZ Organisations

Picture
A Corna Consulting Company
  • Home
  • Services
    • 1. Cyber Governance Audit
    • ​2. Cyber Resilience Program
    • 3. Executive Cyber Advisory
    • 4. Staff Engagement & Culture Program
  • Products
  • Resources
    • The Boardroom Guide to Cyber & AI Governance
    • Board Cyber & AI Governance Self-Assessment
    • Cyberplanz Cyber Culture Dashboard
    • Cyberplanz Board Third-Party Cyber & Ai Risk Dashboard
  • About Us
  • Contact Us
  • Blogs