← All writing

Cutting Through the Noise

You can outsource the software. Not the blast radius.

"We vet our vendors." Everyone says it. And still, the breach that reaches you rarely arrives through the vendor you vetted.

This summer a market-intelligence provider was compromised. The damage didn't stop at its own walls. Through integrations its customers had switched on, the intrusion reached close to 200 downstream companies. Several of them were security firms.

That last detail is the one worth sitting with. These weren't organisations with weak defences. Their perimeters held. The exposure was somewhere else entirely: an integration each had approved once and never looked at again. A token issued to let one tool talk to another, granting standing access, quietly outliving the reason it was granted.

That's the part the vendor-risk conversation keeps missing. We assess a supplier's security at onboarding, tick the box, then treat the connection as permanent furniture. But the access doesn't expire when your attention does. Every "Connect with..." you click is a door left unlocked on someone else's building, and you are trusting them to guard it as well as you guard your own.

You cannot audit your vendor's vendor. You can't see their legacy credentials or their forgotten service accounts. What you can control is what their software is allowed to reach on your side, and for how long.

So the useful questions aren't about their certifications. They're about your own grants:

  • What could this integration actually touch if the vendor were breached tomorrow?
  • Does the access still match the reason we switched it on?
  • Who owns revoking it, and by when does that happen automatically?

Third-party risk isn't a procurement form you file once. It's live, standing access you keep issuing and rarely reclaim.

You can outsource the software. You can't outsource the blast radius. The account you've forgotten about is the one they walk in through.

Related

Written by Mandeep Singh. More at the writing index or get in touch.