Third Parties

Third-Party Cyber Risk Explained

Third-party cyber risk is the exposure that comes from relying on vendors, platforms, software providers, contractors, processors, and other outside parties. An organization may have strong internal controls and still face meaningful risk through a supplier connection or dependency.

Core idea: Third-party risk should be managed across selection, contracting, onboarding, operation, change, and exit. Due diligence is only one point in a longer relationship.

What belongs in the analysis

Service criticalityHow the vendor supports essential work and the effect of interruption.
Access and dataAccounts, integrations, administrative privileges, data handling, and storage locations.
AssuranceEvidence about governance, safeguards, testing, incidents, and subcontractors.
Contract and notificationSecurity obligations, incident notice, audit rights, recovery commitments, and data return.
Ongoing oversightPerformance, changes, exceptions, incidents, concentration, and offboarding.

A practical scenario

Consider a simple scenario: a billing provider outage prevents invoices from being issued and exposes customer records even though the organization’s own network remains intact.

Use the scenario to answer two concrete questions: What business process depends on this vendor? What access, data, or concentration does the relationship create? The record becomes useful when those answers are supported by evidence and tied to a named decision owner.

Evidence worth gathering

Evidence should be proportionate to the importance of the decision. The following records commonly make the discussion more reliable:

  • Risk-tiering criteria tied to business impact
  • Completed due diligence with documented gaps
  • Contract terms aligned to identified exposure
  • Periodic review and issue tracking
  • Offboarding confirmation for access and data

A practical review sequence

  1. Clarify service criticality: How the vendor supports essential work and the effect of interruption.
  2. Describe access and data: Accounts, integrations, administrative privileges, data handling, and storage locations.
  3. Evaluate assurance: Evidence about governance, safeguards, testing, incidents, and subcontractors.
  4. Test contract and notification: Security obligations, incident notice, audit rights, recovery commitments, and data return.
  5. Confirm ongoing oversight: Performance, changes, exceptions, incidents, concentration, and offboarding.
  6. Close the review by answering: How will the relationship be monitored and ended safely?

Common failure modes

  • Approving a vendor based only on a certificate
  • Collecting questionnaires without reviewing answers
  • Failing to reassess after service or ownership change
  • Leaving accounts and data active after termination

Questions for management

  • What business process depends on this vendor?
  • What access, data, or concentration does the relationship create?
  • Which gaps require treatment before or after onboarding?
  • How will the relationship be monitored and ended safely?
Boundary: This page addresses organizational cyber-risk management. It does not provide individualized legal, insurance, compliance, incident-response or technical security advice.

Frequently asked questions

What should be documented first for third-party cyber risk?

Start with service criticality: How the vendor supports essential work and the effect of interruption.

Which evidence should receive early attention?

Begin with risk-tiering criteria tied to business impact and completed due diligence with documented gaps. The right evidence is the evidence capable of changing confidence or the treatment decision.

What commonly weakens this analysis?

One frequent problem is approving a vendor based only on a certificate. The review should make that weakness visible instead of hiding it behind a score or dashboard.

When should it be revisited?

Review it on the scheduled date and whenever the conditions behind this question change: What business process depends on this vendor?