Why Third-Party Risk Is a First-Party Problem
Organizations increasingly depend on vendors, managed service providers, SaaS platforms, and contractors who have access to their systems, networks, and data. When any of these vendors is compromised, the attackers potentially have access to every customer of that vendor. The SolarWinds attack affected thousands of organizations because a trusted software update mechanism was compromised. MSP-targeting ransomware campaigns have encrypted networks of dozens of businesses simultaneously through a single compromised MSP tool. Your security posture is only as strong as the weakest link in your supply chain.
Third-Party Risk Assessment Framework
- Inventory your vendors — Identify every third party with access to your systems, data, or networks. This is harder than it sounds; most organizations discover vendors during an assessment that they had forgotten about.
- Classify by risk level — Tier vendors based on the access they have and the data they can reach. A SaaS tool for expense reports is lower risk than an MSP with domain administrator access.
- Collect security documentation — Require SOC 2 reports, penetration test attestation letters, or completion of a security questionnaire from high-risk vendors. For critical vendors, consider independent assessment.
- Contractual protections — Security requirements, breach notification timelines, right to audit, and data handling obligations should be in vendor contracts.
- Limit access — Third parties should have the minimum access needed to perform their function. Broad network access for a vendor who needs to reach two servers is a liability, not a convenience.
- Review regularly — Vendor relationships change. Access that was granted for a specific project should be revoked when the project ends. Annual vendor access reviews prevent accumulation of unnecessary third-party exposure.
Asking Your Vendors About Penetration Testing
For high-risk vendors, asking whether they conduct annual independent penetration testing — and requesting the attestation letter as evidence — is reasonable due diligence. Vendors who cannot demonstrate a current security testing program represent elevated risk. Organizations subject to NYDFS specifically must address third-party service provider risk as part of their cybersecurity program.
Demonstrate your own security posture to your clients.
Grid32 provides the penetration testing and attestation documentation that your clients and partners may require as part of their vendor due diligence process.
Get a Quote →