Vendor & Third-Party Risk: A Guide
Every vendor with access to your systems, data, or payments extends your attack surface beyond your own walls. Some of the most damaging incidents affecting public entities began at a trusted supplier. Here is KYND's guide to understanding and managing vendor and third-party cyber risk.
What is vendor and third-party risk?
Vendor and third-party risk is the cyber risk you inherit from outside organizations you rely on — software providers, managed IT service providers (MSPs), cloud and payroll platforms, data processors, and contractors. It includes supply chain attacks, where compromising one vendor's software or access lets an attacker reach many of that vendor's customers at once.
Why is it such a significant risk?
Your defenses only extend as far as the weakest organization holding your data or a connection into your network. Vendor access is trusted by design, so a compromised supplier account or software update can bypass perimeter controls entirely — and you may not learn of the breach until the vendor discloses it, long after the exposure began.
Why are public entities exposed?
Public entities outsource heavily — IT support, payment processing, records management — often with a small internal team overseeing many suppliers. Procurement rules can favor lowest-cost bids over security maturity, and pool members frequently share the same regional vendors, meaning a single vendor compromise could affect many members simultaneously.
What if we don't manage vendor risk?
A breach at a vendor holding your data can still trigger your notification obligations, service disruptions, and recovery costs. Without contractual security requirements, you may have no right to timely breach notice, no audit rights, and limited recourse — leaving your entity absorbing the consequences of someone else's security failure.
Which frameworks should we align to?
NIST Cybersecurity Framework (CSF) 2.0 elevated supply chain risk into its Govern function (cybersecurity supply chain risk management), alongside Identify and Protect. CIS Controls v8 addresses it directly through Control 15 (Service Provider Management), which covers inventorying, classifying, assessing, and monitoring providers.
Process defenses: know and hold your vendors accountable
Maintain an inventory of vendors with access to systems or sensitive data, and tier them by criticality. Build security requirements into contracts — breach notification within a defined timeframe, MFA, encryption, and cyber insurance — and reassess critical vendors at each renewal, including their own exit or continuity plans.
Technical controls that reduce vendor risk
Give vendors the least access required, using individual named accounts rather than shared logins, with MFA enforced. Disable dormant vendor accounts promptly, segment vendor connections away from critical systems, and log and review remote vendor sessions so unusual activity can be spotted early.
Checklist
When building or reviewing your vendor risk management program, consider the following:
- Do you maintain a current inventory of vendors with access to your systems or sensitive data?
- Are vendors tiered by criticality, with security assessments for those in the highest tier?
- Do contracts require breach notification within a defined timeframe and minimum security controls?
- Is vendor remote access limited to least privilege, with MFA and named individual accounts?
- Are dormant or expired vendor accounts disabled promptly and reviewed on a schedule?
- Do you have an exit plan for critical vendors, including return or destruction of your data?