openskills.info
Course Preview

Third-Party and Supply Chain Risk Management

Third-party and supply chain risk management is the practice of identifying, assessing, and mitigating the cyber risk carried by suppliers, service providers, software components, and the fourth parties they depend on. It extends the security program past the organization's own boundary, because a breach at a supplier or a flaw in a widely used component becomes the organization's incident with a longer commute.

itCybersecurity fundamentals and governance

Don't Panic — Third-Party and Supply Chain Risk Management

Third-party and supply chain risk management is what you do when you accept that a breach at a supplier or a flaw in a widely used component becomes your incident with a longer commute. It is the security program extended past your own boundary, because the controls on your estate do not protect you from a compromise that arrives through a vendor with valid access.

The thing that catches people is the shared responsibility line. A SaaS platform is secure, and the customer accounts on it are not. That is the customer's breach, not the vendor's. The 2024 Snowflake campaign was not a breach of the platform; it was a breach of customer accounts that had no multi-factor authentication. The lesson generalizes: your exposure depends on how you use the supplier, not just on which supplier you picked.

The load-bearing idea is tiering by criticality, not spend. A small vendor with privileged access to your critical systems is a higher tier than a large vendor with no sensitive access. Sorting the inventory by contract value puts the commodity supplier at the top and the dangerous small one at the bottom, and the assessment effort follows the sort. NACD's board questions ask for criticality-based classification because that is the classification that allocates the work where the risk is.

The second idea is that the fourth party is the part no one maps. Your supplier has a contract; your supplier's sub-processor does not. The risk inherits silently. A fourth party you cannot name is one you cannot assess, and the breach that arrives through it is a surprise at every layer of the program. Forcing the supplier to name and assess its own sub-processors is the work, and it is the work teams skip.

The surprise is that the contract is where the assessment becomes enforceable. A security obligation written into a contract without an audit right and a remedy is marketing. A breach notification window of "as soon as practicable" is a window the regulator will replace with a number, after you have missed your own deadline. A change-of-control clause is what stops your critical supplier's estate from being inherited by an entity you never assessed.

The recurring failure is concentration without exit. Standardizing on one widely used supplier or component is efficient and usually the right call, until the 2021 Kaseya compromise disrupts 1,500 downstream businesses at once. Monitoring the concentration does not make it acceptable; it makes the cascade visible. The real mitigation is an exit path, which costs more than monitoring and is the one teams skip.

The recent shift is that the disclosure clock now follows the supplier. The SEC cyber rule connects third-party cyber risk governance to board oversight, and your materiality clock can start during a supplier incident before the supplier's root cause is known. Your supplier's notification window is the input to your clock, not the trigger for it.

Read the Intro for the three layers of exposure and the four C-SCRM layers. Keep the Cheatsheet beside a live supplier register. The Practice Reference carries the onboarding assessment, the reassessment trigger, and the supplier-breach response plan. The Exercise tests whether you can tier and govern a critical supplier rather than rubber-stamp a low-spend one. Field Notes carries the costly mistakes that a clean contract can hide.

Where this skill leads

Relevant careers

See how this topic contributes to broader role-level skill maps.

Sources