Third-Party and Supply Chain Risk Management
Third-party and supply chain risk management is the practice of identifying, assessing, and mitigating the cyber risk carried by suppliers, service providers, software components, and the fourth parties they depend on. It extends the security program past the organization's own boundary, because a breach at a supplier or a flaw in a widely used component becomes the organization's incident with a longer commute.
itCybersecurity fundamentals and governance | OpenSkills.info
Course pathWalk it in order
Look it upDip in anytime
Go furtherLeaves this page
Don't Panic
Don't Panic — Third-Party and Supply Chain Risk Management
Third-party and supply chain risk management is what you do when you accept that a breach at a supplier or a flaw in a widely used component becomes your incident with a longer commute. It is the security program extended past your own boundary, because the controls on your estate do not protect you from a compromise that arrives through a vendor with valid access.
The thing that catches people is the shared responsibility line. A SaaS platform is secure, and the customer accounts on it are not. That is the customer's breach, not the vendor's. The 2024 Snowflake campaign was not a breach of the platform; it was a breach of customer accounts that had no multi-factor authentication. The lesson generalizes: your exposure depends on how you use the supplier, not just on which supplier you picked.
The load-bearing idea is tiering by criticality, not spend. A small vendor with privileged access to your critical systems is a higher tier than a large vendor with no sensitive access. Sorting the inventory by contract value puts the commodity supplier at the top and the dangerous small one at the bottom, and the assessment effort follows the sort. NACD's board questions ask for criticality-based classification because that is the classification that allocates the work where the risk is.
The second idea is that the fourth party is the part no one maps. Your supplier has a contract; your supplier's sub-processor does not. The risk inherits silently. A fourth party you cannot name is one you cannot assess, and the breach that arrives through it is a surprise at every layer of the program. Forcing the supplier to name and assess its own sub-processors is the work, and it is the work teams skip.
The surprise is that the contract is where the assessment becomes enforceable. A security obligation written into a contract without an audit right and a remedy is marketing. A breach notification window of "as soon as practicable" is a window the regulator will replace with a number, after you have missed your own deadline. A change-of-control clause is what stops your critical supplier's estate from being inherited by an entity you never assessed.
The recurring failure is concentration without exit. Standardizing on one widely used supplier or component is efficient and usually the right call, until the 2021 Kaseya compromise disrupts 1,500 downstream businesses at once. Monitoring the concentration does not make it acceptable; it makes the cascade visible. The real mitigation is an exit path, which costs more than monitoring and is the one teams skip.
The recent shift is that the disclosure clock now follows the supplier. The SEC cyber rule connects third-party cyber risk governance to board oversight, and your materiality clock can start during a supplier incident before the supplier's root cause is known. Your supplier's notification window is the input to your clock, not the trigger for it.
Read the Intro for the three layers of exposure and the four C-SCRM layers. Keep the Cheatsheet beside a live supplier register. The Practice Reference carries the onboarding assessment, the reassessment trigger, and the supplier-breach response plan. The Exercise tests whether you can tier and govern a critical supplier rather than rubber-stamp a low-spend one. Field Notes carries the costly mistakes that a clean contract can hide.
Where this skill leads
Relevant careers
See how this topic contributes to broader role-level skill maps.
Sources
- https://csrc.nist.gov/pubs/sp/800/161/r1/upd1/final
Supports
- Foundational US framework for cybersecurity supply chain risk management practices
- Identifying, assessing, and mitigating risk across the ICT/OT supply chain lifecycle from design through destruction
- Risks include counterfeits, unauthorized production, tampering, theft, malicious software and hardware, and poor development practices
- C-SCRM Program Management Office or risk function for smaller organizations
- https://csrc.nist.gov/projects/cyber-supply-chain-risk-management
Supports
- NIST C-SCRM project scope and foundational resources
- SECURE Technology Act and Federal Acquisition Security Council authority for C-SCRM guidelines
- Quick-start guides, the SCRM assessment scoping questionnaire, and the due diligence resources
- https://csrc.nist.gov/pubs/sp/1326/final
Supports
- C-SCRM Due Diligence Assessment Quick-Start Guide
- Structured starting point for proportionate, tier-based supplier due diligence
- https://www.nacdonline.org/all-governance/governance-resources/governance-research/director-handbooks/2026-cyber-risk-oversight/cyber-risk-handbook-toolkit-2026/third-party-and-supply-chain-cyber-risk/
Supports
- Verizon 2025 DBIR finding that third-party involvement in breaches doubled from 15 percent to 30 percent
- Board oversight must extend to third- and fourth-party dependencies
- SEC disclosure rules require boards to report on governance of third-party cyber risk
- Classify vendors by criticality of service and data access rather than contract size
- Clear cybersecurity standards and responsibilities must be defined in contracts and enforceable
- Limits of liability and insurance coverage for a third-party incident must be adequate
- Realistic simulations should model a failure or disruption from a critical third party
- Snowflake 2024 as a shared responsibility failure on a secure platform
- MOVEit 2023 as systemic software supply chain risk from one flaw in a widely used tool
- Kaseya 2021 as concentration risk disrupting 1,500 downstream businesses
- 2024 XZ-utils backdoor as a foundational open-source tool compromise
- https://www.sec.gov/rules-regulations/2023/07/s7-09-22
Supports
- Public-company disclosure requirements connect material cybersecurity incidents, risk processes, management roles, and board oversight
- Third-party cyber risk governance is part of board oversight
- The organization's materiality clock can start during a supplier incident
- https://www.enisa.europa.eu/publications/threat-landscape-for-supply-chain-attacks
Supports
- European perspective on the supply chain threat landscape
- Maps and studies supply chain attacks, attacker techniques, and mitigation recommendations
- https://www.fedramp.gov/
Supports
- US federal authorization program for cloud services
- Third-party assessment and continuous monitoring model for supplier assurance
- https://csrc.nist.gov/pubs/sp/800/218/final
Supports
- Secure Software Development Framework practices a software supply chain risk program expects of suppliers
- https://www.cisa.gov/cross-sector-cybersecurity-performance-goals
Supports
- Common protections that set the baseline a third-party risk program expects of suppliers
- https://pages.nist.gov/OSCAL/
Supports
- Machine-readable format for control catalogs, profiles, and assessment results supporting supplier assessment sharing
- https://slsa.dev/
Supports
- Supply-chain Levels for Software Artifacts framework for software supply chain integrity assurance
- https://www.iso.org/standard/82875.html
Supports
- ISO/IEC 27001 standard a third-party risk program asks suppliers to demonstrate certification against
- https://github.com/sindresorhus/awesome
Supports
- Discovery of curated community lists relevant to vendor risk, supply chain security, and GRC tooling
- https://www.servicenow.com/products/governance-risk-and-compliance.html
Supports
- Supplier inventory, tiering, due diligence, and continuous monitoring with reassessment triggers
- https://www.onetrust.com/products/third-party-risk/
Supports
- Proportionate tier-based due diligence with sub-processor mapping and breach notification workflows
- https://www.processunity.com/solutions/third-party-risk-management/
Supports
- Tiered assessment and trigger-based reassessment on acquisition, breach, or posture change
- https://www.aravo.com/
Supports
- Supplier inventory and tiering with fourth-party mapping and contractual controls tracking
- https://www.bitsight.com/
Supports
- Continuous external posture signal for supplier monitoring between formal assessments
- https://securityscorecard.com/
Supports
- External rating and continuous monitoring with fourth-party visibility
- https://www.blackkite.com/
Supports
- External cyber risk ratings with supplier-tier-aware monitoring
- https://www.prevalent.net/
Supports
- Supplier assessments, continuous monitoring, and evidence repository tying controls to audit rights
- https://www.whistic.com/
Supports
- Supplier security questionnaire and SOC 2 report exchange with versioning
- https://vanta.com/
Supports
- Continuous control monitoring shared by suppliers as current evidence
- https://drata.com/
Supports
- Continuous evidence sharing proving controls are operating now rather than at the last audit date
- https://www.hyperproof.io/
Supports
- Evidence repository tying supplier assessment to contractual controls and audit rights
- https://www.qualys.com/
Supports
- Technical posture assessment for customer-side controls under a shared responsibility model
- https://www.tenable.com/
Supports
- Exposure management surfacing customer-side configuration gaps in a shared responsibility model
- https://www.mandiant.com/services/incident-response
Supports
- Incident response retainers activating when a supplier breach becomes the organization's incident
