August 9, 2026
You Can Outsource the Service, Not the Risk: Rethinking Third-Party Cybersecurity
Very few modern organisations operate independently.

By Howard Nwonu
2 min read
Businesses rely on cloud providers, payroll platforms, payment processors, software vendors, managed service providers and numerous other suppliers.
These relationships create enormous operational value.
They also extend the organisation's security environment beyond infrastructure it directly controls.
Start With the Relationship, Not the Questionnaire
Third-party security reviews can easily become long questionnaires filled with generic controls.
A better starting point is understanding what the supplier will actually do.
Will they process customer information?
Will they connect directly to production systems?
Will they receive privileged accounts?
Will they host a critical business application?
Could their outage stop the organisation from operating?
The answers determine the depth of assessment required.
Risk should drive due diligence.
Certifications Provide Evidence, Not Certainty
Security certifications and independent assurance reports can provide valuable information about a supplier's control environment.
They shouldn't automatically end the assessment.
The organisation still needs to understand whether the supplier's controls are relevant to the specific service being purchased and the risks created by the integration.
A certificate doesn't understand your architecture.
Access Is a Critical Question
Third parties may require accounts, API credentials, VPN access or administrative privileges to deliver services.
Those access paths should be governed deliberately.
Apply least privilege.
Use appropriate authentication controls.
Monitor important activity.
Review accounts periodically.
Remove access promptly when it is no longer required.
A forgotten supplier account is still an account an attacker may attempt to exploit.
Understand the Data
Organisations should know what information suppliers receive, why they need it, where appropriate how it is protected, and what happens when the relationship ends.
Data minimisation is useful here.
If a supplier only needs five fields to perform a function, sending an entire customer record may create unnecessary exposure.
Incident Notification Matters
When a supplier experiences a security incident affecting your organisation, speed matters.
Contracts and operational processes should establish appropriate communication expectations and escalation paths.
Your incident-response plan should also account for incidents originating outside infrastructure you control.
A third-party breach can still become your incident.
Risk Changes Over Time
Supplier assessment should not end immediately after onboarding.
Services evolve.
Integrations become deeper.
New information is shared.
Subcontractors change.
Organisations merge or are acquired.
Security posture changes.
The level and frequency of ongoing review should reflect the importance and risk of the relationship.
Offboarding Is Part of Security
Ending a supplier relationship creates its own security tasks.
Accounts may need disabling.
API keys may need revoking.
Network connections may need removing.
Data may need returned or securely disposed of according to applicable requirements.
An incomplete offboarding process can leave unnecessary access long after the commercial relationship has ended.
Final Thought
Third-party services are fundamental to modern business.
The objective isn't to eliminate supplier risk.
It's to understand and manage it proportionately throughout the relationship.
Ask what the supplier can access.
Understand what happens if they fail.
Apply appropriate controls.
And keep reviewing the relationship as it changes.
Because while a service can be outsourced, your need to understand the risk cannot.