Third-Party Cyber Risk
Third-party cyber risk is the potential for cybersecurity harm to an organization arising from the vendors, suppliers, service providers, and partners it works with. If one of those external parties suffers a security incident, the effects can extend to the organization that relies on them. Managing this risk generally involves identifying, assessing, monitoring, and reducing the cyber threats connected to these external relationships.
Third-party cyber risk refers to the cybersecurity exposure an organization inherits from external parties in its ecosystem or supply chain, including vendors, suppliers, and service providers. It encompasses the possibility that such a party experiences a security incident that propagates to or otherwise affects the relying organization. This risk is typically addressed through third-party risk management (TPRM) processes, identifying, assessing, monitoring, and mitigating the associated cybersecurity and, in many programs, related compliance risks. The evidence available describes the concept and TPRM at a general level; the specific controls, contractual requirements, and regulatory obligations that apply depend on jurisdiction, sector, the nature of the relationship, and an organization's own risk assessment, and are out of scope here.
Why it matters
Organizations increasingly depend on an extended network of vendors, suppliers, and service providers to deliver core operations, and each of those relationships can introduce cybersecurity exposure that the relying organization does not directly control. When an external party suffers a security incident, the consequences can propagate to the organizations that depend on it, meaning a firm's effective risk surface extends well beyond its own systems and perimeter. This is why third-party cyber risk is generally treated as a distinct focus within enterprise risk and cybersecurity programs rather than as an afterthought to internal controls.
The governance challenge is that accountability for the underlying security often sits with the third party, while the business impact, operational disruption, data exposure, or related compliance consequences, typically lands on the relying organization. This misalignment makes identification, assessment, and ongoing monitoring of external relationships important, because a control that is well designed inside the organization does nothing to address weaknesses in a vendor's environment. The degree of exposure varies with the nature of the relationship, the access or data involved, and an organization's own risk assessment.
For boards and senior management, third-party cyber risk illustrates how oversight responsibilities can extend to relationships the organization does not operate directly. The specific contractual protections, due diligence steps, and regulatory obligations that apply depend on jurisdiction, sector, and entity type, and are outside the scope of this entry. This entry is educational and not legal, audit, or compliance advice.
Who it's relevant to
Inside Third-Party Cyber Risk
Common questions
Answers to the questions practitioners most commonly ask about Third-Party Cyber Risk.