Skip to main content
Category: Third-Party and Supply Chain

Third-Party Cyber Risk

Also known as: Vendor Cyber Risk, Supply Chain Cyber Risk, Third-Party Cybersecurity Risk
Simply put

Third-party cyber risk is the potential for cybersecurity harm to an organization arising from the vendors, suppliers, service providers, and partners it works with. If one of those external parties suffers a security incident, the effects can extend to the organization that relies on them. Managing this risk generally involves identifying, assessing, monitoring, and reducing the cyber threats connected to these external relationships.

Formal definition

Third-party cyber risk refers to the cybersecurity exposure an organization inherits from external parties in its ecosystem or supply chain, including vendors, suppliers, and service providers. It encompasses the possibility that such a party experiences a security incident that propagates to or otherwise affects the relying organization. This risk is typically addressed through third-party risk management (TPRM) processes, identifying, assessing, monitoring, and mitigating the associated cybersecurity and, in many programs, related compliance risks. The evidence available describes the concept and TPRM at a general level; the specific controls, contractual requirements, and regulatory obligations that apply depend on jurisdiction, sector, the nature of the relationship, and an organization's own risk assessment, and are out of scope here.

Why it matters

Organizations increasingly depend on an extended network of vendors, suppliers, and service providers to deliver core operations, and each of those relationships can introduce cybersecurity exposure that the relying organization does not directly control. When an external party suffers a security incident, the consequences can propagate to the organizations that depend on it, meaning a firm's effective risk surface extends well beyond its own systems and perimeter. This is why third-party cyber risk is generally treated as a distinct focus within enterprise risk and cybersecurity programs rather than as an afterthought to internal controls.

The governance challenge is that accountability for the underlying security often sits with the third party, while the business impact, operational disruption, data exposure, or related compliance consequences, typically lands on the relying organization. This misalignment makes identification, assessment, and ongoing monitoring of external relationships important, because a control that is well designed inside the organization does nothing to address weaknesses in a vendor's environment. The degree of exposure varies with the nature of the relationship, the access or data involved, and an organization's own risk assessment.

For boards and senior management, third-party cyber risk illustrates how oversight responsibilities can extend to relationships the organization does not operate directly. The specific contractual protections, due diligence steps, and regulatory obligations that apply depend on jurisdiction, sector, and entity type, and are outside the scope of this entry. This entry is educational and not legal, audit, or compliance advice.

Who it's relevant to

Boards and board risk committees
Boards and their risk committees generally hold oversight responsibility for the organization's approach to cyber risk, including risks arising from external relationships they do not directly operate. Their role is typically to satisfy themselves that management has established a process for identifying, assessing, and monitoring third-party cyber risk, rather than to perform the operational assessment work themselves.
Chief risk and chief information security officers
Risk and security leaders are typically responsible for the design and operation of the third-party risk management process, including how vendors and partners are inventoried, assessed, and monitored on an ongoing basis. They generally own the integration of third-party cyber risk into the broader enterprise risk and cybersecurity programs.
Compliance officers
Because TPRM is often described as addressing both cybersecurity and related compliance risks from external relationships, compliance functions may be involved where third-party incidents could create regulatory or contractual exposure. The specific obligations that apply depend on jurisdiction, sector, and the nature of the relationship and are out of scope here.
Procurement and vendor management functions
Teams that select and manage external relationships are often the point at which third-party cyber risk assessment is embedded into onboarding and ongoing relationship management. They typically operate the day-to-day activities of maintaining vendor inventories and coordinating due diligence and monitoring.
Internal audit and assurance functions
Assurance functions may evaluate whether the third-party risk management process is designed appropriately and operating effectively, providing independent perspective to the board and management. Their role is generally assurance over the process rather than ownership of the risk itself.

Inside Third-Party Cyber Risk

Vendor and Supply Chain Exposure
The cyber risk that arises when an organization relies on external parties, such as suppliers, service providers, or technology vendors, whose systems, access, or security weaknesses can affect the organization's own information assets and operations. The scope typically extends beyond direct contractors to subcontractors and fourth parties, though visibility often diminishes further down the chain.
Access and Data Sharing Arrangements
The connections, credentials, network access, or data flows granted to a third party. The nature and extent of access generally shape the level of risk, and understanding what data or systems a third party can reach is typically a prerequisite to assessing exposure.
Due Diligence and Ongoing Monitoring
The pre-contract assessment of a third party's security posture and the continued oversight of that posture over the life of the relationship. These are generally distinct activities; a point-in-time assessment does not, by itself, provide continuous assurance.
Contractual and Assurance Mechanisms
Provisions such as security requirements, audit or reporting rights, incident notification obligations, and independent assurance reports that parties may use to allocate responsibility and obtain evidence about a third party's controls. Their availability and enforceability vary by jurisdiction, sector, and the bargaining position of the parties.
Accountability and Ownership
The internal question of who owns third-party cyber risk. Management typically owns the operational activities of vendor selection, assessment, and monitoring, often within a first or second line function, while the board or a relevant committee generally holds oversight responsibility. The specific allocation depends on the entity's structure and governance model.
Residual Risk After Controls
The risk that remains after a third party's and the organization's controls are considered. Third-party cyber risk is frequently characterized by the fact that the organization retains accountability for outcomes even where it has transferred an activity, so residual risk may persist despite contractual transfer.

Common questions

Answers to the questions practitioners most commonly ask about Third-Party Cyber Risk.

Is third-party cyber risk just a technology or IT security problem?
No. While technical controls are part of the picture, third-party cyber risk is generally treated as an enterprise risk that spans procurement, legal, compliance, operations, and business ownership as well as information security. Framing it solely as an IT issue tends to obscure the accountability of the business units that own the vendor relationships and the assurance functions that provide independent challenge. Under a three-lines model, the business and its supporting functions typically own and manage the risk in the first line, risk and compliance functions provide oversight and challenge in the second line, and internal audit provides independent assurance in the third. The precise allocation depends on the organization's structure and risk framework.
Does transferring a service to a third party also transfer responsibility for the associated cyber risk?
Generally not. Outsourcing an activity does not, on its own, transfer accountability for the underlying risk or for related legal and regulatory obligations. In many jurisdictions and under various regulatory expectations, the contracting organization remains responsible for the outcomes of activities it delegates, even where a contract allocates certain liabilities to the vendor. Contractual terms, indemnities, and insurance may reallocate some financial consequences, but the board and management typically retain oversight responsibility. Whether and how liability shifts is fact-specific and depends on the contract, applicable law, and sector-specific rules; this is not legal advice.
Who within the organization should own and oversee third-party cyber risk?
Ownership and oversight are typically distributed rather than held by a single function. The business unit that engages a third party generally owns the relationship and the associated risk as part of the first line. Second-line functions such as risk management, compliance, and information security commonly set policy, define standards, and provide challenge. Internal audit typically provides independent assurance over the design and operating effectiveness of the program. The board or a designated committee generally holds oversight responsibility, satisfying itself that management has an adequate program in place. The specific mapping should reflect the organization's governance structure and risk framework.
How should third parties be prioritized for cyber due diligence and monitoring?
A common approach is risk-based tiering, in which vendors are segmented according to factors such as access to sensitive data or systems, criticality to operations, and the potential impact of a compromise. Higher-tier relationships generally warrant more rigorous due diligence, stronger contractual controls, and more frequent monitoring, while lower-tier relationships may be subject to lighter procedures. Distinguishing inherent risk (before controls) from residual risk (after controls) can help calibrate the level of scrutiny. The appropriate tiering criteria and thresholds depend on the organization's risk appetite and are a matter for management judgment.
What contractual provisions are commonly used to manage third-party cyber risk?
Organizations frequently address cyber risk through contract terms covering areas such as security control requirements, data handling and confidentiality, breach and incident notification obligations, audit or assessment rights, subcontractor (fourth-party) flow-down requirements, and termination and exit provisions. Some regulatory regimes prescribe specific contractual elements for certain sectors or types of outsourcing, so requirements vary by jurisdiction, industry, and the nature of the arrangement. Contract terms are one control among several and are generally more effective when supported by ongoing monitoring rather than relied upon in isolation. Specific drafting should involve legal counsel.
How can an organization gain assurance that a third party's cyber controls actually operate effectively?
Assurance approaches commonly include reviewing independent audit reports or attestations, evaluating questionnaires and self-assessments, conducting or commissioning assessments, and using continuous monitoring where available. A useful distinction is between control design, which concerns whether a control is capable of addressing the risk, and operating effectiveness, which concerns whether the control functions as intended over time; evidence of both is generally sought. Point-in-time evidence may not reflect the vendor's posture throughout the relationship, so periodic reassessment is often appropriate. The adequacy of any assurance approach depends on the risk tier and the organization's own judgment.

Common misconceptions

Outsourcing an activity to a third party transfers the associated cyber risk and the organization's accountability along with it.
Contracting with a third party may allocate certain responsibilities and liabilities, but in many jurisdictions and under common regulatory expectations the organization generally retains accountability for protecting its data and operations. A contract typically addresses residual risk allocation rather than eliminating the organization's own exposure or oversight duties.
A completed onboarding security assessment or assurance report means the third party is secure for the life of the relationship.
Due diligence is generally a point-in-time exercise, whereas a third party's security posture, personnel, subcontractors, and threat environment change over time. Ongoing monitoring is typically treated as a separate and continuing activity rather than something satisfied by a single assessment.
Third-party cyber risk is solely a technical or IT matter to be handled operationally.
While assessment and monitoring often involve technical functions, third-party cyber risk generally intersects governance, risk management, and compliance. Management typically owns the operational work, but board or committee oversight, risk appetite considerations, and any applicable regulatory obligations mean it is not exclusively a technical responsibility.

Best practices

Maintain an inventory of third parties that classifies them by the access, data sensitivity, and criticality involved, so that assessment and monitoring effort can be prioritized proportionately to exposure.
Distinguish point-in-time due diligence from ongoing monitoring, and establish a schedule and triggers (such as contract renewal, incidents, or changes in the relationship) for reassessment throughout the vendor lifecycle.
Clarify in advance who owns each element of third-party cyber risk, separating management's operational responsibility for selection, assessment, and monitoring from the board's or committee's oversight role.
Use contractual mechanisms such as security requirements, incident notification timelines, audit or reporting rights, and independent assurance to obtain evidence, while recognizing that enforceability and available leverage vary by jurisdiction and relationship.
Seek visibility into material subcontractors and fourth parties where feasible, acknowledging that assurance generally weakens further down the supply chain and documenting the limits of that visibility.
Assess residual risk after controls and confirm it aligns with the organization's stated risk appetite and tolerance, escalating exposures that exceed those thresholds to the appropriate governance body.
Treat these steps as educational guidance rather than legal, audit, or compliance advice, and confirm specific obligations against applicable laws, regulations, and frameworks relevant to the entity and its sector.