In 2020, SolarWinds distributed an update to 18,000 customers. Hidden inside that update was malware that gave attackers access to some of the most secure networks in the world — including US government agencies. They didn't breach the perimeter. They walked in through the front door, inside a trusted software update.
This is not an isolated incident. It is a pattern.
The Scope of the Problem
The modern enterprise runs on third-party services, software, and contractors. Think about who currently has access to your systems: software vendors with remote support agreements, SaaS platforms integrated with your identity provider, managed service providers with admin rights, contractors with VPN access, accounting and legal firms with access to sensitive data.
In a typical enterprise, this list runs to dozens of relationships. Each has its own security posture — or lack of one. And in many cases, they have privileged access to your most sensitive systems.
What Third-Party Attacks Look Like
Supply chain compromise. Malware injected into legitimate software updates, signed with trusted certificates, bypasses endpoint controls and runs inside your network with application-level permissions.
MSP pivot. The REvil Kaseya attack (2021) compromised over 1,500 businesses through a single MSP platform. Admin-level access to the MSP became admin-level access to every client.
Contractor credential compromise. Contractors have VPN credentials. Their home environments are unmanaged. A malware infection on their personal laptop is a foothold in your network.
SaaS OAuth over-permissioning. Third-party apps request OAuth tokens with broad permissions — access to your entire email history, all files, all contacts — and most organisations have no inventory of what they've granted.
What Effective TPRM Looks Like
- Know what you have. Build and maintain a comprehensive inventory of third-party access relationships.
- Classify by risk. An MSP with domain admin rights is very different from a read-only analytics tool.
- Require security evidence. A DPA doesn't protect you from a breach caused by your vendor. Require SOC 2 reports or independent security assessments for high-risk vendors.
- Scope access tightly. Time-limited. Minimum required. Revoked immediately when the engagement ends.
- MFA on all third-party accounts. No exceptions.
- Monitor third-party activity. Same scrutiny as privileged internal accounts.
NIS2 and Third-Party Risk
NIS2 Article 21 explicitly extends security obligations to supply chain security. Organisations subject to NIS2 are expected to have an ongoing TPRM programme — not a one-time questionnaire at contract signing.