Third-Party Risk has changed. Your vendor assessments should too.
Cyber Engineering 18.08.26
Your organisation’s risk perimeter no longer ends at your own network. It extends through every vendor, supplier and partner with access to your systems, data or operations.
Most organisations can list their vendors. Very few can say, with evidence, what each one can actually access, whether that access is still appropriate, or whether anything about that vendor has changed since the last time anyone looked.
That gap sits between “we did a questionnaire once” and “we know, right now, what our exposure actually is.” That’s where the risk lives.
Many leading vendor risk platforms compound the problem. They condense everything to a single, vendor-level rating, which is useful for triage but doesn’t always surface key risks in with the context of what a vendor actually does for you. A supplier who’s low-risk as a software provider isn’t automatically low-risk once they also have access to your customer data.
The numbers behind it
Third-party involvement now sits at 48 per cent of all breaches, up from 30 per cent the year before, according to Verizon’s 2026 Data Breach Investigations Report1. That is a 60 per cent rise in a single year. Vendor and partner ecosystems have become a primary route into organisations that have hardened their own perimeter.
The cost is significant. A supply chain compromise averages $4.91 million and takes 267 days to identify and contain, the longest resolution time of any initial attack vector tracked in the IBM Cost of a Data Breach Report 20252.
Damage also rarely stays with one company. A single compromised vendor can cascade to hundreds of downstream victims, as MOVEit3 and Snowflake4 both demonstrated.
A security score is not a risk picture
Most vendor risk tools measure one thing well: cyber and information security posture. They then present that single measure as the whole picture. A vendor can have excellent security hygiene and still expose you through undisclosed foreign ownership, financial instability that threatens a critical service, or a sanctions issue buried two or three ownership layers down.
Many platforms compound the problem by condensing everything into one vendor-level rating. That is useful for triage, but it hides the context of what the vendor actually does for you. A supplier who is low risk as a software provider is not automatically low risk once they also hold your customer data.
We assess six categories:
- Ownership and governance
- Operational and continuity
- Cyber and information security
- Physical security and logistics
- Reputation and integrity
- Sanctions and legal compliance
This is a deliberate design choice. The resulting view maps to genuine enterprise risk and gives the whole organisation something to work with, rather than a cyber-only assessment that only one team can use.
The ctrl:cyber approach
ctrl:cyber provide a managed, continuously validated third-party risk assessment service. Our security analysts work alongside the Tracery intelligence platform, an OSINT engine that resolves entities across public and paywalled sources: media, government data, court records, commercial data and sanctions data, at scale.
The service rests on two steps, kept deliberately separate.
Who the vendor is. A verified identity record for the vendor entity, resolved once and shared across every relationship you hold with them. Shell structures, opaque ownership and name collisions are untangled by trained analysts rather than left to automation. Get identity wrong and every risk judgement built on top of it is wrong too.
What the vendor does for you. Each relationship is assessed on its own terms: the access it has, the data it touches, the function it performs. This is where risk actually lives. There is no single score, because a vendor cleared for one purpose is never implicitly cleared for another.
Every relationship is scored against the six categories above, drawing on vendor-specific intelligence, contextual data such as data location, fourth-party dependencies, AI usage and access scope, and a configurable question bank for vendor assessment questionnaires.
Where the platform helps, and where people decide
The platform does the heavy lifting at scale. It synthesises intelligence, runs the assessment logic, and flags where a vendor’s own answers do not match independent intelligence. Every report is then reviewed by an analyst before it reaches you, checked for factual accuracy and for professional risk judgement. You receive an analyst-owned decision, produced faster and at greater scale than a manual process allows.
Keeping assessments current
Assessments aren’t static. They refresh on a defined cycle set by risk tier, and immediately on trigger: a scope change, a new relationship, or a material adverse finding. A full audit trail is retained. Every assessment, retirement and replacement is linked and traceable, so you can show a regulator or board exactly what was known, and when.
The benefits of outsourcing
Doing this properly, in-house, at scale, runs into three walls most internal teams hit.
First, identity is harder than it looks. Untangling shell structures, opaque ownership and name collisions before you can even assess a vendor is specialist, labour-intensive work most security teams don’t have the headcount for.
Second, point-in-time assessment isn’t good enough anymore. A vendor assessed as low-risk in January can look very different by March, and keeping every relationship current on a risk-appropriate cycle is a continuous operational commitment, not an annual project.
Third, risk isn’t one-size-fits-all per vendor. The same vendor can be low risk for one purpose and high risk for another, depending on access, and that needs a methodology built for it rather than a generic scorecard.
We take that operational burden off your team. Analyst and intelligence-driven assessments performed at a scale and cadence an internal function usually can’t sustain, with a human validating every judgement call before it reaches you. What you get is a defensible answer, not just a completed checklist.
How ctrl:cyber handle this
One combined, human-reviewed report per relationship, per assessment cycle, using a risk scale defined jointly with you rather than a fixed proprietary scale you have to translate for your own board reporting.
What it means for leadership teams
Third-party services are usually brought into an organisation by technology teams, working with internal cyber security to identify and address technical risks. Of the six assessment categories, that covers one. Tracery surfaces the risks that sit outside the cyber and information security domain, giving leaders a business view of the people and companies they are about to rely on.
- CEO: is anything about this vendor a reputational or strategic exposure the board doesn’t yet know about?
- CRO: the output slots directly into an enterprise risk framework, rather than sitting alongside it in an IT silo.
- CFO: financial exposure is surfaced directly: continuity disruption, regulatory penalties, concentration risk.
- CISO: you get a defensible, audit-ready answer to “what’s our third-party exposure” for the board and regulators, not a spreadsheet that’s already stale by the time it’s presented.
- GRC / Security Manager: precision replaces false reassurance. Risk-for-a-purpose scoring, human-verified identity, and a methodology that stays comparable over time because rule changes are never applied retroactively.
Cyber together
Third-party risk is a business risk, not just a technical one. ctrl:cyber helps Australian organisations see their vendor ecosystem clearly, and keep seeing it as it changes. Speak to our team to find out what your third-party exposure looks like today.
References:
[1] https://www.verizon.com/about/news/breach-industry-wide-dbir-finds
[2] https://www.ibm.com/reports/data-breach
[4] https://www.huntress.com/threat-library/data-breach/snowflake-data-breach