← Articles
RIPOSTE research · 2026

The Cyber Risk You Inherit From Your Suppliers

You can run your own security impeccably — every control in place, every patch applied — and still be breached through a door you do not own. Your suppliers, your software vendors, your outsourced services and the platforms that hold your data all carry cyber risk of their own, and when they are compromised, the consequences land on you. It is the risk that is not yours — right up until the moment it is.

The risk that isn't yours — until it is

Modern businesses run on other businesses. Your email and documents sit with one provider, your payments with another, your client records with a third; a dozen suppliers hold data about you or connect into your systems. Each is a potential path to you, and each is outside your walls and largely outside your view. Their weakness becomes your exposure, whether or not you ever chose to accept it.

How a supplier compromise reaches you

The routes are well worn. A compromised supplier mailbox sends a convincing invoice to your accounts team, and the payment goes to the attacker — business email compromise, riding on a relationship you trusted. Credentials stolen from one service are reused to breach another. A trusted piece of software ships a malicious update. Or the breach is simply of your data, held by a third party who was accountable for protecting it and did not. In each case your own defences were never the point of entry.

Why you can't see it

The hard part is visibility. You can audit your own environment; you cannot easily see inside your suppliers'. Security questionnaires — the usual tool — are self-reported, point-in-time, and often answered by someone whose job is to tick the box. They tell you what a supplier says about itself on the day it filled in the form, not what an attacker would actually find looking at it today. For a handful of critical suppliers that is a start; across dozens, it is unmanageable and largely unread.

The scale problem

This is fundamentally a problem of scale. A regulator, an insurer, a franchisor or an enterprise may be exposed through hundreds or thousands of organisations it does not control and cannot see into — and it still has to measure and manage that exposure. Assessing them one questionnaire at a time does not work at that size, and waiting for each to volunteer the truth is not a strategy.

Assessing third parties from the outside

There is a better approach: assess suppliers the way an attacker would — from the outside, with no cooperation required. A great deal about an organisation's security posture is observable externally, and reading it that way gives you a consistent, current, comparable picture across your whole third-party portfolio without waiting on anyone to fill in a form. It will not see everything an internal audit would, but it sees what an attacker sees — which is precisely the exposure you inherit.

Making it manageable

The goal is not to assess every supplier to the same depth — it is to see the exposure across the whole portfolio, find the organisations that are genuinely putting you at risk, and act where it counts. That is what ForgeScore is built for: reading third-party cyber risk from the outside, at portfolio scale, and turning it into one comparable picture — so you can weigh the risk your suppliers carry and manage it before it becomes yours.

Sources

  1. ASD's ACSC Annual Cyber Threat Report 2024–25 (cyber.gov.au)
  2. OAIC Notifiable Data Breaches publications (breach statistics)
About the author

Cameron McCollum — Director & Founder, RIPOSTE. He spent two decades in Australian Army intelligence — serving as Head of Intelligence on operations across the Asia-Pacific and Afghanistan — before building and leading the cyber-risk program at Lexon Insurance. He holds Master's degrees in Cyber Security Operations and Business (UNSW) and is an ISO/IEC 27001 Lead Implementer.

RIPOSTE helps organisations turn analysis like this into action.

Talk to us