Third-Party Risk
Your security posture extends beyond the systems you directly control.
Modern operations run on other people's systems. Suppliers hold your data, integrations hold credentials into your environment, and platforms your team adopted without a procurement process hold more than anyone has counted. The APIs behind those integrations carry the same exposure — see Third-Party APIs Are Part of Your Attack Surface.
Third-party risk work is about making that exposure visible and proportionate: knowing which relationships could actually hurt, and assessing those seriously rather than assessing all of them lightly.
What is third-party risk management?
Third-party risk management reviews the security posture of suppliers that matter, classifies vendors by what they can actually reach rather than treating every supplier the same, uses security questionnaires calibrated to the relationship rather than a single template, examines what a vendor claims against what they can show, assesses what a compromise at a supplier would mean for you, prioritizes effort where exposure is real, tracks remediation issues through to resolution, and reassesses when the relationship or vendor changes. Classification has to come first — a small number of vendor relationships typically carry nearly all of the exposure, and a single questionnaire sent to every supplier regardless of access measures nothing.
Who needs it? Organizations onboarding a critical vendor about to be given access to systems or data that matter, organizations whose vendor count has grown quietly with no single view of the exposure, organizations responding to an incident at a supplier and needing to establish their own exposure, and organizations whose customers now assess their supply chain as part of assessing them.
How TMG Security helps. TMG Security classifies vendors by access, calibrates questionnaires to the relationship, reviews vendor claims against evidence, and tracks remediation to resolution, delivering output leadership can act on. This is assessment and advisory support; continuous or automated vendor monitoring is not implied, and review cadence is agreed per engagement.
A questionnaire everyone passes measures nothing
The common failure mode is a single questionnaire sent to every supplier regardless of what they can reach. It generates effort on both sides, everyone answers reassuringly, and the output does not distinguish between a design tool and a provider holding customer records.
Classification has to come first. What a vendor can access determines how much scrutiny the relationship deserves — and for most organizations a small number of relationships carry nearly all the exposure.
How this is put together.
Conceptual view. Review cadence is agreed per engagement — continuous vendor monitoring is not implied.
What this covers
SCOPE OF SERVICEAssessment and advisory support. Continuous or automated vendor monitoring is not implied — review cadence is agreed per engagement.
How the programme runs
- 01INVENTORYEstablish which third parties exist, including unofficial ones.
- 02CLASSIFYSort by access and by what a compromise would mean.
- 03ASSESSReview the relationships that carry real exposure.
- 04PRIORITIZEFocus remediation where it changes the risk picture.
- 05TRACKFollow issues through to closure.
- 06REVIEWReassess on an agreed cadence and on material change.
When Does Vendor Risk Become Your Risk?
Output leadership can act on.
Which of these apply depends on engagement scope.
Where current practice differs from the requirements that apply to you.
Which controls address which requirements, and where nothing does.
What the gaps mean in terms of risk, not just non-conformity.
What needs to exist in writing, and what it needs to say.
Whether you could demonstrate a control operates, if asked.
Sequenced work, with dependencies made explicit.
A version of the findings that a board or exec team can act on.
Adjacent parts of the programme.
Questions we get asked before an engagement.
Fewer, more thoroughly. Most organizations find that a small number of relationships carry the bulk of the exposure, and depth on those beats a shallow pass across everything.
Not by default, and we would not imply otherwise. Assessment is point-in-time unless a review cadence is explicitly agreed. Anyone offering genuine continuous monitoring is describing a different product with different limitations.
That is itself a finding, and a useful one. Where a supplier will not provide assurance, the question becomes whether the access they hold is proportionate to the visibility you are given — which is a commercial decision informed by a security view.
We can advise on the security expectations worth including, but contract drafting and legal terms are matters for legal counsel. We stay on the security side of that line.
Discuss Third-Party Risk
Start with the suppliers that hold your data or reach your systems. That list is usually shorter, and more alarming, than expected.
