TL;DR: Sisense’s breach underscores how supply chain attacks increasingly ride on third-party access paths and identity trust, with Saviynt linking the incident to broader exposure across partner and customer ecosystems. The real problem is not just compromise, but governance built on assumptions that third-party access remains bounded and reviewable.
At a glance
What this is: This is an analysis of the Sisense breach and the broader rise of supply chain identity risk, with the core finding that third-party access paths can become the real attack surface.
Why it matters: It matters because IAM, IGA, and PAM teams have to govern external access as a lifecycle problem, not as a one-time onboarding decision, especially when partners, vendors, and service accounts sit in the trust chain.
Context
Supply chain identity risk is what happens when third-party access, shared integrations, and delegated trust become the easiest path into an environment. In this case, the Sisense breach is being used to show how those paths can matter more than direct compromise of a target’s own users.
For IAM and NHI programmes, the issue is not just vendor access. It is whether partner credentials, tokens, and connected accounts are governed with the same lifecycle discipline as internal identities, including offboarding, review, and scope control.
The starting position is unfortunately typical: many organisations rely on trust relationships that were created for convenience and never fully revalidated as the ecosystem expanded.
Key questions
Q: What breaks when third-party access is not offboarded cleanly?
A: The organisation loses control of who can still reach sensitive systems after the business need has changed. That creates audit gaps, weakens incident containment, and leaves supplier access outside normal review cycles. In a NIS2 context, unrevoked vendor access is not just a security problem, it is a governance failure.
Q: Why do third-party identities increase supply chain risk?
A: Third-party identities increase risk because they depend on another organisation’s hygiene while still operating inside your trust boundary. If those credentials are long-lived, over-scoped, or difficult to revoke, they can outlast the business relationship and provide a path for lateral movement after the supplier is breached.
Q: How do security teams know if supplier access governance is failing?
A: A governance failure shows up when you cannot answer three questions quickly: who has access, what data they can reach, and when that access expires. If the answer depends on email trails, spreadsheets, or a vendor promise, the control is already weak. Frequent breaches through third parties usually indicate that access reviews are not tied to real data flow and credential lifecycle states.
Q: What is the difference between vendor risk management and identity governance?
A: Vendor risk management asks whether a supplier is acceptable overall. Identity governance asks what that supplier can access, for how long, and under what conditions. In a breach, the second question determines blast radius. That is why supplier controls must be measured as access controls, not only as contractual or compliance obligations.
Technical breakdown
How third-party identity paths widen the attack surface
Third-party identity paths create a layered trust model in which one organisation’s access can be granted through another organisation’s tooling, integrations, or support workflows. When those paths are poorly bounded, a compromise at the supplier layer can expose downstream systems without the attacker needing direct access to the primary target first. In NHI terms, the issue is not merely account compromise. It is delegated access with unclear ownership, weak scope boundaries, and insufficient revocation discipline. That makes partner and supplier relationships part of identity attack surface design, not just procurement.
Practical implication: map every external identity path, including delegated and service-led access, to a named owner and a defined offboarding point.
Why compromised third-party access is hard to contain
Containment fails when the access path is legitimate enough to blend into normal business operations. Third-party accounts often have broad visibility, support entitlements, or integration privileges that are difficult to distinguish from authorised work until abuse is already underway. If those credentials are shared, long-lived, or reused across environments, revocation becomes slower and more error-prone. This is why supply chain identity incidents are often governance failures first and intrusion events second. The technical weakness is usually not one control alone, but a chain of trust that was never made narrow enough to fail safely.
Practical implication: reduce partner privilege scope and require revocation workflows that can invalidate access across every connected system.
What supply chain identity risk reveals about lifecycle control
Lifecycle control is the missing discipline in many partner access models. Joiners and movers are often managed, but leavers are not always revoked across all integrated systems, and exceptions accumulate silently. That leaves dormant accounts, stale tokens, and orphaned vendor pathways alive long after their business purpose has ended. In identity governance terms, the problem is that review cadence does not equal lifecycle control. A review can confirm that access exists; only offboarding and re-certification tied to business ownership can prove that it should still exist.
Practical implication: tie third-party access reviews to formal lifecycle events, not only periodic certifications.
Threat narrative
Attacker objective: The attacker aims to turn supplier trust into downstream access that reaches beyond the initial compromise boundary.
- Entry begins through a trusted third-party identity path rather than through direct compromise of the primary target.
- Credential access is enabled when partner or supplier access is already present inside the trust boundary, making misuse look legitimate.
- Impact follows when that access is used to reach customer or internal ecosystems that depend on the third party’s position in the chain.
Breaches seen in the wild
- Palo Alto Networks Salesforce data theft 2025: Stolen Drift OAuth tokens exposed Palo Alto Networks CRM data, including support notes where some customers had shared credentials.
- Sisense breach 2024: A credential in Sisense's GitLab reportedly opened S3 buckets of customer tokens, passwords and certificates; CISA urged a full reset.
Read and download The State of NHI & AI Agent Breach Report 2026, covering 200+ breaches impacting Non-Human Identities including AI Agents.
NHI Mgmt Group analysis
Supply chain identity risk is now a lifecycle problem, not a perimeter problem. Once third-party access is treated as a standing relationship rather than a governed identity, the control model breaks down. That means ownership, review, and revocation must follow the relationship itself, not just the account name. Practitioners should treat supplier access as a managed identity estate.
Third-party access without lifecycle offboarding is the failure mode this breach pattern exposes. The central weakness is not simply that a vendor had access, but that access can outlive the business need that justified it. When offboarding is incomplete, partner credentials become persistent trust debt. The implication is that external identity governance has to measure revocation completeness, not just onboarding coverage.
Identity trust boundaries are becoming as important as network boundaries. In modern supply chains, the weakest identity path may sit inside the collaboration layer, not the edge firewall. That shifts security decisions toward scope limitation, ownership clarity, and exception reduction. Teams should assume that any third-party account with broad reach can become an incident multiplier.
Ephemeral trust debt: third-party access that remains valid after the business relationship, ticket, or integration need has changed. This is the practical concept the article surfaces. If trust debt is not retired alongside the relationship, organisations inherit dormant exposure that survives ordinary access reviews. Practitioners should use this lens to find where external access persists beyond its intended lifetime.
This pattern validates tighter convergence between IGA and third-party risk management. Supplier assessment without identity governance leaves a blind spot, while identity governance without third-party context misses who actually owns the access. The strongest programme designs now connect contract lifecycle, access lifecycle, and offboarding evidence. Practitioners should align those processes before the next partner compromise becomes their incident.
From our research library:
- 92% of organisations expose NHIs to third parties, raising concerns about supply chain security, according to the Ultimate Guide to NHIs.
- Read next: Ultimate Guide to NHIs — Key Research and Survey Results
What this signals
Ephemeral trust debt: third-party access that remains active after the business need has changed is now one of the clearest supply chain identity risks. Organisations should expect more incidents where the initial compromise is less important than the longevity of the trust relationship that made the compromise useful.
Supplier governance and identity governance can no longer be separated cleanly. If access reviews do not connect to contract changes, offboarding events, and ownership records, third-party credentials become persistent exposure rather than controlled access.
A practical NHI and IAM programme now needs to treat partner access as a lifecycle object. That means revocation evidence, not just access approval, becomes the real signal that external trust is under control.
For practitioners
- Map every third-party identity path Inventory partner, supplier, and integrator accounts, then tie each one to a named business owner, allowed purpose, and revocation trigger.
- Shorten external access lifetimes Replace open-ended third-party entitlements with time-bounded access that expires unless the business case is renewed.
- Re-certify supplier access on relationship change Trigger access review and offboarding when contracts end, scopes change, or vendors move roles, rather than waiting for the next periodic review.
- Limit cross-environment privilege for partners Separate support, operations, and customer-facing access so one compromised supplier identity cannot pivot through multiple systems.
- Audit dormant external credentials Look for accounts, tokens, and API keys that remain active after the original integration or service relationship has ended.
Key takeaways
- The breach pattern shows how supply chain attacks often succeed through trusted third-party identity paths rather than direct compromise of the target.
- The key governance failure is access that outlives the relationship that created it, which turns partner credentials into persistent exposure.
- The limiting control is lifecycle-based offboarding tied to ownership, scope, and revocation evidence across all connected systems.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
OWASP Non-Human Identity Top 10 and MITRE ATT&CK address the attack and risk surface, while NIST CSF 2.0 sets the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| OWASP Non-Human Identity Top 10 | NHI-03 — Vulnerable Third-Party NHI | The article centres on third-party access paths as the supply chain attack surface. |
| NHI-01 — Improper Offboarding | The risk persists when external access remains active after the business need ends. | |
| NHI-05 — Overprivileged NHI | Supply chain identity risk escalates when partner accounts hold broader reach than necessary. | |
| Recommendation — Review third-party NHI relationships for scope, ownership, and revocation gaps. Tie supplier offboarding to immediate credential and token revocation. Reduce partner entitlements to the minimum access needed for the engagement. | ||
| MITRE ATT&CK | TA0006;TA0008 — Credential Access; Lateral Movement | The article describes compromise paths that exploit trusted access and then expand reach. |
| Recommendation — Map supplier credential exposure to credential access and lateral movement detections. | ||
| NIST CSF 2.0 | PR.AA-05 — Access Permissions, Entitlements and Authorizations | The issue is governed access scope and entitlement control across external identities. |
| Recommendation — Enforce least-privilege authorisation for every third-party account and integration. | ||
Key terms
- Supply Chain Identity: The collection of credentials, tokens, workflow permissions, and publishing rights that let software move from source to deployment. In NHI terms, it is the identity layer of the pipeline, and when it is weak, compromise can propagate through legitimate automation rather than obvious malware channels.
- Third-Party Access: Third-party access is access granted to vendors, contractors, or support partners who are not direct employees of the organisation. It is higher risk than internal access because accountability, device assurance, and access duration are harder to control, so it usually requires tighter time limits and stronger auditability.
- Trust debt: Accumulated security risk created when access assumptions are not revalidated quickly enough for the pace of modern automation. In identity programmes, trust debt appears when roles, secrets, or agent permissions persist longer than the environment that justified them.
Deepen your knowledge
NHI governance, agentic AI identity, and machine identity lifecycle are core topics in our NHI Foundation Level course, the industry's only accredited NHI security programme. If you are building or maturing an IAM programme, it is worth exploring.
Published by the NHIMG editorial team on June 24, 2026.
Updated on October 7, 2026.
NHI Mgmt Group, the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org