TL;DR: Supply chain attacks are increasingly using compromised non-human identities and delegated access to move through trusted relationships, with major incidents like the Sisense breach underscoring how third-party exposure can widen blast radius according to Saviynt. The lesson is that identity governance must extend beyond direct employees to vendors, service accounts, and machine credentials before trust becomes an attack path.
At a glance
What this is: This is a Saviynt analysis of the Sisense breach and the wider rise in supply chain attacks that exploit third-party identity exposure.
Why it matters: It matters because IAM and NHI programmes now need to govern vendor access, delegated credentials and offboarding discipline as part of supply chain risk management.
Context
Supply chain identity risk is the point where trusted external access, machine credentials and vendor relationships create an attack path instead of a control boundary. In practice, the issue is not only who gets access, but how long that access persists, how much privilege it carries, and whether it is governed like an enterprise identity.
Saviynt uses the Sisense breach to show that third-party exposure can widen the blast radius of an incident even when the initial compromise sits outside the primary organisation. That makes lifecycle governance, credential scope and third-party offboarding core identity security concerns, not adjacent procurement issues.
The article positions this as a widening governance gap for enterprises that still treat vendor access as exceptional rather than routine. That starting position is now typical, not atypical, across modern SaaS, cloud and software supply chains.
Key questions
Q: What breaks when third-party access is not lifecycle managed?
A: Access outlives accountability. When vendor credentials are not tied to a clear offboarding process, old support paths, dormant accounts, and overbroad entitlements remain available after the business need has ended. That creates a standing exposure window that attackers can exploit and auditors will struggle to explain.
Q: Why do vendor credentials create such a large supply chain risk?
A: Because they often grant authenticated access that bypasses normal perimeter checks and can persist across many connected services. A single credential may reach multiple systems, which means compromise can spread through legitimate trust rather than noisy exploitation. The larger the integration graph, the larger the blast radius.
Q: How do teams know if identity security controls are actually working?
A: Identity security controls are working when teams can show a current view of high-risk entitlements, detect privilege drift quickly, and remove access before exposure spreads. A useful sign is reduced time between entitlement change and policy review. Another is fewer unresolved conflicts between approved access and actual production permissions.
Q: What should organisations do when a vendor relationship changes?
A: They should revoke or narrow the vendor’s access as part of the relationship change itself, not as a separate cleanup task. Offboarding, service substitution, and integration retirement all need a deliberate access removal step or old privileges will outlive the business need.
Technical breakdown
How third-party identity exposure turns trust into an attack path
Third-party identity exposure means external vendors, integrations and service relationships hold credentials or delegated permissions inside the enterprise trust boundary. Once those credentials exist, the attacker does not need to defeat the primary organisation directly; they can abuse the trusted path already established through supplier access, support tooling or connected accounts. In supply chain incidents, the control failure is often not initial authentication but the absence of tight lifecycle governance around who can still use that trust relationship and under what conditions.
Practical implication: inventory every external identity path and treat each one as a governed trust relationship, not a one-time setup task.
Why non-human identities amplify blast radius in supplier-linked incidents
Non-human identities such as API keys, service accounts, tokens and certificates are especially dangerous in supply chain compromise because they are designed to operate quietly and at scale. They often persist longer than human access, are reused across systems, and can bypass the visibility that teams expect from interactive logins. When an external compromise lands on an NHI, the attacker can often move through connected systems without triggering the same review and approval patterns used for human accounts.
Practical implication: apply ownership, rotation and offboarding controls to NHIs that cross organisational boundaries.
How delegated access changes the meaning of least privilege
Delegated access is not safer just because it is indirect. In supply chain environments, least privilege must be defined for the actual business task, the exact data set, and the precise time window, otherwise a vendor account becomes a durable lateral movement route. The problem is magnified when teams grant broad roles for support efficiency and then leave them in place after the need has passed. That turns a temporary integration into standing privilege through another name.
Practical implication: recertify vendor permissions as task-scoped access, not as permanent partner entitlements.
Threat narrative
Attacker objective: The attacker seeks to leverage a trusted third-party identity path to expand access beyond the initially compromised environment and increase downstream exposure.
- Entry occurred through a trusted supplier or third-party identity path rather than direct compromise of the primary target.
- Credential access or delegated permission abuse let the attacker operate inside connected environments using legitimate trust relationships.
- Escalation followed when the exposed access reached broader systems, increasing the blast radius across customer or partner data.
- Impact was amplified because third-party trust converted one compromise into a wider supply chain incident.
Breaches seen in the wild
- Sisense breach 2024: A credential in Sisense's GitLab reportedly opened S3 buckets of customer tokens, passwords and certificates; CISA urged a full reset.
- reviewdog Action compromise 2025: A stolen maintainer token poisoned reviewdog/action-setup, leaking CI secrets including the tj-actions bot token used in the next attack.
Read and download The State of NHI & AI Agent Breach Report 2026, covering 200+ breaches impacting Non-Human Identities including AI Agents.
NHI Mgmt Group analysis
Supply chain identity risk is becoming a lifecycle problem, not a point-in-time breach problem. The Sisense example fits a broader pattern in which third-party access survives longer than the business assumption that justified it. When access is granted for integration, support or delivery, it is rarely re-evaluated with the same discipline at offboarding or contract change. The practitioner conclusion is that supplier access must be governed as an identity lifecycle, not as a static connection.
Third-party exposure widens blast radius because trust is transitive. If a vendor can reach data, support workflows or machine credentials, the compromise of that vendor can become the compromise of the primary organisation. That is why supply chain incidents increasingly look like identity incidents in practice, even when the first foothold is not inside the target. The implication is that external access needs the same privilege scoping and recertification pressure as internal access.
Ephemeral access is not enough when the underlying trust model remains permanent. Short-lived sessions do not solve the deeper problem if vendor relationships still permit broad and recurring identity reuse. The named concept here is identity blast radius: how far a single external identity can propagate across systems before governance intervenes. Practitioners should measure that radius across third parties, not just count connected accounts.
Vendor access without lifecycle offboarding is the failure mode that supply chain breaches keep exposing. The relationship changes, but the credentials, tokens or delegated paths remain valid. That breaks the assumption that partner access is self-limiting, and it leaves the enterprise with permanent trust in a temporary relationship. The conclusion is straightforward: offboarding discipline is a security control, not an administrative afterthought.
Converged governance across human, NHI and partner access is now a field requirement. The identity perimeter no longer ends at employee IAM or at internal service accounts. Modern supply chains mix human support accounts, machine credentials and delegated integrations in the same trust chain. A practitioner who governs those in separate silos will miss how one compromise becomes many. The conclusion is to unify governance across all identity types that can reach production data.
From our research library:
- 92% of organisations expose NHIs to third parties, raising concerns about supply chain security, according to the Ultimate Guide to NHIs.
- 59% of compromised machines in a major 2025 supply chain attack were CI/CD runners rather than personal workstations, according to the State of Secrets Sprawl 2026.
- Read next: Ultimate Guide to NHIs — Key Research and Survey Results
What this signals
Identity blast radius is the useful lens here: supply chain incidents are no longer just about whether a vendor was breached, but how far that vendor's access could travel before governance intervened. That makes third-party recertification, credential ownership and offboarding discipline core control points for any programme that extends into cloud or SaaS.
The practical shift is toward governing supplier access as a living identity estate. If vendor accounts, tokens and support permissions are not tracked with the same discipline as internal identities, a single external compromise can become a multi-system event before anyone notices.
For practitioners
- Map every third-party identity path Inventory vendor accounts, API keys, service accounts and delegated tokens that can reach production systems, then record the business owner and offboarding trigger for each one.
- Reduce standing partner privilege Replace broad vendor roles with task-scoped access, and require time-bound approvals for support and integration access that crosses trust boundaries.
- Tie credential lifecycle to contract lifecycle Revocation should happen when the relationship changes, not when someone notices misuse, so vendor access must be retired as part of procurement and offboarding.
- Review machine credentials shared with suppliers Treat tokens, certificates and API keys held by third parties as enterprise credentials, with rotation and revocation tracked the same way as internal secrets.
- Test the blast radius of a partner compromise Simulate what one supplier account can reach across cloud, SaaS and support tooling, then narrow any path that exceeds the actual business need.
Key takeaways
- Supply chain breaches increasingly succeed by abusing trusted third-party identity paths rather than by attacking the primary target head-on.
- The article's cited figures show how widespread third-party NHI exposure has become and why CI/CD infrastructure can sit in the compromise path.
- Enterprises need lifecycle controls for supplier access, not just onboarding checks, because offboarding and scope reduction are what shrink blast radius.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
OWASP Non-Human Identity Top 10 and MITRE ATT&CK address the attack and risk surface, while NIST CSF 2.0 sets the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| OWASP Non-Human Identity Top 10 | NHI-03 — Vulnerable Third-Party NHI | The article centres on third-party identities widening supply chain exposure. |
| NHI-01 — Improper Offboarding | The risk pattern depends on external access surviving relationship changes. | |
| NHI-05 — Overprivileged NHI | Broad third-party roles increase the blast radius of a supplier compromise. | |
| Recommendation — Map supplier accounts and delegated access to NHI-03 and remove any path without a clear business owner. Tie partner offboarding to NHI-01 and revoke every credential when the relationship changes. Use NHI-05 to shrink vendor permissions to task-scoped access with explicit expiry. | ||
| NIST CSF 2.0 | PR.AA-05 — Access Permissions, Entitlements and Authorizations | The article is fundamentally about governing entitlements across external identities. |
| Recommendation — Apply PR.AA-05 to review and limit third-party entitlements across your identity estate. | ||
| MITRE ATT&CK | TA0006;TA0008 — Credential Access; Lateral Movement | The breach pattern turns credential abuse into wider movement through trusted connections. |
| Recommendation — Map supplier compromise paths to TA0006 and TA0008 to prioritise detection on exposed trust routes. | ||
Key terms
- Third-party identity exposure: Third-party identity exposure is the risk that external suppliers, contractors, partners, or their systems can access an organization through identities that are not directly controlled by the organization. It includes shared accounts, delegated access, tokens, and integrations. The exposure increases when identity lifecycle, privilege, and monitoring are weak.
- Identity Blast Radius: The amount of damage a compromised identity can cause across systems, data, and infrastructure. In NHI environments, it is shaped by permissions, network reach, and administrative capability rather than by the credential alone. Reducing blast radius is a containment strategy that limits lateral movement and data exposure.
- Delegated Access: Delegated access is permission granted to one identity to act on behalf of another user, service, or system. In NHI environments, this usually appears in OAuth-connected apps and automation tooling. It is powerful, but it must be tightly scoped and reviewed because it can persist long after the original business need ends.
- Vendor offboarding: Vendor offboarding is the controlled removal of a third party's access, data paths, and operational dependencies when the relationship ends or changes. It is a lifecycle control, not an administrative closeout, because any surviving credentials or integrations remain active security exposure.
Deepen your knowledge
NHI governance, agentic AI identity, and machine identity lifecycle are core topics in our NHI Foundation Level course, the industry's only accredited NHI security programme. If you are building or maturing an IAM programme, it is worth exploring.
Published by the NHIMG editorial team on June 9, 2026.
Updated on October 7, 2026.
NHI Mgmt Group, the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org