By NHI Mgmt Group Editorial TeamBased on Saviynt: “Sisense Breach Highlights Rise in Major Supply Chain Attacks” (March 23, 2026)

TL;DR: Third-party compromise increasingly reaches identity systems, credentials, and downstream data access, according to Saviynt's analysis of recent supply chain attacks, making supplier trust paths part of the attack surface rather than a separate risk tier. IAM, NHI, and PAM controls inherit supplier failure modes when access outlives oversight.


At a glance

What this is: Saviynt examines how supply chain attacks turn third-party access into an identity security problem, not just a vendor risk problem.

Why it matters: This matters because IAM teams have to govern the identities, credentials, and privileged paths that suppliers use, or inherited access becomes the easiest route into core systems.


Context

Supply chain attacks become an identity security problem when third parties hold credentials or delegated access inside the trust path. The governance gap is not only who the supplier is, but what identities, tokens, and privileged workflows that supplier can touch once they are connected.

For IAM programmes, the question is no longer whether a third party is trusted at onboarding. It is whether that trust is continuously governed across NHI, PAM, and access review processes after integration, contract change, or incident response.

Saviynt frames the issue through recent breach reporting and supplier exposure patterns. The starting position is typical for modern enterprise ecosystems: third-party access is common, and the control model is usually behind the dependency model.


Key questions

Q: What breaks when third-party access is not fully inventoried?

A: Identity governance loses visibility into the accounts, tokens, and certificates that actually extend trust into supplier environments. That creates hidden access paths, missed revocations, and scope drift that standard reviews often do not catch. The result is not just weaker oversight, but a broader attack surface that persists after the business reason for access has changed.

Q: Why do supplier identities increase breach impact so quickly?

A: Supplier identities often connect to multiple systems, so one compromised account can unlock a much larger trust chain than a normal internal user account. If the same credential reaches production, data pipelines, and administration paths, the attacker inherits broad access from a single foothold. That is why third-party identity scope is a blast-radius issue, not a paperwork issue.

Q: How should teams detect risky third-party access before it is abused?

A: Look for external identities with broad scopes, long-lived secrets, and permissions that no longer match current contracts or operational need. Those are the strongest indicators that trust has outgrown governance. Monitoring should focus on issued credentials, last-used dates, and whether the integration still has a valid business owner.

Q: Who should own identity risk when governance spans IAM, PAM, and security operations?

A: Ownership should sit with the identity programme, but it must be operationally linked to security and compliance teams. When governance is split into disconnected functions, no one can close the loop between discovery, decision, remediation, and evidence.


Technical breakdown

Why third-party access becomes identity exposure

A supply chain attack often lands through a supplier relationship, but the operational damage comes from the identities already trusted within that relationship. These may be service accounts, OAuth grants, API keys, or delegated admin roles that persist beyond the original business need. Once those credentials are embedded in workflows, the attacker does not need to break perimeter controls again; they inherit the supplier's access path. The technical issue is that identity trust is transitive, while many governance programmes still treat third parties as external to core IAM scope.

Practical implication: inventory every third-party identity and treat it as part of your governed access estate.

Standing privilege inside supplier integrations

Supplier integrations frequently accumulate standing privilege because they are built for continuity, not task-scoped access. Long-lived credentials and broad scopes reduce friction for operations, but they also create a stable bridge into production systems when a partner account, token, or integration secret is exposed. In practice, the attack surface is often the control plane around identity issuance and revocation, not just the supplier system itself. When lifecycle discipline is weak, compromise at the partner layer turns into persistent access at the customer layer.

Practical implication: restrict third-party access to the smallest stable scope and force periodic revalidation of every integration.

Why NHI governance now sits at the center of third-party risk

Non-human identities are the connective tissue of third-party access because most supplier workflows depend on tokens, certificates, service accounts, or machine-to-machine permissions. That makes NHI governance central to supply chain security rather than a side control. The challenge is not only secrecy or rotation; it is ownership, inventory, and offboarding when a vendor relationship changes faster than the credentials do. Without that governance layer, the customer inherits the supplier's identity hygiene problems and the breach path becomes much easier to traverse.

Practical implication: place third-party NHI ownership, rotation, and offboarding under explicit governance review.


Threat narrative

Attacker objective: The attacker wants to use third-party trust to reach customer systems and extract data or maintain unauthorized access with less resistance.

  1. Entry typically occurs through a compromised supplier or integration path, where the attacker gains access to credentials, tokens, or connected workflows that the customer already trusts.
  2. Credential access follows because the attack targets standing secrets or delegated permissions rather than direct user login, allowing the attacker to operate as the supplier identity.
  3. Escalation and lateral movement happen when that supplier identity has broader scope than the business use case required, exposing adjacent systems and downstream data flows.
  4. Impact appears as data theft, unauthorized access, or further compromise of customer environments through the trusted third-party channel.
  • reviewdog Action compromise 2025: A stolen maintainer token poisoned reviewdog/action-setup, leaking CI secrets including the tj-actions bot token used in the next attack.
  • Sisense breach 2024: A credential in Sisense's GitLab reportedly opened S3 buckets of customer tokens, passwords and certificates; CISA urged a full reset.

Read and download The State of NHI & AI Agent Breach Report 2026, covering 200+ breaches impacting Non-Human Identities including AI Agents.


NHI Mgmt Group analysis

Third-party access is now an identity governance domain, not a procurement afterthought. When suppliers sit in the execution path, their accounts, tokens, and certificates become part of the enterprise identity estate. The practical consequence is that IAM, PAM, and NHI controls must extend to external operators, not stop at the firewall boundary.

Supplier trust creates identity blast radius. The risk is not just that a vendor may be compromised, but that one trusted integration can open multiple downstream systems at once. That is why privilege scope and lifecycle ownership matter more than the supplier label itself. Practitioners should read supply chain risk as a question of how far a third-party identity can travel once issued.

Standing access outlives business intent in most third-party models. Contracts change, integrations remain, and revocation often lags behind reality. This is the control gap supply chain attackers exploit most often: access persists because offboarding is not tied tightly enough to operational change. The implication is that third-party identity governance must be measured against actual relationship state, not annual review cycles.

NHI governance is the control plane for supplier risk. Tokens, service accounts, API keys, and certificates are how most third parties touch enterprise systems, so they are the true objects of governance. If those identities are invisible or unmanaged, the organisation is effectively trusting unknown machines inside its own trust boundary. Practitioners should treat external machine identities as first-class governance objects.

Supply chain attacks validate a broader market shift toward converged identity security. The boundary between human IAM, NHI governance, and privileged access is disappearing in operational terms. A third-party breach now tests all three at once, which means fragmented ownership creates blind spots that attackers can turn into reach. Security teams should expect supplier risk reviews to become identity reviews.

From our research library:

What this signals

Identity blast radius is the right way to think about supply chain risk. Third-party compromise is not only a vendor problem because the damage depends on how far supplier identities can move once they enter the enterprise trust path. IAM teams should measure blast radius by reach, not by vendor count.

External machine identities need the same lifecycle discipline as internal ones. If a supplier token, certificate, or service account is still valid after the business relationship changes, the organisation has created residual trust. That is a governance failure, not a detection failure.

92% of organisations expose NHIs to third parties, raising concerns about supply chain security, according to the Ultimate Guide to NHIs. That scale means external identity governance is no longer edge-case work; it is core programme design for NHI, PAM, and access review teams.


For practitioners

  • Inventory every third-party identity Build a live register of supplier accounts, tokens, certificates, API keys, and delegated roles that can reach internal systems.
  • Tie access to relationship state Revoke or narrow third-party access when contracts change, vendors are offboarded, or integrations are no longer actively needed.
  • Scope supplier permissions tightly Replace broad standing access with task-specific permissions and separate production access from non-production use cases.
  • Review machine credentials first Prioritise service accounts and integration secrets in access reviews, because they often bypass the scrutiny given to human users.
  • Test third-party offboarding Verify that removing a supplier relationship actually removes every credential, token, and trust path that relationship created.

Key takeaways

  • Supply chain attacks become identity incidents when third-party accounts, tokens, and certificates are trusted inside core systems.
  • The main weakness is lifecycle drift: supplier access often outlives the business relationship that justified it.
  • Practitioners need a shared control model for external identities, with inventory, scope control, and revocation tied to relationship changes.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

OWASP Non-Human Identity Top 10 and MITRE ATT&CK address the attack and risk surface, while NIST CSF 2.0 sets the governance and control requirements practitioners need to meet.

FrameworkControl / ReferenceRelevance
OWASP Non-Human Identity Top 10NHI-03 — Vulnerable Third-Party NHISupplier identities and their exposure through trusted third-party access are the article's central risk.
NHI-05 — Overprivileged NHIThe risk described is broad, persistent access granted to external identities.
NHI-07 — Long-Lived SecretsSupplier integrations often rely on credentials that remain valid long after the business need changes.
Recommendation — Inventory and govern third-party NHIs so supplier access is reviewed, scoped, and revoked like any other privileged identity. Reduce third-party permissions to the minimum operational scope and remove standing privilege where possible. Rotate and expire supplier secrets on a governance schedule tied to relationship changes and usage.
MITRE ATT&CKTA0006;TA0008 — Credential Access; Lateral MovementThe attack pattern depends on accessing supplier credentials and moving through trusted paths.
Recommendation — Map third-party credential exposure to TA0006 and TA0008, then hunt for reachable downstream systems.
NIST CSF 2.0PR.AA-05 — Access Permissions, Entitlements and AuthorizationsThe article is fundamentally about governing external permissions and entitlements.
Recommendation — Apply PR.AA-05 to external identities so access is approved, scoped, and periodically revalidated.

Key terms

  • Third-Party Identity: An identity issued to a partner, vendor, contractor, or external service that can access internal systems. These identities often sit outside normal employee governance and can become persistent trust paths if they are not reviewed, expired, and revoked on schedule.
  • Identity Blast Radius: The amount of damage a compromised identity can cause across systems, data, and infrastructure. In NHI environments, it is shaped by permissions, network reach, and administrative capability rather than by the credential alone. Reducing blast radius is a containment strategy that limits lateral movement and data exposure.
  • Standing Privilege: Standing privilege is access that remains active even when no immediate task requires it. For NHI programmes, it is a common failure mode because long-lived credentials and persistent roles create unnecessary exposure. Reducing standing privilege usually means tighter expiry, on-demand access, and clearer review of who or what still needs access.
  • External Identity Offboarding: External identity offboarding is the process of removing every account, token, key, certificate, and delegation path tied to a supplier relationship. Unlike simple account deletion, it requires checking downstream integrations and hidden trust paths so access truly ends when the business relationship ends.

Deepen your knowledge

NHI governance, agentic AI identity, and machine identity lifecycle are core topics in our NHI Foundation Level course, the industry's only accredited NHI security programme. If you are building or maturing an IAM programme, it is worth exploring.
NHIMG Editorial Note
Published by the NHIMG editorial team on June 24, 2026.
Updated on October 7, 2026.
NHI Mgmt Group, the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org