Join our Newsletter — 33% off our NHI Course

Notifications
Clear all

Third-party cyber risk: what data reach means for IAM teams


(@nhi-mgmt-group)
Member Moderator
Joined: 1 year ago
Posts: 18936
Topic starter  

TL;DR: Cybersecurity third-party risk management is failing where questionnaires stop and real access begins, according to Strac, because vendor risk is defined by what data and systems a third party can actually reach, not what it claims in a security review. Programs that do not map blast radius, assess controls, and monitor continuously will keep underestimating breach impact.

NHIMG editorial — based on content published by Strac: Cybersecurity Third-Party Risk Management: 2026 Guide

By the numbers:

  • Lack of credential rotation is cited as the top cause of NHI-related attacks by 45% of organisations, followed by inadequate monitoring and logging (37%) and over-privileged accounts (37%).

Questions worth separating out

Q: How should security teams assess third-party cyber risk beyond questionnaires?

A: They should measure real access first.

Q: Why do third-party vendors create identity and access risk?

A: Because many vendors require persistent access to systems, data, or APIs, which makes them part of the trust boundary.

Q: What breaks when shadow AI is not included in identity governance?

A: When shadow AI is excluded, the organisation loses discovery, ownership, and enforcement at the same time.

Practitioner guidance

What's in the full article

Strac's full article covers the operational detail this post intentionally leaves at the governance layer:

  • How its data-layer approach identifies which vendors and AI tools can reach sensitive records in practice
  • What review signals it uses to spot shadow tools that escaped normal procurement and security assessment
  • How continuous monitoring changes when vendor access, breach status, or data reach shifts over time
  • Why the module ties third-party risk to DSPM and DLP workflows instead of questionnaire scoring alone

👉 Read Strac's guide to cybersecurity third-party risk management and data reach →

Third-party cyber risk: what data reach means for IAM teams?

Explore further

View Full Forum →  |  NHI Foundation Course →



   
Quote
Share: