TL;DR: Third-party compromise increasingly reaches identity systems, credentials, and downstream data access, according to Saviynt's analysis of recent supply chain attacks, making supplier trust paths part of the attack surface rather than a separate risk tier. IAM, NHI, and PAM controls inherit supplier failure modes when access outlives oversight.
Editorial analysis by NHI Mgmt Group, based on content published by Saviynt: “Sisense Breach Highlights Rise in Major Supply Chain Attacks”.
Key questions
Q: What breaks when third-party access is not fully inventoried?
A: Identity governance loses visibility into the accounts, tokens, and certificates that actually extend trust into supplier environments.
Q: Why do supplier identities increase breach impact so quickly?
A: Supplier identities often connect to multiple systems, so one compromised account can unlock a much larger trust chain than a normal internal user account.
Q: How should teams detect risky third-party access before it is abused?
A: Look for external identities with broad scopes, long-lived secrets, and permissions that no longer match current contracts or operational need.
Practitioner guidance
- Inventory every third-party identity Build a live register of supplier accounts, tokens, certificates, API keys, and delegated roles that can reach internal systems.
- Tie access to relationship state Revoke or narrow third-party access when contracts change, vendors are offboarded, or integrations are no longer actively needed.
- Scope supplier permissions tightly Replace broad standing access with task-specific permissions and separate production access from non-production use cases.
Bottom line: Supply chain attacks become identity incidents when third-party accounts, tokens, and certificates are trusted inside core systems.
Explore further
View Full Forum → | NHI Foundation Course → | Our Services → | Read the full analysis →
Third-party access is now an identity governance domain, not a procurement afterthought. When suppliers sit in the execution path, their accounts, tokens, and certificates become part of the enterprise identity estate. The practical consequence is that IAM, PAM, and NHI controls must extend to external operators, not stop at the firewall boundary.
A few things that frame the scale:
- 92% of organisations expose NHIs to third parties, raising concerns about supply chain security, according to the Ultimate Guide to NHIs.
A question worth separating out:
Q: Who should own identity risk when governance spans IAM, PAM, and security operations?
A: Ownership should sit with the identity programme, but it must be operationally linked to security and compliance teams. When governance is split into disconnected functions, no one can close the loop between discovery, decision, remediation, and evidence.
👉 Read our full editorial: Supply chain attacks expose the identity risk hidden in third parties