TL;DR: Third-party breaches are increasingly exposing identity data and connected access paths, with incidents such as Sisense showing how vendor relationships can become an entry point for broader compromise, according to Saviynt. Identity governance has to extend beyond employees to service, vendor, and machine identities before trust becomes an attack surface.
Editorial analysis by NHI Mgmt Group, based on content published by Saviynt: “Sisense Breach Highlights Rise in Major Supply Chain Attacks”.
Key questions
Q: What breaks when third-party access is not lifecycle managed?
A: Access outlives accountability.
Q: Why do third-party identities increase supply chain risk?
A: Third-party identities increase risk because they depend on another organisation’s hygiene while still operating inside your trust boundary.
Q: How can IAM teams tell whether third-party access is overexposed?
A: Look for external accounts that can reach production data, administrative workflows, or automation layers without a narrow business purpose and expiry condition.
Practitioner guidance
- Map third-party trust chains Document every supplier, support provider, and integration that can reach production systems, then trace what each one can touch across data, admin, and automation layers.
- Review supplier-linked machine identities Inventory service accounts, tokens, and delegated credentials tied to external parties, then assign an owner and expiry condition for each one.
- Tighten offboarding for external access Remove third-party access as part of contract change, platform migration, or relationship end, rather than waiting for periodic access certification.
Bottom line: Third-party breaches become identity incidents when external access and delegated trust can be reused against customer systems.
Explore further
View Full Forum → | NHI Foundation Course → | Our Services → | Read the full analysis →
Third-party supply chain breaches expose a governance boundary problem, not just a vendor risk problem. Once external identities can reach production systems, the enterprise has already extended its trust boundary beyond direct employment relationships. That means identity governance has to cover suppliers, service providers, and machine identities with the same seriousness as internal users. The practitioner takeaway is that external access is part of the identity programme, not an exception to it.
A few things that frame the scale:
- 92% of organisations expose NHIs to third parties, raising concerns about supply chain security, according to the Ultimate Guide to NHIs.
- 59% of compromised machines in a major 2025 supply chain attack were CI/CD runners rather than personal workstations, according to the State of Secrets Sprawl 2026.
A question worth separating out:
Q: How should organisations govern supplier-linked service accounts?
A: Treat supplier-linked service accounts as governed identities with named owners, least-privilege scopes, and explicit offboarding triggers. Review them whenever a vendor relationship changes, not only on a calendar cycle. If the business cannot justify the credential’s current use, the account should be removed or reduced before it becomes an active breach path.
👉 Read our full editorial: Third-party supply chain breaches are reshaping identity governance