Join our Newsletter — 33% off our NHI Course

Third-party risk management: what IAM teams need to change

 

(@nhi-mgmt-group)
Member Moderator
Joined: 1 year ago
Posts: 20739
Topic starter  

TL;DR: Third-party risk management now shapes security, compliance, and operational resilience because vendors routinely sit on trusted paths into enterprise systems, according to SecurEnds. That makes vendor access governance, continuous monitoring, and lifecycle oversight a core identity problem, not a periodic procurement exercise.

Editorial analysis by NHI Mgmt Group, based on content published by SecurEnds: “Why Third-Party Risk Management Is Important”.

Key questions

Q: What breaks when third-party access is not included in identity governance?

A: Auditability breaks first, followed by containment.

Q: Why do vendor accounts create higher breach risk than internal user accounts?

A: Vendor accounts often combine external connectivity, broad permissions, and weaker lifecycle oversight, which makes them attractive to attackers and hard to govern.

Q: How should organisations monitor third-party access after onboarding?

A: They should monitor vendor access as an ongoing identity lifecycle, not as a static approval.

Practitioner guidance

  • Inventory every third-party identity path Catalogue vendor accounts, tokens, API keys, certificates and federated access paths, then tie each to a business owner and a system owner.
  • Classify vendors by access criticality Rank each third-party relationship by data reach, administrative scope, integration depth and downstream dependency, then apply review frequency accordingly.
  • Enforce revocation at relationship change Make offboarding, contract renewal and scope reduction trigger automatic access review so vendor credentials are removed when business need ends.

Bottom line: Third-party risk management is now an identity governance problem because vendors, SaaS platforms and service partners hold real access into enterprise systems.

Explore further

View Full Forum →  |  NHI Foundation Course →  |  Our Services →  |  Read the full analysis →


This topic was modified 1 day ago by NHI Mgmt Group

   
Quote
(@mr-nhi)
Member Moderator
Joined: 5 months ago
Posts: 20760
 

Third-party risk management has become a lifecycle governance problem, not a questionnaire problem. The article correctly points to continuous monitoring and access governance, but the deeper issue is that vendor relationships create identities that outlive the original approval moment. Once a third party can authenticate repeatedly, the organisation needs joiner-mover-leaver discipline for external access, not just onboarding due diligence. Practitioners should treat vendor access as governed identity, not static vendor status.

A few things that frame the scale:

  • 92% of organisations expose NHIs to third parties, raising concerns about supply chain security, according to the Ultimate Guide to NHIs.

A question worth separating out:

Q: Who should own third-party access revocation when a vendor relationship changes?

A: Ownership should sit with both the business system owner and the identity governance function, with procurement triggering the process and security verifying closure. If revocation is left to informal coordination, access often persists after the contract, project or integration ends. The goal is to make offboarding a control, not a courtesy.

👉 Read our full editorial: Third-party risk management is now an identity governance issue


This post was modified 1 day ago by NHI Mgmt Group

   
ReplyQuote
Share:

Free weekly newsletter

Subscribe to the NHI & AI Identity Journal

The latest on NHI and Agentic AI security – articles, research, breaches, news and events every week.

Bonus 33% off our NHI Course when you subscribe.