Join our Newsletter — 33% off our NHI Course
Home› FAQ› Governance, Ownership & Risk› Should organisations prioritise segmentation or access review first…
Governance, Ownership & Risk

Should organisations prioritise segmentation or access review first for third-party risk?

← Back to all FAQ
By NHI Mgmt Group Editorial Team Updated October 11, 2026 Domain: Governance, Ownership & Risk

Segmenting high-value data paths should usually come first because it limits how far an abused identity can move. Access review still matters, but without segmentation a single valid account can reach too much data too quickly. The right order is to shrink the blast radius, then tighten the account lifecycle.

Why Segmentation Usually Comes Before Access Review

When third-party risk is driven by valid access paths, segmentation changes the shape of the problem before review can. A strong access review can remove excess entitlements, but it does not stop a compromised account from reaching too much if the environment is flat. IAM and IGA Basics is a useful baseline for understanding how entitlement governance and access control fit together.

Segmentation is the faster way to reduce blast radius because it constrains where a third party can move, even when its account is still active. That matters most for high-value data paths, vendor portals, admin consoles, and integration points that connect to sensitive systems. In practice, segmentation buys time and reduces consequence while the slower governance work catches up.

Access review becomes the stronger follow-on control once exposure has been reduced. If reviewers are looking at a sprawling, overconnected estate, they can remove obvious excess but still miss how much residual reach remains. Access Reviews and Certification Guide shows why review quality improves when the access surface is already narrowed and better contextualised.

Where Access Review Still Matters

Access review is still essential for third-party accounts, especially where contracts, integrations, or support workflows create long-lived entitlements. It is the control that finds stale access, orphaned vendor accounts, and permissions that no longer match the business relationship. Without it, segmentation alone can leave a wide population of dormant but still valid accounts in circulation.

Review also helps distinguish necessary connectivity from inherited access that survived past the original use case. That is particularly important for vendors that change personnel often, rely on shared admin channels, or aggregate multiple customer environments. A good review process should be able to answer who owns the access, why it exists, and what would break if it were removed.

IAM and IGA Basics and Access Reviews and Certification Guide are both useful here because they reinforce that review is not a substitute for architecture. It is the governance step that validates and cleans up access after the environment has already been made safer.

How to Decide the Order in Practice

The order should follow exposure, not bureaucracy. If a third party can traverse from one account to a critical dataset, service tier, or privileged function, the first move is to segment that path or isolate that trust boundary. If the third party has limited reach already, and the main issue is unclear ownership or stale entitlements, review can move earlier.

EU Digital Operational Resilience Act (DORA) is a good reminder that third-party resilience is judged on operational impact, not just policy completeness. In the same way, third-party risk programs should prioritise controls that reduce the size and speed of a likely incident before they optimise the paperwork around it.

Ultimate Guide to NHIs — Lifecycle Processes for Managing NHIs is relevant because the same sequencing applies to access lifecycle: reduce standing exposure first, then tighten recertification, rotation, and offboarding. For vendor access, that usually means fewer reachable systems before more review cadence.

Risk and Threat Considerations

Third-party accounts are attractive because they often combine legitimate trust with broad operational reach. If those accounts are compromised, the first damage is rarely the login itself, it is the ability to move farther, touch more systems, and reach more data than the business intended.

Failure mechanism: A valid vendor identity, token, or support path is abused inside a flat or weakly segmented environment, allowing rapid lateral movement and overbroad data access before review can remove the entitlement.

Impact: The organisation experiences larger blast radius, slower containment, and higher likelihood of data exposure or privileged misuse, even when the original account was technically authorised.

Practitioner Guidance

What to prioritise: Start with the third-party paths that can touch crown-jewel data, administrative planes, or broad internal transit. If the environment allows lateral reach from one vendor account to many assets, segmentation is the higher-value first move.

Decision rule: If a single valid third-party credential can still reach more than one sensitive trust zone, segment first. If access is already tightly bounded and the main issue is entitlement sprawl, move straight to review and recertification.

What to verify: Confirm that segmentation actually changes reachability, not just diagrams. The control should block real data paths, management paths, and inherited trust routes that a vendor account could otherwise use.

Practitioner takeaway: Use segmentation to shrink the blast radius, then use access review to clean up what remains. If you reverse that order, you often spend time certifying access that is still too dangerous to keep.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

OWASP Non-Human Identity Top 10 addresses the attack and risk surface, while NIST SP 800-53 Rev 5 and NIST Zero Trust (SP 800-207) set the governance and control requirements practitioners need to meet.

FrameworkControl / ReferenceRelevance
NIST SP 800-53 Rev 5AC-4 — Information Flow EnforcementSegments third-party paths to limit data movement.
AC-6 — Least PrivilegeAccess review reduces excess third-party permissions.
AC-2 — Account ManagementThird-party access depends on provisioning, review, and revocation.
Recommendation — Enforce information flow restrictions between vendor and sensitive zones. Remove unnecessary third-party entitlements and privileges. Maintain third-party accounts with periodic review and timely removal.
NIST Zero Trust (SP 800-207)N/A — Zero Trust ArchitectureSupports segmenting trust boundaries before relying on account review.
Recommendation — Apply ZTA to shrink trust zones and verify access continuously.
OWASP Non-Human Identity Top 10NHI-05 — Overprivileged NHIThird-party identities often retain more access than they need.
Recommendation — Reduce overprivileged non-human access before it can be abused.

Practitioner Guidance

What to prioritise: Start with the third-party paths that can touch crown-jewel data, administrative planes, or broad internal transit. If the environment allows lateral reach from one vendor account to many assets, segmentation is the higher-value first move.

Decision rule: If a single valid third-party credential can still reach more than one sensitive trust zone, segment first. If access is already tightly bounded and the main issue is entitlement sprawl, move straight to review and recertification.

What to verify: Confirm that segmentation actually changes reachability, not just diagrams. The control should block real data paths, management paths, and inherited trust routes that a vendor account could otherwise use.

Practitioner takeaway: Use segmentation to shrink the blast radius, then use access review to clean up what remains. If you reverse that order, you often spend time certifying access that is still too dangerous to keep.

Free weekly newsletter

Subscribe to the NHI & AI Identity Journal

The latest on NHI and Agentic AI security – articles, research, breaches, news and events every week.

Bonus 33% off our NHI Course when you subscribe.

NHIMG Editorial Note
Reviewed and updated by the NHIMG editorial team on October 11, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org