Segmenting high-value data paths should usually come first because it limits how far an abused identity can move. Access review still matters, but without segmentation a single valid account can reach too much data too quickly. The right order is to shrink the blast radius, then tighten the account lifecycle.
Why Segmentation Usually Comes Before Access Review
When third-party risk is driven by valid access paths, segmentation changes the shape of the problem before review can. A strong access review can remove excess entitlements, but it does not stop a compromised account from reaching too much if the environment is flat. IAM and IGA Basics is a useful baseline for understanding how entitlement governance and access control fit together.
Segmentation is the faster way to reduce blast radius because it constrains where a third party can move, even when its account is still active. That matters most for high-value data paths, vendor portals, admin consoles, and integration points that connect to sensitive systems. In practice, segmentation buys time and reduces consequence while the slower governance work catches up.
Access review becomes the stronger follow-on control once exposure has been reduced. If reviewers are looking at a sprawling, overconnected estate, they can remove obvious excess but still miss how much residual reach remains. Access Reviews and Certification Guide shows why review quality improves when the access surface is already narrowed and better contextualised.
Where Access Review Still Matters
Access review is still essential for third-party accounts, especially where contracts, integrations, or support workflows create long-lived entitlements. It is the control that finds stale access, orphaned vendor accounts, and permissions that no longer match the business relationship. Without it, segmentation alone can leave a wide population of dormant but still valid accounts in circulation.
Review also helps distinguish necessary connectivity from inherited access that survived past the original use case. That is particularly important for vendors that change personnel often, rely on shared admin channels, or aggregate multiple customer environments. A good review process should be able to answer who owns the access, why it exists, and what would break if it were removed.
IAM and IGA Basics and Access Reviews and Certification Guide are both useful here because they reinforce that review is not a substitute for architecture. It is the governance step that validates and cleans up access after the environment has already been made safer.
How to Decide the Order in Practice
The order should follow exposure, not bureaucracy. If a third party can traverse from one account to a critical dataset, service tier, or privileged function, the first move is to segment that path or isolate that trust boundary. If the third party has limited reach already, and the main issue is unclear ownership or stale entitlements, review can move earlier.
EU Digital Operational Resilience Act (DORA) is a good reminder that third-party resilience is judged on operational impact, not just policy completeness. In the same way, third-party risk programs should prioritise controls that reduce the size and speed of a likely incident before they optimise the paperwork around it.
Ultimate Guide to NHIs — Lifecycle Processes for Managing NHIs is relevant because the same sequencing applies to access lifecycle: reduce standing exposure first, then tighten recertification, rotation, and offboarding. For vendor access, that usually means fewer reachable systems before more review cadence.
Risk and Threat Considerations
Third-party accounts are attractive because they often combine legitimate trust with broad operational reach. If those accounts are compromised, the first damage is rarely the login itself, it is the ability to move farther, touch more systems, and reach more data than the business intended.
Failure mechanism: A valid vendor identity, token, or support path is abused inside a flat or weakly segmented environment, allowing rapid lateral movement and overbroad data access before review can remove the entitlement.
Impact: The organisation experiences larger blast radius, slower containment, and higher likelihood of data exposure or privileged misuse, even when the original account was technically authorised.
Practitioner Guidance
What to prioritise: Start with the third-party paths that can touch crown-jewel data, administrative planes, or broad internal transit. If the environment allows lateral reach from one vendor account to many assets, segmentation is the higher-value first move.
Decision rule: If a single valid third-party credential can still reach more than one sensitive trust zone, segment first. If access is already tightly bounded and the main issue is entitlement sprawl, move straight to review and recertification.
What to verify: Confirm that segmentation actually changes reachability, not just diagrams. The control should block real data paths, management paths, and inherited trust routes that a vendor account could otherwise use.
Practitioner takeaway: Use segmentation to shrink the blast radius, then use access review to clean up what remains. If you reverse that order, you often spend time certifying access that is still too dangerous to keep.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
OWASP Non-Human Identity Top 10 addresses the attack and risk surface, while NIST SP 800-53 Rev 5 and NIST Zero Trust (SP 800-207) set the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| NIST SP 800-53 Rev 5 | AC-4 — Information Flow Enforcement | Segments third-party paths to limit data movement. |
| AC-6 — Least Privilege | Access review reduces excess third-party permissions. | |
| AC-2 — Account Management | Third-party access depends on provisioning, review, and revocation. | |
| Recommendation — Enforce information flow restrictions between vendor and sensitive zones. Remove unnecessary third-party entitlements and privileges. Maintain third-party accounts with periodic review and timely removal. | ||
| NIST Zero Trust (SP 800-207) | N/A — Zero Trust Architecture | Supports segmenting trust boundaries before relying on account review. |
| Recommendation — Apply ZTA to shrink trust zones and verify access continuously. | ||
| OWASP Non-Human Identity Top 10 | NHI-05 — Overprivileged NHI | Third-party identities often retain more access than they need. |
| Recommendation — Reduce overprivileged non-human access before it can be abused. | ||
Practitioner Guidance
What to prioritise: Start with the third-party paths that can touch crown-jewel data, administrative planes, or broad internal transit. If the environment allows lateral reach from one vendor account to many assets, segmentation is the higher-value first move.
Decision rule: If a single valid third-party credential can still reach more than one sensitive trust zone, segment first. If access is already tightly bounded and the main issue is entitlement sprawl, move straight to review and recertification.
What to verify: Confirm that segmentation actually changes reachability, not just diagrams. The control should block real data paths, management paths, and inherited trust routes that a vendor account could otherwise use.
Practitioner takeaway: Use segmentation to shrink the blast radius, then use access review to clean up what remains. If you reverse that order, you often spend time certifying access that is still too dangerous to keep.
Related resources from NHI Mgmt Group
- Should organisations prioritise edge-device monitoring or third-party access reviews first?
- How should organisations structure a vendor risk management programme to prioritise the highest third-party threats first?
- How should organisations prioritise third-party vendor risk management when suppliers have access to sensitive data and core operations?
- Should organisations prioritise cyber risk, AI risk, or third-party risk first?
Deepen Your Knowledge
Free weekly newsletter
Subscribe to the NHI & AI Identity Journal
The latest on NHI and Agentic AI security – articles, research, breaches, news and events every week.
Bonus 33% off our NHI Course when you subscribe.
Reviewed and updated by the NHIMG editorial team on October 11, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org