Join our Newsletter — 33% off our NHI Course
Home› Glossary› Governance, Ownership & Risk› Third-Party ICT Service Provider
Governance, Ownership & Risk

Third-Party ICT Service Provider

← Back to Glossary
By NHI Mgmt Group Updated September 25, 2026 Domain: Governance, Ownership & Risk

A third-party ICT service provider is an external company that supplies technology services such as cloud hosting, data centre operations, software, or managed infrastructure. Under DORA, these providers matter because their failures, outages, or control gaps can directly affect the resilience of regulated financial organisations.

What a third-party ICT service provider is

A third-party ICT service provider is an external organisation that delivers technology capabilities a regulated business depends on, such as cloud hosting, data centre operations, software delivery, or managed infrastructure. The defining feature is dependence, because the provider sits outside the customer’s direct control while still supporting critical services.

This arrangement is common in modern financial and digital operations, but the security meaning is broader than vendor management. Once a provider can affect availability, integrity, confidentiality, or recoverability, its controls and failures become part of the customer’s risk surface. That is why DORA treats these providers as operationally important rather than merely contractual suppliers.

Why third-party ICT providers matter in resilience and governance

Third-party ICT providers matter because they can become single points of failure, concentration risks, or sources of cascading disruption. A small defect in one provider, such as an outage, misconfiguration, or loss of administrative control, can propagate into many downstream customers at once. For financial entities, that makes provider selection and ongoing oversight a resilience issue, not just a procurement issue.

They also matter because the customer often inherits responsibility for the business impact even when the provider owns the infrastructure. That creates a governance challenge around accountability, service criticality, exit planning, and visibility into sub-contractors and shared dependencies. DORA and related control frameworks push organisations to understand not only who the provider is, but what services are truly essential and how recoverable they are.

Common security and operational failure modes

The main failure modes are availability loss, weak access control, opaque change management, and poor segregation between customers. Third-party ICT providers can also introduce hidden dependency risk when one downstream platform, integration, or identity boundary supports many business services. If monitoring is shallow, a customer may not detect the control gap until service disruption or data exposure has already occurred.

Security exposure often appears through shared administrative pathways, long-lived credentials, weak API controls, or excess privilege in managed environments. The customer may not operate those controls directly, but the customer is still exposed to the consequences when the provider’s authentication, patching, logging, or recovery practices are weak. In practice, this is where outsourcing and cyber risk meet.

How the term is used in DORA and supplier oversight

Under DORA, the concept is tied to ICT risk management, incident resilience, and contractual oversight of critical or important functions. The term covers more than cloud brands or hosting companies, it also includes managed service providers, software providers, and infrastructure operators when their services support regulated operations. That broader scope is why third-party ICT service provider reviews should focus on service criticality, not just vendor reputation.

Organisations typically assess these providers through security assurances, resilience testing, contractual rights, exit arrangements, and ongoing monitoring of performance and control changes. The point is to verify that the provider’s service model matches the business’s tolerance for disruption and control loss. Where a provider is central to core operations, the governance bar should be correspondingly higher.

Risk and Threat Considerations

Third-party ICT service providers can create systemic exposure because one compromise or outage may affect many customers at the same time. The biggest risks are concentration, dependency opacity, and access-path abuse, especially where the provider holds privileged operational access or manages sensitive integrations on the customer’s behalf.

Failure mechanism: A provider outage, insecure remote access path, weak segregation, or compromised administrative credential can interrupt service delivery or expose customer environments and data.

Impact: The result can be downtime, regulatory breach, data exposure, recovery delay, or a cascading failure across multiple dependent services.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

NIST CSF 2.0 and CIS Controls v8 set the technical controls, while DORA and ISO/IEC 27001:2022 define the regulatory obligations.

FrameworkControl / ReferenceRelevance
DORAICT Third-Party Risk ManagementDORA directly governs ICT third-party providers and their operational resilience impact.
Recommendation — Classify critical providers, test resilience assumptions, and enforce exit and oversight obligations.
NIST CSF 2.0GV.SC-01 — Cyber Supply Chain Risk ManagementThird-party ICT providers are a supply-chain and dependency risk to operations.
RC.RP-01 — Recovery Plan ExecutionProvider failure directly affects restoration and continuity planning.
Recommendation — Map external ICT dependencies and govern supplier risk through the supply-chain risk function. Validate that recovery plans still work when a third-party ICT provider is unavailable.
CIS Controls v8CIS-15 — Service Provider ManagementThe term is fundamentally about managing external technology providers and their risk.
Recommendation — Maintain an inventory of service providers and review their security and resilience obligations.
ISO/IEC 27001:2022A.5.19 — Information security in supplier relationshipsSupplier relationships govern security expectations for third-party ICT providers.
A.5.22 — Monitoring, review and change management of supplier servicesOngoing review is essential when provider changes can alter customer risk.
Recommendation — Set security requirements for suppliers and verify that contracts reflect those obligations. Monitor supplier service changes and revalidate controls when the provider’s service model changes.

Practitioner Guidance

Governance implication: Treat the provider as part of the operating model for any service it materially supports, not as an externality. Ownership should be explicit for service criticality, monitoring, exit planning, and escalation paths, because those responsibilities do not disappear when technology is outsourced.

What to watch for: Pay close attention to shared dependencies, long-lived privileged access, sub-processors, and vague outage commitments. These are the signals that a vendor relationship is drifting from routine procurement into a resilience dependency that needs stronger oversight.

Deepen Your Knowledge

Sign up to our weekly newsletter — get 33% off our NHI Foundation Level Course

    NHIMG Editorial Note
    Reviewed and updated by the NHIMG editorial team on September 25, 2026.
    NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org