At 2:13 a.m., a vendor's administrator account is used to enter your environment.

The vendor is not on your incident bridge. Their contract is in procurement. Their last security questionnaire is in a folder nobody has opened since March.

Your team still owns the breach.

I have watched third-party risk programs grow into impressive machines. Thousands of suppliers. Annual questionnaires. Risk scores with two decimal places. Dashboards that turn red when an assessment expires.

Then an incident begins, and the organization discovers it cannot answer three basic questions.

What access does this supplier have? Who can revoke it? How quickly can the supplier show us what happened?

A vendor assessment is a snapshot. Third-party risk is a live operating problem.

Stop treating every supplier the same

A payroll processor, a marketing platform, and a facilities contractor do not create the same risk. Yet many programs give them the same 150-question form and the same annual review cycle.

That is busywork disguised as control.

I want CISOs to classify suppliers by the harm their compromise could create. Can the vendor reach identity systems? Can it touch payment instructions? Does it hold patient records, employee data, or source code? Can it change production systems? Does it support a process that cannot stop on a Friday night?

Those answers should determine the depth of review, the technical controls, and the response obligations. A supplier with privileged access needs continuous attention. A low-impact provider may need a lighter path.

Risk is not a vendor count. It is a map of pathways into your business.

Put evidence ahead of promises

A clean questionnaire does not prove that a supplier can protect your data. It proves that someone completed a questionnaire.

Ask for evidence that matches the exposure. Current access lists. Logging coverage. Recovery test results. Named incident contacts. Proof that privileged accounts use strong authentication. A record of the last material incident and what changed afterward.

Then test the answers. Run a joint tabletop with the suppliers that can interrupt your operations. Ask who calls whom. Ask what data is preserved in the first hour. Ask how access is cut off when the normal contact is unavailable.

The exercise will reveal more than another policy PDF.

Contracts need an emergency lane

Many contracts are written for calm conditions. They describe reporting timelines, audit rights, and insurance. They say little about the first thirty minutes when a supplier may be the route into your network.

I want four items written in plain language.

  • A named incident channel that is monitored outside business hours.
  • A right to suspend or reduce access quickly when there is credible danger.
  • A minimum evidence-preservation requirement before systems are rebuilt or wiped.
  • A clear rule for notifying affected people when the supplier's failure creates real harm.

Legal teams should shape these terms. Security teams need to tell them what is operationally possible. A promise that cannot be executed at 2 a.m. is decoration.

The board question has changed

Boards do not need another count of completed assessments. They need to know where concentration is building.

One provider may support payroll, identity verification, customer communications, and recovery operations across several business units. That is a single point of failure hiding behind four contracts.

Show the board the top access pathways. Show which critical suppliers have been tested in the last year. Show where your team lacks the authority or technical means to revoke access. Show the decisions that still depend on a vendor's goodwill.

That is a risk conversation. A percentage on a dashboard is not.

What I want CISOs to do this quarter

Choose the ten suppliers that could cause the most harm if compromised. Map their access. Confirm the owner on your side. Test one incident with the supplier. Fix the fastest, most consequential gap you find.

Then repeat the process until the map reflects reality, not procurement records.

A third-party program earns trust when it helps a CISO make a hard decision before the breach. Cut access. Change a provider. Fund a control. Tell the board the exposure is larger than the score suggests.

The spreadsheet can wait. The pathway cannot.

That is the enterprise risk signal I am watching this quarter. Fellow CISOs, how are you turning third-party review into an operating capability?

Lekshmy Sankar, PhD