Skip to main content

Third-party data risks: Protect sensitive information across vendors, partners and supply chains

I remember the moment a CISO stepped out of a briefing to buy cigarettes. He had quit twenty years earlier. We had just spent the morning explaining what a kill chain looks like, and how a state-sponsored group works its way into a well-run organization.

When he came back, his first question was not technical: “We always patch when we need to. How is this even possible?”

That question has stayed with me for over a decade. Not because the client had done anything wrong, but because it captures something every organization eventually has to confront: doing the right things internally is necessary, but it is not sufficient.

A pattern, not an incident

I was in charge of a practice that led regional incident response and client engagement through one of the defining espionage campaigns of the last decade: the one now publicly documented as Operation Cloud Hopper, attributed to the China-linked group known as APT10. Nation-state actors used managed service providers as an entry point, riding legitimate, trusted access into the networks of the providers’ clients.

The public record on this campaign is well documented. Researchers have described a sustained, multi-year operation in which a small number of managed IT service providers were compromised, giving attackers a foothold that reached client organizations across dozens of countries and industries. What that public record cannot fully convey is what it feels like from inside the response.

I cannot name the organizations involved, but the shape of it will be familiar to anyone who lived through those years. A client was notified by law enforcement about unusual outbound traffic, months of forensic work, and the slow realization that the intrusion was neither recent nor isolated. Bringing that first environment back under full control took roughly two and a half years – not because the response was slow, but because a state-sponsored actor is built for persistence, not for a single payday.

A year later, I sat through a very different kind of meeting.

A client’s security leadership presented their governance and compliance posture, and on paper, it looked almost flawless. A colleague turned to me afterward and said there was nothing for us to do here, they had it figured out. I was not so sure. That instinct was confirmed later that same day, at a coffee machine, by a single question from that same client’s security leader: How good are your forensic and investigation skills?

We had a team on-site by Monday morning. Within days, we confirmed the same tools and patterns we had seen elsewhere. Over the five to six years that the overall response effort ran, we confirmed at least ten separate breaches across different organizations, all carrying the same signature: excellent governance on paper, coexisting with a compromised environment underneath it.

Neither client had been careless. Both had invested seriously in security. The lesson was never about negligence. It was about the limits of what even well-run internal controls can see, when the access path runs through someone else’s environment.

What changed, and what is changing again

These cases, and the public record around Cloud Hopper more broadly, are why I no longer treat third-party risk as a checkbox category. A supplier relationship is not secure just because a questionnaire says so. It is secure to the extent you can see what that supplier can reach, and how that access is used on an ongoing basis rather than once a year.


That lesson is about to be tested again, in a different form. Ungoverned and uncontrolled AI agents are becoming the next version of the same structural problem.

According to Gartner’s Predict 2026: Secure AI agents to avoid ungoverned sprawl and abuses, organizations that skip preproduction offensive testing on their AI agents should expect roughly twice as many cybersecurity incidents by 2028, compared with those that test before deployment. An agent acting on your behalf, or a supplier’s, with broad tool access and no clear owner, is functionally the same risk a managed service provider (MSP) represented a decade ago – a trusted actor operating inside your perimeter with more reach than anyone has actually mapped.

What this means for leadership

Three things follow from this, and none of them are new in principle, only in urgency. I think of them as prepare, respond and adapt, because that is genuinely the order in which they matter.

  1. Prepare. Access mapping has to be continuous, not contractual. A signed agreement or a passed audit tells you what a supplier or an agent is permitted to reach; it tells you nothing about what it is actually doing with that access, day to day. The organizations that fared best were the ones that had already built the visibility to answer that question before anyone needed to ask it under pressure.
  2. Respond. Incident response plans need to explicitly account for intrusions that arrive through a trusted third party rather than a direct attack. That means plans should define escalation paths, decision rights, evidence-preservation duties, notification thresholds, log-access requirements and secure communications with critical suppliers, rather than a change-approval cycle designed for calmer circumstances. The clients who moved fastest were not the ones with the most mature internal SOC; they were the ones willing to bring in experts with forensic capability the moment something looked slightly wrong, rather than waiting for certainty.
  3. Adapt. A clean governance presentation is not the same as a clean environment. The gap between the two is exactly where sophisticated actors tend to operate, and a strong compliance posture is worth treating as a reason to look closer, not a reason to stop looking. That applies as much to the AI agents being onboarded into your environment this year as it did to the suppliers being onboarded a decade ago.

A closing thought

There is a great deal from those years I still cannot talk about publicly, and honestly, I suspect some of it would be hard to believe even if I could. Parts of the investigative work our teams carried out during that period fed directly into broader law enforcement efforts – work I still can’t discuss in detail, but that I’m proud my teams did.

What has stayed with me most, though, is not any single technical detail. It is the instinct you build for recognizing when something is quietly wrong, long before anyone else in the room sees it. That instinct does not come from a framework. It comes from having sat across the table from a CISO who genuinely could not understand how a well-run organization had been breached and realizing that the honest answer had very little to do with him, and everything to do with how much of his environment was never really his alone to defend.

Share this article

X IconLinked-in Icon

Quint Ketting

Executive advisor Cybersecurity, BNN

View detailsof Quint Ketting >
  • Follow Quint Ketting on LinkedIn
 

Subscribe for regular insights

Thank you for your interest. You can download the report here.
A member of our team will be in touch with you shortly

Protecting what matters most in the AI economy