Cybersecurity Glossary

Third Party Risk

The risk you inherit from suppliers, contractors and platforms with access to your systems or data.

What Third Party Risk means

Third party risk covers anyone who holds your data or can reach your systems: software vendors, managed providers, bookkeepers, marketing agencies. Their weaknesses become yours, and their breach becomes your notification obligation if your data is involved.

Why Third Party Risk matters for small businesses and nonprofits

Small organisations cannot audit their suppliers, but they can limit what each supplier reaches and require prompt notification. That contractual and technical limiting is the realistic control.

What to do about Third Party Risk

Three steps to deal with Third Party Risk

  • Keep a list of suppliers with access and what each can reach
  • Require breach notification within a defined period in your contracts
  • Remove supplier access as soon as an engagement ends

Not sure where you stand on this?

We review your current setup against the basics, tell you plainly what is covered and what is not, and give you a ranked list with effort and cost. No jargon and no scare tactics.