When your vendor gets hit: managing third-party ransomware exposure
Key takeaways
- Some of the most disruptive incidents never touch your network — a critical vendor or MSP is encrypted and your operations stop anyway.
- Third-party exposure has two shapes: dependency risk (a supplier's outage halts you) and access risk (a supplier's compromise reaches you).
- For each critical supplier, know what you do if they're down for a week and what an attacker could reach through their access.
The incident that never touches you
Some of the most disruptive ransomware incidents never touch your own network. A critical vendor, managed service provider, or software supplier is encrypted, and your operations grind to a halt anyway. Attackers increasingly target providers precisely because a single compromise cascades across many downstream customers — the return on one intrusion multiplies, and you can be a casualty of an attack aimed at someone else.
Two shapes of exposure
The exposure comes in two distinct shapes, and they call for different controls. There is dependency risk — a supplier whose outage stops your business even though your systems are untouched — and there is access risk — a supplier whose compromised connection into your environment becomes the attacker's route in. Managed service providers and remote-management tooling carry both at once, which is what makes them such high-value targets.
The controls that map to each
- Maintain a register of critical third parties mapped to the business function each one supports.
- Contractually require prompt incident notification and a minimum security baseline.
- Scope, monitor, and constrain vendor access with least privilege, dedicated accounts, and phishing-resistant MFA.
- Include 'key vendor unavailable' as an explicit scenario in your business continuity planning.
Two questions per critical supplier
For each critical supplier, answer two questions plainly: what do we do if they are down for a week, and what could an attacker reach through the access we have granted them? A vendor with standing administrative access and no oversight is an extension of your attack surface you do not control. If either answer is blank, you have found the gap worth closing first.