Mohammed AlMoneer, Sr. Regional Director, Türkiye, France, Africa & Middle East at Infoblox
Rich Marcus, CISO at Optro and operational workflows. Even relatively small SaaS providers may hold privileged access to sensitive information, while maintaining their own network of subcontractors that remains largely invisible to customers. Combined with the growing dependence on hyperscale cloud providers, a single outage or security incident can now cascade across multiple industries. Third-party risk, he argues, has evolved from a procurement concern into a core business resilience issue.
Mohammed AlMoneer, Sr. Regional Director, Türkiye, France, Africa & Middle East at Infoblox, adds that attackers do not distinguish between internal infrastructure and external partners.
“ They simply ask: what can I reach, and where is the weakest path in?”
As digital ecosystems continue to expand, organisations must contend with forgotten internet-facing assets, DNS misconfigurations, exposed credentials and vulnerable supplier infrastructure hidden deep within increasingly complex supply chains.
Moving beyond annual assessments
Many organisations continue to rely on annual vendor questionnaires and compliance reviews. While these exercises may satisfy governance requirements, they provide little protection against threats that evolve daily.
ElOuazzani argues that many organisations have reduced vendor assessments to a compliance exercise rather than a meaningful security activity. Questionnaires are completed, reassuring responses are filed away and the process repeats the following year, even though the threat landscape may have changed dramatically within weeks. Shortening review cycles offers only marginal improvement if organisations continue relying on the same static processes.
Rich Marcus, CISO at Optro, believes the industry has already recognised the limitations of point-in-time assessments. Historically, annual reviews represented the best organisations could achieve with the tools available. Today, however, AI-assisted attackers can weaponise newly disclosed vulnerabilities within hours, making continuous visibility essential.
Security leaders now require constant awareness of supplier breaches, critical vulnerabilities, regulatory developments, domain reputation, indicators of compromise and changes in a supplier’ s external attack surface. The good news, Marcus notes, is that continuous monitoring has finally become a practical reality rather than an aspirational goal.
Davies agrees that annual questionnaires often confirm only whether policies exist, not whether they are actually effective. More importantly, they frequently apply identical scrutiny to every supplier, regardless of risk.
Instead, organisations should adopt a risk-based approach that prioritises suppliers supporting critical business services or holding privileged access. Higher-risk vendors should receive deeper and more frequent assessments, while contracts should include clear incident reporting obligations, audit rights and regularly tested contingency plans.
Seeing beyond direct suppliers
Understanding fourth and fifth-party risk remains one of the biggest challenges facing security teams.
According to AlMoneer, CISOs should begin by viewing their organisations from an attacker’ s perspective rather than relying solely on procurement records. That means identifying what is actually exposed to the internet across both internal infrastructure and vendor environments.
Continuous monitoring should include internetfacing IP addresses, domains, exposed services, open ports, known vulnerabilities, certificate health, DNS hygiene, leaked credentials and references appearing across the deep and dark web.
While organisations may have no direct contractual relationship with fourth or fifth parties, those organisations can still introduce significant operational risk. Rather than attempting to monitor every supplier equally, AlMoneer recommends focusing on vendors that support critical business functions and integrating external threat intelligence directly into SOC and incident response workflows. This transforms supply chain visibility from a static spreadsheet into an operational security capability.
Lessons from recent supply chain attacks
The growing number of high-profile supply chain attacks has reinforced a fundamental reality for security leaders: trusted partners can quickly become trusted pathways for attackers.
26 WWW. INTELLIGENTCISO. COM / MIDDLE-EAST