ElOuazzani believes the biggest shift organisations need to recognise is that the attack surface has expanded well beyond their own infrastructure.
“ What I’ ve seen change most dramatically is the attack surface itself. It’ s no longer your infrastructure. It’ s everything your infrastructure trusts: vendors, SaaS integrations, OAuth connections, open-source dependencies that nobody owns but everyone runs. Third-party involvement now appears in nearly a third of all breaches. That’ s not a trend. That’ s a structural shift,” she said.
She argues that organisations can no longer limit their visibility to assets they own directly. The first priority should be extending visibility beyond the corporate perimeter to understand what critical suppliers expose to the internet. Without that visibility, organisations are attempting to manage risks they cannot accurately measure.
Equally important is recognising that risk often extends well beyond direct contractual relationships. Fourth-party suppliers, while largely invisible to the customer, can introduce significant operational and security exposure if they are compromised.
“ The second is that fourth-party risk is real. Your vendor’ s vendor, with whom you have no contract and no conversation, can still bring you down.”
According to ElOuazzani, many organisations are still relying on third-party risk programmes that were designed for an entirely different era. Annual questionnaires and periodic reviews simply cannot keep pace with today’ s threat landscape, where attackers exploit new opportunities within hours rather than months. Building resilience now requires continuous visibility, continuous assessment and a security strategy that treats the extended supply chain as part of the organisation’ s own attack surface.
Removing friction from governance
One of the biggest pressures facing security teams is balancing rapid vendor onboarding with appropriate governance. Business leaders increasingly expect new suppliers to be approved quickly without compromising security.
Marcus argues that speed and governance only appear to conflict when governance remains manual. Traditional processes built around spreadsheets, periodic reviews and one-off
One of the biggest pressures facing security teams is balancing rapid vendor onboarding with appropriate governance. Business leaders increasingly expect new suppliers to be approved quickly without compromising security.
questionnaires simply cannot keep pace with modern business.
Instead, organisations are adopting AI-powered governance platforms that automate evidence collection, recommend appropriate controls and provide standardised templates that allow monitoring to begin immediately. Rather than acting as a gatekeeper that slows innovation, governance becomes an ongoing process operating alongside the business.
From compliance to resilience
The evolution of third-party risk reflects a broader shift taking place across cybersecurity. Organisations are no longer protecting clearly defined networks surrounded by traditional perimeters. They are defending highly interconnected digital ecosystems where suppliers, cloud providers, software vendors and AI services all contribute to business operations and, increasingly, business risk.
Managing that complexity requires more than periodic assessments or compliance checklists. It demands continuous visibility, intelligent prioritisation and the ability to understand how external exposures translate into operational risk. For today’ s CISOs, third-party risk has become far more than a vendor management exercise. It has become a defining element of enterprise resilience.
WWW. INTELLIGENTCISO. COM / MIDDLE-EAST 27