The breach you don’t see coming

Why third-party risk needs to shape enterprise security, according to Karl McGowan, Co-Founder, FrontierZero.

If you look across the major cyber incidents of the past two years, a quiet pattern emerges. The organisations that were breached didn’t fall because their own systems were weak. They fell because someone else’s were.

The recent Jaguar Land Rover incident is a clear example. Attackers didn’t target JLR directly; they came in through a leaked username and password from an external supplier. That single connection led to five weeks of operational disruption and an estimated £500 million in impact, followed by a £1.5 billion government loan guarantee to steady the business. And incidents like this are appearing in the headlines more often.

Different industries. Different budgets. Same story

Attackers aren’t using complex malware or zero-days to get in. They don’t need to. A single reused or leaked password from an employee, vendor or supplier is often enough to open the door. And because most organisations don’t track what ‘normal’ looks like for their external users – their usual login times, locations, devices or data usage – these accounts can behave abnormally for weeks without anyone noticing.

Why third-party risk has become the most reliable way in

No company can operate without partners. To improve profitability and efficiency, we share more data with more organisations than ever before. And while internal security has strengthened with identity platforms, MFA, segmentation and mature processes, these controls raise the bar only for attacks aimed at employees.

Vendors, suppliers, partners and even customers sit outside those controls. They inherit trust, access and data without inheriting the same scrutiny.

Qantas learned this the hard way when a third-party breach exposed sensitive staff information, and the financial fallout was significant enough that senior executives saw reductions in their own compensation.

It’s a reminder that the consequences of third-party incidents don’t stay confined to IT; they reach leadership and the business directly.

From all the recent breaches, three things stand out:

  1. Every vendor has different access, sometimes more than employees.
    A single leaked username and password can unlock high-value systems. Whether it’s to support HR, manage marketing platforms, run logistics integrations or troubleshoot critical applications, external partners often receive permissions that would never pass an internal review.
  2. They authenticate in ways most security teams don’t monitor well.
    OAuth grants, API tokens, platform-specific logins. These routes don’t always appear in the core identity system. Once approved, they can remain active for years with no visibility.
  3. The number of external connections grows faster than internal teams can track.
    Every new tool, consultant, system upgrade or integration creates another access path. It’s good for the business. It’s a burden for security.

This is why third-party attacks scale so effectively: they bypass the front door entirely. And once an attacker has that initial foothold, the situation can escalate quickly.

Most companies don’t track the pattern of life of their suppliers: when they normally log in, what they access, how much data they move, or whether their usage has changed. Without that baseline, abnormal behaviour looks perfectly ordinary. That’s the real exposure. The credential is just the trigger; the unseen connection and the unnoticed deviation from normal is what turns it into a breach. And once an attacker has access, the options available to them grows dramatically.

The rise of Ransomware-as-a-Service means smaller threat actors no longer need sophisticated tools. They simply rent them. With access in hand, often from a single leaked vendor password, they can outsource the ransomware itself to larger groups, typically giving up 10–20% of the payout, for high-quality, targeted ransomware, which they couldn’t create on their own.

This elevates the core problem. A leaked vendor password is dangerous, but only because it’s attached to an external connection the organisation doesn’t track, review or even realise is still active. The credential is the spark, the unseen access path is the fuel.

The Middle East is particularly exposed, and not because of weakness

Across the GCC, digital adoption is moving at an extraordinary speed. Banks, airlines, retailers, government entities, energy companies and manufacturers are integrating cloud platforms at a pace rarely seen elsewhere. With this comes enormous opportunity, but also a rapidly expanding dependence on external services.

Two things make this region uniquely vulnerable:

Your company’s ecosystem is expanding faster than the governance around it.
In the GCC, SaaS adoption is growing at over 15% annually, with new tools onboarded in hours and integrations added in a day. Yet security reviews and oversight often take weeks. Without continuous external visibility, organisations face mounting risks as their reliance on third-party services accelerates. From Canva for marketing to Expensify for finance plus all of those contractors.

Regulatory expectations are rising.
Whether in finance, aviation or government, regulators increasingly expect organisations to understand and manage vendor access. Not only during onboarding, but throughout the relationship. The message is clear: visibility is not optional.

None of this is a criticism. It’s the natural consequence of rapid growth and technological ambition. But it does mean organisations need a more honest view of the risks that accompany this progress.

Can organisations track their suppliers and vendor teams?

A common misconception is: “Our MFA is strong. Our IAM is centralised. Our network is segmented. We’re covered.”  Unfortunately, these controls only defend the single systems they are active on. Your Microsoft may be secure, but what about HubSpot or Jira?

Most organisations don’t track the pattern of life of their suppliers at all. A quarterly review tells you they were fine that day, but it won’t catch a login at 3am from a new device the very next morning.

  • A single compromised vendor user account bypasses all of it, as Qantas found out.
  • If an external user holds elevated privileges inside your SaaS applications, your IAM won’t stop them from using those privileges, as JLR found out.
  • If a third-party platform stores your customer data, no internal policy prevents attackers from accessing it through that platform.
  • If an OAuth connection grants a marketing tool access to your CRM, an attacker compromising that tool inherits the same access.

Put simply: in today’s hyper-connected world, internal strength does not compensate for external weakness.

Boards are now asking a new question

For years, the question was: “How secure are we?” Now it has become: “How secure are the people we trust?”

And that shift brings new responsibilities. Organisations must be able to answer:

  • Who are our third-party users?
  • Which systems can they reach?
  • What data can they access?
  • Do they still need that level of access?
  • How quickly can we revoke it?
  • Are we monitoring their activity with the same seriousness we apply internally?

And visibility isn’t just knowing who has access. It’s knowing how they normally behave, so you can see when something isn’t right.

Many would struggle to provide a clear answer. That is precisely where attackers operate.

Practical steps companies can take right now

The good news: tackling third-party risk doesn’t require dramatic reinvention. It requires structure, clarity, consistency and most importantly, VISIBILITY.

Here are the steps that matter most:

  1. Build a living inventory of external access

Not a spreadsheet that gets updated once a year. A continuously maintained view of all:

  • vendor accounts
  • API tokens
  • SSO links
  • service accounts
  • external users
  • SaaS applications with integrations into core systems

Most organisations underestimate this landscape by a wide margin.

  1. Apply least privilege, but do it properly

Vendors rarely need permanent admin rights. Set the minimum access required for their job. Make elevated privileges temporary. Review permissions on a regular basis, daily, weekly and monthly as a rule, not a reaction.

  1. Revisit OAuth and API permissions

These are now among the most common entry points in real-world breaches. Know what each integration can see, modify or export.

  1. Treat vendor offboarding as seriously as employee offboarding

When a contract ends, access must end the same day. No exceptions. Dormant vendor accounts are one of the highest-risk access paths.

  1. Monitor external behaviour continuously

Look for:

  • unusual login locations
  • high-risk permissions being used unexpectedly
  • data exports that don’t match normal patterns
  • logins outside operational hours
  • sudden privilege escalations

The aim is simple: build a clear picture of each external user’s pattern of life, so abnormal activity stands out immediately rather than blending into the noise. External activity deserves the same level of scrutiny as internal activity.

  1. Prepare a response plan for vendor compromise

When a vendor is breached, your window to respond is short. Have a clear process covering:

  • immediate token revocation
  • system isolation
  • communication protocols with the vendor
  • enhanced monitoring while the investigation unfolds

Minutes matter in these scenarios.

A more honest understanding of modern risk

The nature of cyber risk has changed. We are long past the point where companies can rely solely on their own controls. The modern enterprise is an ecosystem, and every part of that ecosystem can be targeted.

The breach you fear may not come from inside your organisation. It may come from a vendor you onboarded years ago, through a connection nobody remembers creating.

Middle Eastern organisations, in particular, sit at a critical moment. The region’s rapid growth means the number of external connections will only increase. That growth brings opportunity, innovation and competitive advantage, but without visibility and governance, it also brings exposure.

Strengthening internal security was the first phase of digital transformation. Strengthening the extended ecosystem will be the next step.

This feature appeared in issue 146 of Security Middle East magazine. 

Tags:
No Comments

Sorry, the comment form is closed at this time.

1