Getty Images

Tip

When a critical supplier gets breached: CISO's response guide

Third-party breaches account for a growing number of cyberattacks. Organizations must have strategies and systems in place before a critical vendor breach occurs.

One of your organization's critical third-party suppliers has been breached. Are you prepared for the fallout?

Each product or service your organization uses increases its third-party risk. Any cybersecurity or privacy issue involving one of these products or services could result in harm to your customers, regulatory penalties and reputational damage.

Yet, a breach at a supplier doesn't automatically mean your organization is compromised. The more deeply integrated the third party is in your data, systems and processes, however, the harder it can be to determine.

Third-party breaches are becoming more prevalent and broader in scope. Verizon's "2026 Data Breach Investigations Report" found that third-party exposures account for 48% of all breaches, while Black Kite's "2026 Third-Party Breach Report" concluded that every vendor breach results in an average of five downstream victims.

Let's examine how CISOs and security leaders should respond when a critical supplier is breached, from the most immediate actions to those taken in the days and weeks following breach disclosure. Then review how to strengthen your organization's third-party risk management practices to reduce risk from future breaches.

Responding to a critical supplier breach

The appropriate response actions for a critical vendor breach vary from case to case, but the following are typically important elements of any such response.

Is this our incident?

The first thing to determine is whether the breach extends into your organization. If, for example, the supplier has privileged access to your organization's systems, stores or processes your organization's data, connects directly to your organization's critical systems, or provides software or infrastructure within your environment, treat the incident as your organization's incident.

Immediate actions: First 24 hours

The first 24 hours are all about confirming, assessing and containing.

  • Confirm the breach scope and impact. Verify with the supplier that the breach is legitimate. Validate details, including which systems and services were affected and indicators of compromise.
  • Activate response teams. Notify and gather the incident response team, including legal, communications and PR teams.
  • Assess your organization's exposure. Identify which systems, services and data -- including customer, employee and enterprise -- were impacted.
  • Contain potential exposure. Isolate affected systems and begin containment, eradication and recovery processes. Use microsegmentation or firewall rules to isolate vendor-managed appliances and hosted software. Monitor the network for suspicious activity.
  • Map exposures and revoke access. Evaluate and suspend the supplier's access privileges, credentials, API keys and any CI/CD connections, including access to shared data stores, databases and S3 buckets, if feasible. Temporarily block data exchanges and stop shipments of any affected products.
  • Inform stakeholders. Notify executive leadership and the board and prepare internal communications.
  • Keep communication open with the vendor. Get more information from the supplier on the nature of the breach, its potential impacts and its recommended response and mitigation actions.
  • Document everything. Record all actions and findings. Meet all reporting and notification deadlines related to the breach.
  • Consider downstream clients. If your organization is a supplier, estimate what impact, if any, the breach might have on your products, services and customers.

Subsequent actions: Days 2-7

The first week involves investigating, communicating and mitigating risk.

  • Assess supplier dependencies and business continuity risks. Fully map supplier dependencies, including all touchpoints between your organization and the supplier. For example, assess data flows, connections and shared credentials. Identify which business processes depend on the supplier and determine if an alternative supplier or manual process exists. Establish how long your organization can operate without the supplier and whether inventory, manufacturing, payments, customer service or other operations could be affected. Activate business continuity and disaster recovery plans as needed.
  • Continually communicate with the vendor. Make sure the vendor shares its breach timeline, blast radius and root cause analysis, including forensics findings, and provides any other updates on a regular schedule.
  • Perform in-depth incident analysis, threat hunting and forensics investigations. Determine the full extent and impact of the breach, including potential attack vectors and entry points to your network and systems. Assess the probability of lateral movement from supplier systems. Review logs for indicators of compromise and assess the risk of data exfiltration. Preserve relevant logs, authentication records, communications and key dates and times, including when credentials and access were revoked. Engage third-party forensics support if needed.
  • Risk mitigation. Implement additional security controls as needed, reset affected credentials and rotate keys. Continuously monitor the network for suspicious behaviors.
  • Communicate with stakeholders. Keep key stakeholders, both inside and outside the organization, updated on the progress of incident response actions. Brief executive leadership and board members, business units, IT teams and company employees. Notify customers who might be affected and coordinate communications with legal and PR teams. Manage media response, if needed.
  • Evaluate regulatory responsibilities. Review breach notification requirements and legal mandates, as well as contractual obligations. Notify regulatory bodies if necessary.

Next steps: The weeks after

In the following weeks, begin operational recovery. Restore affected systems and validate their security. Continue with compensating controls and resume operations with enhanced monitoring.

Now is the time to assess the relationship with the affected supplier. Review its remediation plan and incident response measures, and confirm it has remediated the issues. Consider the following questions:

  • How transparent was the vendor during the incident response lifecycle? Did the vendor proactively share information or only respond to inquiries?
  • What was the supplier's mean time to disclosure after discovering the breach?
  • What steps is the supplier taking to prevent future breaches and to improve how it handles future attacks? What specific controls has it implemented?
  • Has the vendor engaged third-party auditors to validate remediation?
  • Did the supplier meet all requirements in the current contract regarding the breach, such as reporting sufficient information to the organization in a timely manner?
    • If not, how did the supplier fail to meet requirements, and what measures is the supplier taking to ensure that does not happen again?
  • Is the vendor offering any financial remedies or service credits?
  • Is the supplier willing to negotiate changes to the contract that add or strengthen breach-related requirements? Will it agree to more frequent security assessments and audits?
  • Will the supplier share its cyber insurance information and/or incident response plan?

These questions will help you decide whether to continue the relationship with the supplier.

Set clear benchmarks before restoring any integrations or connections with the supplier and assess future contracts and renewal terms. When the vendor relationship resumes, follow third-party risk management best practices.

Continue to brief stakeholders on the latest information related to the breach.

Longer-term steps: Lessons learned and program updates

In the months after the critical third-party supplier breach, complete post-incident analysis and perform a comprehensive review. Evaluate response effectiveness and update incident response plans accordingly. Conduct tabletop exercises based on the review and plan updates.

Review your organization's third-party risk management program. Now's the time to update it -- not in the middle of a critical vendor breach. Breach response strategies should be proactive and implemented well before the next breach occurs.

The third-party risk management lifecycle has three phases:

  1. Before the contract. Characterize the type of risk a supplier is likely to pose. Once identified, include those risk requirements in the contract with the supplier and ensure they reflect your organization's third-party risk management policy. Conduct due diligence, determine fourth-party dependencies and negotiate incident notification requirements.
  2. During the contract. Onboard the supplier, then continuously monitor and periodically assess its behavior. Ongoing oversight is particularly challenging for many organizations. Review any changes in the supplier's environment, and periodically review access. Test incident response processes.
  3. Contract termination. End the contract. Ensure all assets are returned to their owners and that all proprietary data and other sensitive information are securely wiped from supplier systems. This includes terminating contracts with cloud service providers. Revoke credentials and connections, retrieve data, verify data destruction and remove integrations.

Additional key third-party risk management best practices include:

  • Implementing continuous vendor monitoring.
  • Following the principle of least privilege for all vendor access.
  • Keeping track of vendors' security ratings.
  • Auditing suppliers and vendors regularly, based on their risk tier.
  • Developing supplier breach response playbooks.
  • Regularly reviewing and updating incident response plans and playbooks.
  • Adopting zero trust with microsegmentation for vendor access.
  • Creating and regularly updating software bills of materials.
  • Conducting third-party breach response tabletop exercises.

Karen Kent is the co-founder of Trusted Cyber Annex. She provides cybersecurity research and publication services to organizations and was formerly a senior computer scientist for NIST.

Sharon Shea is executive editor of TechTarget Cybersecurity.

Dig Deeper on Enterprise Risk Management