VenDefend Third-Party Risk Management
Book A Demo
← All posts

Preparing for the “What If” Moment

The rise in third-party related data breaches is testament that third-party risk management must evolve into third-party resilience. By understanding your dependencies, anticipating how incidents could affect the business and testing your ability to respond and recover.

Risk Management Guru·

Third-party risk is no longer a distant or theoretical concern. In the space of just a few days, Cell C, EasyEquities and Bidvest Bank notified customers of cybersecurity incidents involving external service providers and the potential exposure of customer information. These incidents were not necessarily connected, but their timing offers a powerful reminder of how deeply modern businesses depend on third parties

This is not a criticism of how these organisations managed their third parties. Every organisation, regardless of how mature its controls may be, operates with some degree of third-party exposure. Rather, these incidents provide a timely local example of a wider trend. According to Verizon’s 2025 Data Breach Investigations Report, third-party involvement in breaches doubled from 15% to 30% in a single year. The risk is also becoming more concentrated. One compromised provider can expose several organisations at the same time.

The odds favour the attacker

An organisation must understand and protect every part of the third-party supply chain. How a third-party connects to its systems, processes and stores its data, and support its processes and customers. Were as an attacker only needs to find one vulnerable system, process or person across the entire supply chain.

The more suppliers, platforms, integrations and subcontractors a business relies on, the more potential points of exposure it must understand. Some will hold personal information. Others will support essential operations, manage customer verification, host critical systems or provide services without which the organisation cannot meet its own commitments.

Businesses cannot eliminate all third-party risk. Even a supplier that performs well during an assessment can later experience a breach, outage, control failure or disruption.

So, the question should therefore not only be “How do we prevent a third-party incident?”

It should also be “What happens to our business when one occurs?”


Preparing for the “what if” moment

Traditional third-party risk management often concentrates on due diligence. A supplier completes a questionnaire, submits policies and certificates, receives a risk rating and is reassessed periodically. These activities remain important, but they do not establish whether the organisation is ready to respond when something goes wrong. That requires businesses to work through realistic “what if” scenarios before they become real incidents.

What if our third party experiences a data breach?

Do we know what information it holds, where that information is stored and whether subcontractors can access it? Is the provider contractually required to notify us quickly enough for us to meet our own legal, regulatory and customer obligations? Do we know who will investigate, make decisions and communicate with affected customers?

What if our third party cannot meet its service-level commitments?

Which business services would be affected? Would customers experience delays or lose access to an essential service? How long could the business continue operating before the disruption became unacceptable?

What if the provider’s recovery takes longer than our business can tolerate?

Do we have a practical workaround, an alternative provider or the internal ability to continue the service? Has that arrangement ever been tested, or does it exist only in a document?

What if the incident begins with one of the provider’s own suppliers?

Many organisations assess their direct providers without understanding the subcontractors, cloud platforms and specialist services supporting them. This creates an important blind spot: the organisation may depend on a company with which it has no direct relationship, limited visibility and no contractual control. These are not simply cybersecurity questions. They are questions about operational resilience, customer protection and the organisation’s ability to continue delivering its services.

Moving from third-party security to third-party resilience

Third-party security focuses largely on whether a supplier has appropriate controls. Third-party resilience goes further by examining how the organisation will anticipate, withstand, respond to and recover from a disruption involving that supplier.

A resilient approach begins with context.

The organisation must understand which business services depend on each third party, which systems and data support those services, and what would happen if the relationship were disrupted. This makes it possible to identify which providers require more scrutiny, stronger contractual obligations, closer monitoring and tested contingency arrangements.

It also changes the purpose of an assessment. Instead of asking every provider the same collection of questions, the organisation can assess the controls that matter for the specific relationship. A supplier processing customer identity information should face detailed questions about data protection, access control, incident detection, breach notification and secure data disposal. A supplier supporting a time-sensitive operational process may require greater attention to service availability, recovery capabilities, capacity and alternative delivery arrangements.

This is the foundation of context-driven third-party risk management. Connecting the provider’s controls to the actual exposure created for the business.

Resilience must exist before the incident

The early stages of a third-party incident are often marked by incomplete information. The affected provider may still be investigating what happened, which systems were accessed and whose information was exposed. The organisations relying on that provider cannot wait for every question to be answered before beginning their response.

They need to know where the provider fits into their operations, what information has been shared with it, which customers or services could be affected and who has the authority to act. Incident notification channels must already exist, responsibilities must be understood and escalation thresholds must be clear.

Continuity arrangements should also be tested against realistic scenarios. A document stating that another provider could take over is not enough if that provider has never been evaluated, contracted or tested. Similarly, a manual workaround offers little reassurance if it cannot support the required transaction volumes or recovery time. Resilience is created through preparation, not while an incident is in progress.

The question every business should ask

The recent data breach reports bring third-party cyber risk firmly into our local business environment. They demonstrate that an organisation’s exposure extends beyond the systems it owns and directly controls.

Preventing incidents must remain a priority. But prevention alone is not a complete third-party risk strategy. Businesses must identify their important third-party dependencies, understand the potential impact of disruption, establish clear incident-reporting arrangements and test how they will continue operating when a provider fails.

The most important question is no longer simply whether a third party could experience an incident. It is whether your business will be ready when it does.

Prepare for a third-party breach or disruption before it affects your business.