BLOG

Why Supply Chain Attacks Succeed: Your Vendors Are Your Attack Surface

Supply chain cyber attack and vendor risk: attackers reach you through a trusted vendor's authorized access, not your perimeter.

By David Chernitzky, Co-Founder and CEO, Armour Cybersecurity  |  Serving organizations across Canada, the US, and beyond  |  Last updated August 18, 2026

Quick answer: Supply chain attacks succeed because attackers find it easier to compromise a trusted vendor with access to your systems than to breach your own perimeter directly. When a software provider, managed service provider, or SaaS platform you rely on is compromised, the attacker inherits that vendor’s legitimate access to your environment. Most organizations have no structured program for evaluating, monitoring, or responding to the supply chain cyber attack and vendor risk their suppliers carry, which is exactly why supply chain is now one of the most exploited attack vectors against mid-market and enterprise businesses.

Key Takeaways

  • A supply chain attack does not breach your perimeter. It uses a trusted vendor’s legitimate access to reach your systems, data, and customers. Your perimeter controls do not stop an attacker who arrives through an authorized connection.
  • The average mid-market organization shares system or data access with dozens to hundreds of vendors. Most organizations have not inventoried which vendors have access to what, which means they cannot prioritize, monitor, or respond to vendor risk in any structured way.
  • Software supply chain attacks, in which malicious code is embedded in a software update delivered to customers, are particularly difficult to defend against because the malicious code arrives through a channel the organization explicitly trusts and has approved.
  • Regulators, auditors, and cyber insurance underwriters now explicitly require documented third-party risk management programs. SOC 2, ISO 27001, HIPAA, PCI DSS, and NIST 800-161 all include vendor risk management as a required control area.
  • The first step in any supplier risk program is vendor discovery: a structured inventory of every vendor with access to your data, systems, or customers. Organizations that have not completed this inventory cannot manage the risk they cannot see.

How Supply Chain Attacks Work

A supply chain attack exploits the trust relationships between an organization and its vendors, suppliers, and software providers. Rather than attempting to breach the target organization directly, the attacker identifies a vendor that has authorized access to the target and compromises that vendor first. Once the vendor is compromised, the attacker uses the vendor’s legitimate credentials, connections, or software distribution channels to reach the target organization. From the target’s perspective, the intrusion arrives through an authorized channel, which makes it significantly harder to detect than an external attack against the perimeter.

The SolarWinds breach of 2020 remains the most widely cited example of software supply chain attack at scale. Attackers compromised SolarWinds’ build environment and embedded malicious code into a software update for the Orion network management platform. When SolarWinds distributed the update, approximately 18,000 customers installed it, trusting that a signed update from their software vendor was legitimate. The malicious code provided the attacker with backdoor access to each customer’s environment. The attack was not discovered for months because the malicious traffic was indistinguishable from normal Orion traffic. The victims’ perimeter controls were irrelevant; the attacker had arrived through a trusted channel.

Why Third-Party Access Is Structurally Difficult to Control

The business reasons for granting vendors access to systems and data are legitimate and often unavoidable. A managed IT service provider needs administrative access to manage infrastructure. A SaaS platform needs access to data to provide the service. A payroll processor needs access to employee records to process compensation. A cybersecurity monitoring vendor needs network access to observe traffic. Each of these access grants serves a defined business purpose, and the vendor’s access is authorized precisely because the organization trusts the vendor to use it appropriately.

The structural problem is that every vendor access grant extends the organization’s attack surface beyond its own perimeter controls. The organization cannot directly observe what security practices the vendor applies to the credentials it holds, the data it processes, or the connections it maintains. It cannot verify in real time whether the vendor’s environment has been compromised. And when a vendor is compromised, the attacker has access that the organization itself authorized, making detection and response significantly more complex than for an unauthorized intrusion. Broad vendor access of this kind is best constrained through identity and privileged access management, so that even an authorized connection is scoped and monitored.

What Most Organizations Are Missing

Vendor inventory

The most fundamental gap in most organizations’ third-party risk posture is the absence of a complete, accurate inventory of which vendors have access to which systems and data. IT-sanctioned vendors appear in procurement records. Shadow IT vendors, the SaaS tools that individual teams adopt without formal procurement review, do not. Vendors that were onboarded years ago and whose access was never re-evaluated sit in the environment with permissions that may no longer reflect the current relationship or business need. Organizations that have not conducted a structured vendor discovery exercise cannot know how many vendors they have, what access each has, or which ones represent the highest risk.

Risk differentiation

Not all vendor relationships carry the same risk. A vendor with administrative access to production systems carrying customer data is a materially different risk than a vendor providing office supplies with no system access. Most organizations without a formal supplier risk program apply the same level of attention to all vendors, or more commonly, no structured attention to any. The managed service provider with broad administrative access and the courier company with a vendor login to the shipping portal receive identical treatment: an onboarding questionnaire that nobody reviews and a contract that nobody audits. This failure to differentiate risk by vendor access and criticality means that high-risk vendors receive the same cursory attention as low-risk ones.

Ongoing monitoring

Vendor risk assessments conducted at onboarding capture the vendor’s security posture at a point in time. A vendor that was well-managed when it was onboarded two years ago may have experienced a leadership change, a significant growth phase, a security incident, or a deterioration in its controls in the intervening period. Without ongoing monitoring, the organization has no mechanism for detecting these changes. Security ratings services provide automated monitoring of publicly observable indicators of vendor security health. Certification tracking identifies when a vendor’s SOC 2 or ISO 27001 certification has expired or not been renewed. Threat intelligence feeds identify when vendors have been mentioned in breach reports or vulnerability disclosures. These monitoring inputs require a structured program to be actionable.

Contractual safeguards

Vendor contracts that lack specific security provisions provide no contractual basis for requiring security improvements, obtaining audit rights, or enforcing breach notification timelines. Many organizations have vendor relationships that are governed by the vendor’s standard terms, which are written to protect the vendor rather than the customer. The security provisions in these standard terms are typically minimal: a general statement that the vendor will maintain reasonable security practices, with no definition of what reasonable means and no audit rights that allow the customer to verify it. Negotiating specific security provisions into vendor contracts, including minimum control requirements, audit and assessment rights, breach notification timelines, and data return and deletion obligations at contract termination, is a component of supplier risk management that most organizations have not systematically addressed.

Armour Cybersecurity’s Supplier Risk Management service addresses all of these gaps through a structured six-phase program: vendor discovery, criticality tiering, framework and questionnaire design, assessment execution, contractual and monitoring design, and program operationalization.

What Regulators and Auditors Expect

Third-party risk management is no longer an optional best practice for organizations subject to security certification or regulatory oversight. SOC 2 Trust Services Criteria CC9.2 explicitly requires that the organization assesses and monitors the risks from vendors and business partners that could affect the achievement of the service commitments and system requirements. ISO 27001 Annex A includes supplier relationships as a required control domain. HIPAA requires covered entities and business associates to manage the security risks from their business associates through signed business associate agreements and an assessment of the business associate’s security practices. PCI DSS Requirement 12.8 requires maintaining and implementing policies and procedures to manage service providers with whom account data is shared. NIST SP 800-161 is dedicated entirely to supply chain risk management and is the reference framework for federal supply chain participants and organizations aligning to NIST standards. Managing these obligations coherently is part of a broader governance, risk and compliance function rather than a standalone vendor exercise.

Cyber insurance underwriters have similarly elevated their expectations for third-party risk management in recent years, driven by the significant claims resulting from supply chain attacks. Applications that cannot demonstrate a structured vendor risk program, including tiered assessment, ongoing monitoring, and contractual safeguards, increasingly receive scrutiny, higher premiums, or coverage limitations for supply chain-related losses, a pattern covered in more detail in our cyber insurance advisory work.

Frequently Asked Questions

How do attackers identify which vendor to target for a supply chain attack?

Attackers conducting supply chain attacks research the target organization’s vendor relationships using publicly available information, including job postings that list technology platforms in use, vendor case studies and press releases that name customers, social media profiles of employees that mention specific tools, and domain infrastructure analysis that reveals connected systems and services. Managed service providers are particularly attractive targets because a single MSP typically has administrative access to multiple customer environments, giving the attacker reach across the MSP’s entire customer base from a single compromise. Software vendors with large customer bases represent high-value targets for the same reason.

What is a managed service provider and why is it a high-risk vendor category?

A managed service provider is a company that delivers IT services to client organizations under a long-term agreement, typically with remote administrative access to the client’s infrastructure. MSPs often have broad administrative privileges across the environments they manage: domain administrator rights, access to backup systems, network management authority, and in some cases privileged access to security tools. This level of access, combined with the fact that the MSP connection is authorized and trusted by the client’s security controls, makes MSPs a priority target for supply chain attackers. When an MSP is compromised, every client whose environment the MSP has access to is potentially reachable through the compromised MSP infrastructure.

What is the SIG questionnaire framework?

The Standardized Information Gathering questionnaire is published by Shared Assessments, a member-driven organization focused on third-party risk management. The current SIG covers 21 risk domains organized within four control areas, governance and risk management, information protection, IT operations and business resilience, and security incident and threat management, and it is designed to be used by organizations assessing the security practices of their vendors. It is structured to be tiered: a shorter SIG Lite version for lower-risk vendors and a fuller SIG Core for higher-risk vendors. Because Shared Assessments updates the SIG annually and the domain and question counts change from year to year, the working assumption should be to use the domains and question set in the specific SIG version being requested rather than a fixed count. Using a recognized questionnaire framework like the SIG rather than developing questions from scratch reduces the assessment design burden, ensures coverage of all relevant risk areas, and makes responses more comparable across vendors that may complete the SIG for multiple customers.

How does NIST SP 800-161 apply to organizations that are not in the federal supply chain?

NIST SP 800-161 was originally developed for federal agencies and their supply chains, but its guidance is applicable to any organization that wants a structured framework for cybersecurity supply chain risk management. The publication provides guidance on identifying, assessing, and mitigating cybersecurity risks throughout the supply chain, including risk assessment methodologies, acquisition guidance, and controls specific to supply chain risk. Many private sector organizations use NIST 800-161 as a reference framework for their supplier risk programs alongside ISO 27036 and the SIG framework, particularly when they need to satisfy government customers or operate in sectors that reference NIST standards in their regulatory frameworks.

What should we do immediately if we discover a vendor has been breached?

The immediate actions when a vendor breach is discovered follow the vendor incident response protocol that a mature supplier risk program has pre-arranged. If no protocol exists, the immediate priorities are to assess what access the vendor has to your systems and data, to temporarily restrict or revoke that access while the vendor’s breach is being investigated, to review your own systems for indicators of compromise that may indicate the attacker reached you through the vendor’s access, and to determine whether the breach triggers any notification obligations under applicable privacy or security regulations. Legal counsel and your breach response team should be engaged immediately. The absence of a pre-arranged protocol at this moment is the primary cost of not having a supplier risk program in place before the incident.

The Bottom Line

A supply chain attack does not knock on your front door; it walks in through a vendor you already trust, using access you already granted. That is why your firewall, your endpoint controls, and your perimeter do not stop it. The organizations that manage this well are not the ones with the most tools; they are the ones that know exactly which vendors can reach their systems and data, have tiered those vendors by risk, monitor them over time, and have put real security terms in their contracts. It starts with vendor discovery, because you cannot manage the risk you cannot see. A structured supplier risk management program builds that visibility and the controls around it, before a vendor’s breach becomes yours.

Leave the first comment