Attacks through suppliers
Data and third partiesComes in through: Suppliers
The door someone outside opens
Your accountant, your IT provider or your management software have access to your data or systems. If they're attacked, the problem can reach you too.
Threat mapHow it happens
- 1
The supplier
A supplier with access to your systems or data suffers an attack or a lapse.
- 2
The jump
The attacker uses that trusted access, or the supplier's email, to reach your company.
- 3
The impact
Fake emails that look legitimate, exposed data or compromised systems without you doing anything wrong.
How to spot it
- Suppliers with permanent access nobody reviews
- Emails from a supplier with account changes or odd requests
- You don't know what data of yours each supplier holds
- Passwords shared with suppliers
How to protect yourself
- Give each supplier only the access they need, and remove it when the work ends
- Verify a supplier's change of details through another channel
- Ask key suppliers how they protect your data
- Review third-party access regularly
If it has already happened
Remove or change the affected supplier's access, warn the team about possible fake emails in their name and ask the supplier what happened.
How many of these risks does your company have right now?
Take the cybersecurity test and discover your exposure level in 3 minutes. You'll get your score with the highest-risk areas, no sign-up required.
Free · No sign-up · 3 minutes