# What is Third-Party Cyber Risk?

> Third-party cyber risk is the potential for harm arising from an organization’s reliance on suppliers, service providers, contractors, partners, and other external parties.

- Canonical URL: https://yellowcube.eu/glossary/third-party-cyber-risk/
- Publisher: Yellow Cube
- Language: en
- Contact: hello@yellowcube.eu

## Content

Harm can result from a provider’s compromise, outage, unsafe product, excessive access, poor data handling, insecure integration, or inability to meet recovery and notification needs. Dependencies can extend through subcontractors and shared platforms that the organization does not contract with directly.

Managing this risk is a lifecycle activity. It begins before selection, continues through contracting, onboarding, operation, change, incident response, renewal, and offboarding, and should be proportionate to the service’s access, data, substitutability, concentration, and business criticality.

### Key points

- **Prioritize relationships:** Identify which parties support critical services, process sensitive data, hold privileged access, supply trusted code, or create concentration and systemic dependencies.
- **Set requirements:** Define security, resilience, evidence, subcontracting, vulnerability handling, incident communication, recovery, data return, and termination expectations in enforceable agreements.
- **Control connectivity:** Apply least privilege, separate identities, monitored administration, approved integration paths, and prompt removal of access when the relationship changes.
- **Monitor and prepare:** Reassess material changes, review relevant evidence, coordinate response contacts, test important contingencies, and maintain viable substitution or exit plans.
- **Important limitation:** A questionnaire, audit report, certification, or contract clause provides evidence — not certainty. The organization retains risk from the dependency and must decide how to reduce, share, avoid, or accept it.

### Related terms

[Supply-chain security](<https://yellowcube.eu/glossary/supply-chain-security/>) · [Cyber risk](<https://yellowcube.eu/glossary/cyber-risk/>) · [Third-party risk management (TPRM)](<https://yellowcube.eu/glossary/third-party-risk-management/>) · [Concentration risk](<https://yellowcube.eu/glossary/concentration-risk/>) · [Managed security service provider (MSSP)](<https://yellowcube.eu/glossary/managed-security-service-provider/>)

### Sources

[NIST Cybersecurity Framework 2.0](https://csrc.nist.gov/pubs/cswp/29/the-nist-cybersecurity-framework-csf-20/final) · [NIST SP 800-161 Rev. 1 Update 1: Cybersecurity Supply Chain Risk Management](https://csrc.nist.gov/pubs/sp/800/161/r1/upd1/final) · [CISA: Assessing Vendors and Suppliers](https://www.cisa.gov/resources-tools/resources/assisting-small-and-medium-sized-businesses-assess-vendors-and-suppliers-fact-sheet)

## Attribution and scope

This Markdown representation is generated from the same approved content records as the canonical HTML page. Cite the canonical URL above when referencing this material. Product and service descriptions are informational; confirm project-specific requirements with Yellow Cube.

