Where does your supply chain really end?
For many organisations, the answer is no longer obvious.
π A supplier may rely on a platform.
π π That platform may rely on a software provider.
πππ That software provider may depend on another technology partner, infrastructure provider or outsourced service.
And so, the chain continues.
The challenge is that risk rarely stops with the organisation you have contracted with directly. It moves through relationships, dependencies and services that sit beyond your visibility, extending far beyond the traditional boundaries of the organisation.
And while that has always been true to some extent, what has changed is the level of exposure those relationships can now introduce.
As a result, third-party risk is evolving beyond a supplier management exercise and into a broader resilience challenge.
Supply chains have always introduced complexity to operations, but what has changed is how actively that complexity is now being exploited.
The National Cyber Security Centre (NCSC) describes supply chain risk as the threat created by the extended network of relationships organisations rely on to deliver products, systems and services1.
The important word here is relationships.
Modern supply chains are built on trusted connections between organisations, systems and service providers, creating an ecosystem through which both value and risk can travel.
This reality helps explain why third-party attacks have become such an attractive option for threat actors.
Verizon's 2026 Data Breach Investigations Report found that breaches involving a third party increased by 60% year-on-year and now account for almost half (48%) of all breaches investigated2; a statistic that is striking, but hardly surprising.
As organisations continue to outsource services, adopt cloud platforms and depend on more layered supplier networks, attackers are following the same path.
Compromising one trusted supplier can create opportunities across hundreds or even thousands of downstream customers, making indirect access both efficient and scalable from an attackerβs perspective.
This is what makes third-party attacks so effective.
Rather than attempting to breach every target individually, attackers can exploit existing trust relationships and access paths already embedded within the supply chain.
As a result, organisations may invest heavily in securing their own environment, yet still remain exposed through the suppliers, platforms and services they depend on.
The perimeter, therefore, can no longer be defined simply by where the network ends. Today, it must be defined by where dependency begins.
As those dependencies become harder to secure directly, the challenge extends beyond assessing individual suppliers. It becomes a question of how organisations understand, manage and remain accountable for risk that sits beyond their direct control.
The regulatory environment is starting to catch up with this reality.
For a long time, third-party assurance has often been shaped by individual customer expectations: procurement questionnaires, contractual clauses, audit requests and internal security standards.
These are still important, but they are no longer the whole picture.
Regulation is beginning to formalise what organisations must understand, evidence and govern across the supply chain.
Across sectors, regulators are placing greater emphasis on supply chain resilience and third-party accountability, recognising that disruption often originates beyond an organisation's direct perimeter.
In financial services, the Digital Operational Resilience Act (DORA) places explicit focus on ICT third-party risk management, including oversight of critical providers and greater scrutiny of dependencies across the supply chain3.
In wider UK legislation, the Cyber Security and Resilience Bill proposes reforms designed to improve cyber defences and protect essential and digital services by adapting the existing Network and Information Systems Regulations 20184.
One of the most significant signals is the proposed ability for regulators to designate critical suppliers. The UK Government argues that suppliers supporting essential or digital services can be attractive targets because attacks on one part of a supply chain can cause widespread disruption5.
Under this intended approach, suppliers to organisations essential to the operation of national infrastructure could become subject to mandatory cyber requirements.
Together, these developments point in the same direction: a shift from customer-led assurance to clearer regulatory accountability for supplier risk and resilience.
This shift creates implications for both sides of the supply chain.
For buyers of business services, it raises the expectation to understand which supplier relationships create meaningful exposure. For suppliers, it increases the need to demonstrate resilience in a way that customers, regulators and auditors can trust.
In other words, regulation is not just adding another compliance burden. It is raising expectations around what organisations must know, evidence and be accountable for across their supply chains.
But clearer accountability does not automatically make assurance easier to deliver. That is where the third force comes in: the complexity of the ecosystems organisations now depend on.
The final force reshaping third-party assurance is complexity.
Not complexity driven by poor practice, but by modern business dependence on external platforms, specialist providers and outsourced expertise.
> Services have moved to the cloud.
> Critical business functions increasingly sit outside the traditional organisational boundary.
> Specialist partners now support everything from technology delivery to security monitoring, compliance, operations and customer experience.
While these decisions often make perfect operational, commercial or technical sense in isolation, they also make it harder to identify which supplier relationships introduce the greatest exposure. And this matters because not all suppliers pose the same level of risk.
A facilities provider, a SaaS platform and a managed service provider may all sit within the supply chain, yet the access they hold, the services they deliver and the disruption they could cause are fundamentally different.
As these ecosystems expand, organisations need to understand which relationships matter most, what level of assurance is appropriate and where attention should be focused.
In other words, the conversation needs to shift from collecting more supplier information to building more meaningful assurance.
Because when dependencies extend far beyond the organisation itself, the question is no longer:
Have we assessed this supplier?
It is:
Are we applying the right level of assurance to the risk they introduce?
The chain of effect is now clear:
π Attackers are exploiting trusted relationships.
π π Regulation is extending accountability.
π π π Organisations are becoming more dependent on suppliers, platforms and service providers that sit beyond their direct control.
Individually, each force is significant. But combined, they are reshaping how organisations approach third-party assurance.
The objective isnβt collecting more evidence, but collecting evidence that can answer the right questions, like:
This is why organisations are increasingly using third-party assurance to benchmark resilience, not simply demonstrate compliance. Because at its core, this movement is about confidence: confidence that risk is understood, prioritised and defended appropriately.
What that looks like will vary by organisation:
The immediate priorities may differ but the goal is the same: building third-party risk management programmes that are structured, proportionate and easy to defend.
For leaders looking to understand how third-party risk, accountability and assurance are evolving in real-time, we explore this topic in more depth in our on-demand webinar βBeyond the Perimeter: Navigating Third-party Riskβ, delivered in partnership with SureCloud.
Click here to catch up on the webinar insights.
1 NCSC, 2026. Supply Chain Cyber Security Guidance.
2 Verizon, 2026. Data Breach Investigations Report (DBIR).
3 PwC UK, 2026. DORA and its Impact on UK Financial Entities and ICT Service Providers.
4 UK.GOV, 2025. Cyber Security and Resilience Bill.
5 UK.GOV, 2026. Designating Critical Suppliers: Cyber Security and Resilience Bill Factsheet.