· THIRD-PARTY RISK

Third-Party Cyber Risk in Regulated Supply

A supplier’s weaknesses become the organisation’s exposure without ever appearing on its own asset inventory. CROs hold trial data, CDMOs hold batch records, software vendors hold standing remote access, and cloud platforms hold everything. The quieter risk is concentration: many suppliers depending on one underlying platform means a single outage reaches everywhere at once, through relationships that each looked independent when they were assessed.

What an explainer is not

A topic explainer is SPEQ’s synthesis of what a practice involves, cited to the standards that govern it. It does not reproduce their text, and it does not determine which of them apply to your product or process.

[ POSITION IN THE FRAMEWORK ]

7 DIMENSIONS · 25 LINKS

A supplier’s security failure becomes the sponsor’s regulatory problem: the obligation to demonstrate control does not transfer with the work, which makes cyber risk a supplier-quality question rather than a procurement one.

06 · QUALITY MATURITY — THIRD-PARTY CYBER RISK IN REGULATED SUPPLY, REACTIVE TO ADAPTIVE

L1
Reactive

Suppliers are assessed on quality and price. Security is assumed, or covered by a clause nobody has tested.

L2
Defined

A security questionnaire is issued at onboarding, filed, and never revisited or verified.

L3
Controlled

Security assessment depth follows what the supplier holds and what they connect to, obligations are contractual including notification, and connections are enumerated.

L4
Predictive

Supplier security is monitored in service, notification obligations have been exercised, and a supplier incident triggers the sponsor’s own assessment of record integrity.

L5
Adaptive

Critical suppliers are integrated into the sponsor’s security posture — shared exercises, agreed recovery expectations — so an incident is a joint response rather than a discovery.

SPEQ’s shared five-stage progression, labelled synthesis — not the FDA QMM rating scale. Where does your organization sit? Score your quality system →

07 · REGULATORY & EVIDENCE

GOVERNING STANDARDS · 5

Derived from the 5 standards SPEQ maps to this subject, across 4 regulatory bodies: EMA, ICH, ISO, EC.

RECORDS & OBJECTIVE EVIDENCE

  • The inventory of suppliers holding regulated data or connecting to regulated systems
  • Security assessment records, scaled to what each supplier holds or accesses
  • Contractual security and breach-notification obligations
  • Records of supplier connections, including what each can reach
  • Any supplier incident, and the sponsor’s own integrity assessment following it

COMMON INSPECTION FINDINGS

  • No inventory of which suppliers hold regulated data
  • Onboarding questionnaires accepted without verification and never refreshed
  • Supplier network connections with broader access than the work requires
  • No breach-notification obligation, so the sponsor learns of an incident indirectly
  • A supplier incident closed by the supplier with no sponsor assessment of the records involved
EVERY CHIP IS A DOOR · WALK THE FRAMEWORK FROM ANY SUBJECTHow SPEQ maps the framework →

Assessment that asks the questions a questionnaire cannot

Annex 11 requires the regulated user to assess suppliers of computerised systems and services, with the depth driven by risk and criticality. The default implementation is a questionnaire, and its weakness is structural: it asks whether controls exist and gets the answer the supplier believes. What it does not establish is whether the certified scope covers the service being bought, whether the attestation excludes the relevant subsystem, and what access the supplier actually holds today.

Those three questions are worth more than the rest of the questionnaire. Read the ISO/IEC 27001 Statement of Applicability rather than the certificate; read the scope section of a SOC report rather than the opinion; and enumerate the supplier’s live access from your own identity system rather than from their answer. The third is routinely surprising.

Contract terms that are usable during an incident

Most supplier agreements say something about security and very few say anything usable at two in the morning. The terms that matter are specific: notification of a security incident affecting your data or service within a defined period, a right to the information you need to make your own regulatory notifications, notice of material subprocessor changes, defined data-return and deletion obligations at exit, and audit or evidence rights proportionate to criticality.

The notification clause deserves particular attention because of the clocks it feeds. If GDPR Article 33 requires notification within 72 hours of awareness, and NIS2 requires an early warning within 24 hours, a contract permitting the supplier to notify you within a week has made both obligations unmeetable — through a term nobody read as a compliance decision.

Concentration risk hides behind independent relationships

Third-party risk is assessed relationship by relationship, which is exactly why concentration is invisible. Six suppliers assessed independently can all run on the same infrastructure provider, use the same identity platform, or depend on the same specialist subcontractor. Each assessment was reasonable; the aggregate exposure was never assessed at all.

The analysis is not difficult and is rarely done: map the fourth parties behind the critical suppliers and look for the names that repeat. Where a single dependency underlies several supposedly independent services, that is a business-continuity input rather than a security finding — it changes what a continuity plan has to assume, because the fallback supplier may share the failure.

The access nobody revoked

Supplier access outlives supplier relationships with striking regularity. A contract ends, the commercial relationship closes, and the accounts, VPN profiles and API credentials remain live because offboarding was a procurement activity and nobody told identity management. The same applies to individuals: a vendor engineer who left that vendor two years ago may still hold a working account.

The controls are ordinary and specific: supplier accounts owned, scoped and reviewed like privileged human accounts; per-session rather than standing access wherever the work allows; and an offboarding step in contract closure that verifies revocation against the systems rather than against the directory. Verification against the systems matters — the directory entry is usually the one thing that does get removed.

SPEQ interpretation — one supplier, one assessment

Regulated organisations typically assess the same supplier twice: a quality audit against GxP expectations, and a security assessment against information-security expectations, run by different functions on different schedules with different records. The supplier experiences two overlapping requests; the organisation gets two partial pictures and no combined view of what that supplier could actually cause.

SPEQ’s view is that the assessment should be one activity with two lenses. The scoping question is the same — what does this supplier do for us, what data and access do they hold, what happens if they fail — and the divergence starts only at the control set. Running them together also puts the security finding in front of the person who owns the quality agreement, which is where a remediation commitment can actually be enforced.

FREQUENTLY ASKED

Is a supplier’s SOC 2 report or ISO 27001 certificate enough assurance?

Only after reading its scope. Both are scoped documents and the scope frequently excludes the specific service being bought, or covers a corporate entity rather than the operating site. Read the Statement of Applicability or the SOC scope section, and confirm it covers the service, the location and the subsystem you depend on.

What contract terms actually matter for supplier cyber risk?

Incident notification within a period that lets you meet your own regulatory clocks, a right to the information needed for your notifications, notice of material subprocessor changes, data-return and deletion obligations at exit, and evidence or audit rights proportionate to criticality. A notification clause permitting a week makes GDPR’s 72 hours and NIS2’s 24-hour early warning unmeetable.

What is concentration risk and why is it usually missed?

Several suppliers depending on the same underlying provider, platform or subcontractor, so one outage reaches services that looked independent. It is missed because third-party risk is assessed relationship by relationship and the aggregate is never assessed. Mapping the fourth parties behind critical suppliers and looking for repeated names is the analysis.

Should quality and security assess a supplier separately?

They should not. The scoping question is identical — what the supplier does, what data and access they hold, what happens if they fail — and only the control set diverges. Running one assessment with two lenses gives a combined picture and puts security findings in front of the person who owns the quality agreement and can enforce remediation.

PROFESSIONAL · INSPECTION PLAYBOOK · SPEQ SYNTHESIS

The inspection-readiness playbook for this topic

CHECKING ACCESS

Checking your Professional access…