INSIGHT DETAIL

Third-Party Integration Risks

Does Your Company's Security Depend on Another Company?A company might use strong passwords, regularly update its systems, and implement security controls flawlessly. Yet, its data could still be compromised due to an issue with an external service it relies on.

Back to Homepage
Back to Homepage

Does Your Company's Security Depend on Another Company?

A company might use strong passwords, regularly update its systems, and implement security controls flawlessly. Yet, its data could still be compromised due to an issue with an external service it relies on.

This is because companies today do not operate solely within their own systems.

Payment processing is handled by a third-party provider. Customer emails are prepared using an external service. Personnel data is stored in human resources software. Visitor activity on the website is tracked via a separate analytics tool.

Each of these connections simplifies operations, but it also expands the scope of what the company needs to secure.

The main gate might be secure

Consider an apartment building. The main entrance has a security camera, a guard, and a robust lock. However, it is unknown who actually holds the key to the side entrance used by the cleaning company.

In this scenario, how well the main entrance is guarded is not enough on its own.

A similar situation can arise with third-party integrations. When an external service is granted permission to view customer records, access files, or perform operations within your system, that company's security posture becomes part of your own security.

If the external service is compromised, an attacker might attempt to exploit this connection rather than attacking your core system directly.

Why should a calendar app have access to all your files?

The problem isn't always that the service provider itself gets hacked; sometimes, an integration is granted excessive permissions.

For instance, an app used to schedule employee meetings should only need access to calendar data. If, however, it can also read email accounts, download contact lists, or access company files, the risk increases unnecessarily.

This is akin to giving a repairperson the keys to every room in the house, rather than just the kitchen door. Even if a service is reliable, it should not have access beyond what is strictly necessary. This is because if the provider's account is compromised, an attacker could inherit those same privileges.

Signing a contract is not enough

Before partnering with a company, details regarding pricing, service duration, and technical specifications are typically scrutinized. However, security matters are often glossed over with just a few boilerplate statements.

Yet, certain fundamental questions should be asked from the outset:

What data will the provider access? How long will they retain this data? In the event of a security incident, how quickly will they notify their customers? How is employee access restricted? Will the company's data actually be deleted once the service ends?

NIST’s Cyber Supply Chain Risk Management guide recommends that organizations evaluate not only the features of the product they are purchasing but also the cyber risks associated with the supplier. This approach encompasses the entire relationship, from the initial selection of the provider to the eventual termination of the contract.

Why do unused connections remain open?

Companies often experiment with various services over time. An application added for a specific project might fall out of use, yet the access permissions granted to it may remain active.

Months later, no one may recall why that connection was established in the first place. Even if employees no longer use the application, the access key may still be valid.

Therefore, third-party connections should be reviewed not only when they are first established but also at regular intervals. Unused integrations should be removed, obsolete access keys revoked, and privileges granted to external providers re-evaluated.

CISA also recommends auditing access granted to third parties and managed service providers, with particular attention paid to externally accessible accounts. ## Can risk be completely eliminated?

It is often not feasible for companies to develop all their services in-house. Working with third parties is standard practice and, when managed correctly, offers significant convenience.

However, working with a trusted brand does not eliminate the need for oversight.

You must know which services access which data, keep granted permissions as restricted as possible, and log any unusual activity. Terminating the relationship with a service provider requires just as much care as initiating it.

After all, your company's security does not depend solely on the strength of your own defenses; it also depends on how well the people you have entrusted with a "key" protect that key.

Disclaimer: This content has been prepared for general informational purposes and does not constitute professional cybersecurity consulting.