It does not matter how much a business has invested in securing its own network if an attacker can walk in through a supplier, service provider or SaaS application with legitimate access. Your weakest supplier could be your biggest cyber risk.

In today’s interconnected supply chains, the security of a business increasingly depends on organisations it does not control, may barely know, and may never have considered part of its cyber security perimeter.
This is not a theoretical problem for South African businesses. Third-party risk was identified as the leading concern by 60% of South African CISOs in the 2026 ITWeb Brainstorm CISO Survey, while PwC’s 2026 Digital Trust Insights research found that only 6% of South African organisations consider themselves very capable of managing supply chain vulnerabilities.
The uncomfortable part is that supply chain businesses can have hundreds or even thousands of suppliers, and every one of those relationships potentially introduces another point of exposure.
The risk becomes even harder to manage because suppliers have suppliers of their own. A manufacturer, distributor, retailer or logistics company may depend on technology providers, outsourced service companies, contractors and software platforms, all of which may have some level of access to its systems or information.
Somewhere in that chain there may be a smaller business with access to an email account, application, shared platform or corporate network that has security controls nowhere near those of the organisation ultimately carrying the risk. The bigger the ecosystem becomes, the harder it is to know exactly where the exposure sits.
Cloud and SaaS have made this trust chain even longer. A business may rely on Microsoft 365 for email, a cloud platform for financial systems, a SaaS application for customer management, another service for logistics and an external provider for IT support. These systems are often connected through APIs and integrations, creating relationships that are easy to establish but surprisingly difficult to understand.
The security of an application matters, but so does what it can access. An organisation can carefully assess the security of a SaaS provider while overlooking the permissions granted to the application itself, potentially giving a compromised service access to sensitive data, mailboxes, files or business systems.
There is another problem, and it is often hiding in plain sight. Business users can introduce cloud applications without waiting for IT, signing up for services within minutes and connecting them to corporate data. Marketing, finance, sales and operations teams may all have legitimate reasons for doing so, but the organisation can quickly lose visibility of which applications are connected to corporate identities and information.
This is often referred to as shadow SaaS. What begins as a useful productivity tool can quietly become another part of the attack surface, particularly when nobody knows who still has access to it or what happens when an employee leaves.
This is where traditional supplier due diligence starts to fall short.
A questionnaire completed once a year does not tell you whether a supplier has subsequently suffered a breach, changed its infrastructure, added another subcontractor, altered access permissions or introduced another cloud service into the environment. Nor does it necessarily tell you what happens when that supplier depends on another provider.
The real question is not simply whether a supplier is secure, but how far the trust relationship extends. Critical suppliers need to be identified, privileged access controlled, cloud and SaaS connections understood and third-party accounts monitored, while access should disappear when the business relationship ends.
Where a supplier is genuinely critical, organisations also need to understand how they would continue operating if that supplier suffered a cyber incident, ransomware attack or prolonged outage.
Addressing third party risk requires continuous visibility across endpoints, cloud environments, Microsoft 365, SaaS platforms and the wider digital estate.
The objective is not simply to monitor what happens inside the organisation, but to identify the signs that something connected to it has become a security problem, giving IT and security teams an opportunity to respond before a supplier compromise becomes a business compromise.
The answer is not to stop using suppliers, cloud services or SaaS. That would be neither realistic nor commercially sensible. The answer is to understand where trust exists, what that trust allows someone to access and what the consequences would be if it were abused.
Every supplier, SaaS platform, integration and business partner effectively extends a company’s digital footprint. Cyber security is no longer just about defending the systems a company owns, it is about understanding the ecosystem on which the business depends. For supply chain companies, that ecosystem is now part of the attack surface, and ignoring it does not make the risk disappear.
Roy Alves, Sales Director, J2 Software