By Dominic Hawthorne · 11/10/2026 · 15 min read

There is no pleasant way about it; the security challenges posed by third-party vendors can put an end to a Monday morning in a hurry, not to mention the data breaches, ransomware and theft they can bring in their wake. Your systems, people and payments are within reach of your contractors, suppliers, managed service providers and cloud apps, meaning any vulnerability on their side is yours for the taking.

I am Dominic Hawthorne. You will find me in the company of small tourism operators, regional businesses and park teams most of my working life. In such circles one tends to know everyone and resources are what they are. A supplier has been around for years so he is trusted. That is fine, but trust should be no substitute for a sensible check. Here I set out the foundational cyber steps for countryside firms that an Australian SME can put in place without having to put together a security operation as big as a road train.

Vendor Connections and the Risk They Pose

person using laptop with security lock

Put simply, any outside organisation tied to your business is another avenue into your data, systems or bank account. Be it a login, a shared mailbox, remote access, an accounting platform or a cloud app.

You will not be able to dictate the internal processes, devices or passwords of every supplier’s staff and that makes supply chain cyber security a thorny issue. But you can make rules on who gets in, for how long and what they are allowed to do, and have a plan for when things go pear-shaped. The official resources from the Australian Cyber Security Centre are a good place to turn for some plain-English direction rather than wading through a 200-page tome that is better suited to collecting dust by the printer.

Don’t Confuse Trust with a Control

It is not that SMEs are wanting to be remiss on security; they have wages to pay and customers to please and suppliers to see to. But a vendor security assessment can be put to one side on the strength of an old relationship.

The error is to think a supplier you know is a safe bet. The contractor may be all right but his email has been compromised, there is an unpatched laptop in use or one of his own suppliers has had a breach.

What Puts the Squeeze on an Australian SME

When it comes to managing vendor risk you are up against limited staff, a budget and perhaps some informal purchasing habits, and the odd supplier whose security programme is not exactly polished. Proportional control is the way to go, not red tape.

Concentrate on those vendors that can do the most damage. An MSP with administrator rights or a SaaS firm with your customer records is a different proposition to a local cleaner who has no system access.

Access is Where the Risk Lies

Vendor type Typical access Main exposure Useful first control
Managed service provider Administrator accounts, backups and remote access Ransomware and a wide-ranging compromise of recovery systems Enforce least privilege and named accounts with logging; have off-site backups you have tested
SaaS provider Cloud applications, documents and the like Service disruption, account takeover, a breach of data Multi-factor authentication and clauses for breach notification
Bookkeeper / accountant Financial records, payroll, invoices Supplier invoice and business email fraud Independent verification of payment and dual approval
Contractor Files, site systems or some temporary remote access Permissions that are forgotten and uncontrolled accounts Offboard immediately and keep access time-limited
Low-access supplier None to speak of Operational disruption, impersonation, phishing A simple register and verify the contact

Do not read too much into the table, it is a guide not a science. Even a minor supplier can cause you no end of trouble if its email is used to ask for a change to your bank details. The size of the logo is irrelevant; risk will take whatever path is open to it.

Cash Can Go Quickly to Invoice Fraud

For an SME this is a very direct form of third-party cyber risk. An attacker will put in a convincing message to say payment details have been altered, or he will get into a supplier’s mailbox and make himself at home.

Business email compromise is effective because the timing is usually right. There is a real project and a genuine invoice and the person in accounts is looking to clear the queue before the day is done. It is the fraudulent bank account that gets past him.

Make Sure Before Parting with Cash

An email is not enough to warrant a change of bank details. Do not use the number provided in the message, but ring back on one you have in your records for the supplier. Have another authorised person look over any new supplier, an urgent transfer or anything out of the ordinary. With large or unanticipated payments, dual approval is worth having. One should not view payment verification as an indication of any suspicion on the part of the supplier, but rather as a routine matter of business. There is an awkwardness to a quick call that is nothing compared with having to put right a missing payment in front of the owner, his staff or the tax office.

Then there is the matter of fraud, which does not forgive. I made the error of giving a group the wrong tide time once; we were wading back over our heads with our gear when it was plain to see. With a fraudulent payment the warning might not show itself until the money is gone. So make a habit of the callback before the tide comes in.

The Case For MSP And SaaS Security

MSPs warrant a closer look at their security. They can be running your email, devices, firewalls, remote access and backups for the entire company. Should an attacker get into an MSP account the consequences can be far reaching.

SaaS presents its own serious risks of a different order. The cloud is where you will have your financials, internal plans, customer information, contracts and identity documents. Even if the provider has good controls in place, one has to be mindful of user accounts, integrations and the like.

Examine Your Attack Surface

Put some questions to your key suppliers: how do they give, monitor and take back access? You want to know if they have multi-factor authentication, distinct administrator accounts, endpoint protection that is up to date, secure backups and procedures for incident response on paper.

Do not extend remote access beyond what is truly necessary. A zero trust approach will not put faith in a connection just because the vendor is known; least privilege will see a technician given no more than he needs to do his job and only for so long.

In a sizeable or spread out operation, Zero Trust Network Access or SASE can put an end to wide open network access in favour of something more controlled and based on identity. But they are not incantations. If the business is not going to be able to keep up with the configuration, a simpler control under watch is preferable.

Proper Supplier Vetting

There is no need to start with an imposing questionnaire for due diligence. Make a list of those who have access to your systems, your data or your money and segment them by impact, reserving the more thorough checks for the high-risk ones.

A register of suppliers ought to have the name of the service and the supplier, the contract dates, offboarding requirements, the data they handle and who in your business is the owner of the relationship. Put it where it can be found; a register languishing in someone’s inbox is hardly a register at all.

Be Proportionate

With a low-risk supplier, note down that he has no system access and check the contact details. With a high-risk one, have them put forward evidence of their security practices, go over their incident process and find out who is on the hook to let you know if there is trouble.

A brief security questionnaire will do for matters such as multi-factor authentication, patching, privileged access, data storage, staff training and breach response. Do not put in questions that are beyond your team to act upon or make sense of. You may as well not have the questionnaire if it is not read.

When it is time to renew a contract, re-evaluate the risk and access. Vendors change their tools and their people. An assessment from three years back could be of a company that is gone.

Contracts That Stand Up

cybersecurity presentation to business leaders

Make the vendor security contract an obligation, not just an expectation. It will not head off every incident but it clarifies where responsibilities lie before a crisis is upon you.

An MSP contract must cover logging, administrator access, recovery assistance, remote support and subcontractors. A SaaS agreement should deal with service availability, deletion, data handling and incident communication.

Your Safety Net In Writing

If an incident is likely to impinge on your data or systems, your breach notification clause should call for it to be made known without delay. State what information is required and the channel for it, as well as the supplier’s part in containment and investigation.

For critical suppliers reserve the right to a reasonable audit or to review the security information. Be explicit about the end of access: once the contract is done, you want tokens revoked, accounts disabled and devices collected, and confirmation that any business data has been returned or put to the delete.

It is tempting to hand permanent admin rights to a contractor for convenience, but that is an open gate. Rely on named accounts, multi-factor and time-limited remote access instead.

An SME Cybersecurity Checklist

We have put together this checklist for the practical needs of Australian SMEs. Go through it with the technology manager, the person in charge of payments and the one with the supplier relationship.

If resources are thin, focus on the five suppliers most likely to do damage. There is more to be gained from securing the front gate than putting the shine on the garden shed with the back door ajar.

Foundational Cyber Steps For Rural Firms

Connectivity can be patchy, teams are small and there are shared devices, travelling contractors and little in the way of specialist support to be had. These are the kind of constraints a rural or regional business will know well. Yet one can still have robust cybersecurity as an Australian small business; it is simply a matter of what one prioritises.

The basics for a countryside firm ought to be staff awareness, controlled administrator access, regular updates, multi-factor authentication and backups that have been put to the test. The Cyber Wardens Program is of assistance to small businesses in developing day to day cyber habits without the need for every member of staff to turn into a security engineer.

Plan Around Real Conditions

In much the same way you would prepare for the Gibb River Road by seeing to the vehicle, fuel, route and recovery options before you set off, so too should your security plan be thought through. You do not want to find the track is flooded and no one can lay hands on the spare key.

Your email, phones, cloud apps, payment systems and remote support tools are your points of access. A recovery plan that has been tested is your way back: protected or offline backups, an emergency contact list and a process to put a compromised account in isolation. As for parking, disable any accounts you are not using, do not let them idle.

Then there is seasonality. In the busy times staff might put an invoice through without a second thought, or with travel disruptions and bushfire closures come a rise in remote access. It is better to review the plan before the season gets under way and the internet is having a lie-down, rather than when everyone is flat out.

There is a wide range of costs. Some basic controls are a question of staff time and the software you already have; but stronger identity systems, an audit or managed monitoring from a specialist vendor will cost. Get a clear scope from the provider and weigh the expense against what is at risk in terms of data, money and systems.

Expectation Versus Reality

It is easy to expect a supplier’s security questionnaire to vouch for a vendor’s safety. In reality it is only evidence for a decision and may not tell the whole story.

You might think cyber insurance is the answer to third-party risk. It can offset some losses but it is no substitute for the likes of access controls, backups, contractual obligations and verifying payments.

Or that a small supplier is no threat. But an exposed remote access account or a password taken from a mailbox can have repercussions for a much larger operation.

Frequently Asked Questions

What Is Third-Party Cyber Risk?

The risk that a technology provider, contractor, MSP or supplier will be the source of harm to your business be it fraud, ransomware, service down time or loss of reputation, by virtue of its people, systems or security lapses.

How Often Should Suppliers Be Reviewed?

At the very least when there is a change in access or systems, or in the course of a contract renewal. After a major ownership change, new subcontractor or material shift in the data being handled, or in the wake of a cyber incident, you should recheck sooner.

Do Small Suppliers Need Security Audits?

Not in every case. One that is low risk and has no system access requires nothing more than contact verification and a record to show it. Where a supplier has influence over payments or privileged access to sensitive data then independent assurance or a targeted audit is warranted.

What Should An SME Ask An MSP?

Find out how they go about revoking access and in what time frame. Also on the subject of their multi-factor authentication, how they segregate customer environments, deal with a cyber incident, keep backups and monitor activity. How do they handle their own administrator accounts and restrict remote access?

Is The Essential Eight Enough For Vendor Risk?

It is a good baseline for an organisation to improve its own security but it will not of itself eliminate third-party risk. Consider it a foundation and not the whole of your supply chain strategy; due diligence on suppliers, safeguards on payments and proper vendor security contracts are still called for.

Make Vendor Risk Manageable

workplace cybersecurity scene

Australian SMEs have to put up with the security challenges that come with relying on outside specialists and cloud platforms. That is the way of modern business. What is avoidable is unverified changes to payments, vague responsibilities on the part of a supplier and access left unchecked.

Put your efforts where the money, data and admin accounts are. Rank and verify those suppliers, put it all on record and once the job is done, take away the access. It is not the sort of work that earns you a trophy but when an account is compromised or a dodgy invoice comes in, it is those unglamorous habits that will see your business carry on.

Dominic Hawthorne
My name’s Dominic Hawthorne, though if you ask around the small towns where I grew up, most people still call me Dom or young Hawthorn. I was born in 1987 in Perth, Western Australia. Mum was a primary school teacher, Dad worked on the mines up in the Pilbara and was away a lot.