Supply Chain Attacks: How Your Vendors Become Your Biggest Risk
The most devastating attacks in recent years came through trusted vendors. Learn how to assess and mitigate your digital supply chain risk.
The weakest link isn't inside your company
In December 2020, the SolarWinds attack — documented publicly by CISA and several US federal agencies — compromised thousands of organizations worldwide, including US government agencies and Fortune 500 companies. The attack vector wasn't a phishing email or a weak password: it was a legitimate software update from a monitoring tool that organizations trusted.
In 2021, the Kaseya attack (documented by CISA in alert AA21-183A) hit hundreds of businesses through a remote management vendor. In 2023, the MOVEit attack exposed data from multiple organizations through a vulnerability in a file transfer application (documented by CISA in a same-year advisory).
The pattern is clear: attackers no longer target their victim directly. They target the victim's vendor. And this applies to SMBs just as much as enterprises.
How a vendor becomes an attack vector
Scenario 1: Your IT provider
Your IT support provider has admin credentials in your Microsoft 365 tenant. If the provider is compromised, the attacker has direct access to your data with maximum privileges. This is exactly what happened in the Kaseya MSP (Managed Service Provider) attack.
Scenario 2: Software you use
You install a third-party app in Microsoft Teams or use an Outlook add-in. That software has access to your tenant data. If the software developer is compromised, the next update could include malicious code that silently exfiltrates your data.
Scenario 3: A vendor with network access
Your security camera, HVAC, or printer vendor has access to your network for remote maintenance. Those IoT devices rarely have the same security as your servers. The 2013 Target breach — which exposed 40 million credit card numbers — started through an HVAC vendor.
Scenario 4: Your payroll or accounting provider
Your accountant or payroll service has access to financial and personal data of all your employees. If their system is compromised, the leaked data is yours.
Assessing your supply chain risk
Step 1: Third-party access inventory
List all vendors that have:
- Login credentials to your systems
- Apps installed in your Microsoft 365
- Remote access to your network
- Sensitive data about your company or employees
Most SMBs discover they have 15-30 vendors with some level of access they never cataloged.
Step 2: Risk classification
Classify each vendor by:
- Access level: M365 admin? Network access? Data only?
- Data exposure: Does it hold client data? Financial data? Employee data?
- Operational dependency: If this vendor fails, does your business stop?
Step 3: Vendor security assessment
For high-risk vendors, request evidence of:
- Certifications (ISO 27001, SOC 2)
- Vulnerability management process
- Security training for their employees
- Incident response plan
- Cyber insurance
Step 4: Technical controls
Implement controls that limit damage if a vendor is compromised:
- Separate vendor accounts — never share employee credentials with vendors. Create specific accounts with minimum permissions.
- Just-in-time access — the vendor only has access when needed, not 24/7.
- Activity monitoring — audit what vendor accounts do in your tenant.
- Third-party app review — quarterly review what third-party apps have access to your Microsoft 365 and revoke ones no longer in use.
How Microsoft 365 helps (and how it can expose you)
Helps:
- Azure AD app consent policies — control which third-party apps can access your tenant
- Conditional Access for vendors — create policies specific to external accounts
- Unified audit log — records everything vendor accounts do
- Admin consent workflow — requires IT approval for new app installations
Exposes:
- Default guest access — Azure AD guests can see more than you think if you don't limit permissions
- OAuth consent phishing — an attacker can create a fake app that requests email read permissions, and an employee approves it without reading
- Delegated admin privileges — many MSPs have GDAP/DAP privileges giving them unrestricted access to the client tenant
First step: visibility
You can't protect what you can't see. Our free scan evaluates the 155 Microsoft Graph rules of the 201-rule library, including third-party apps with tenant access, active guest accounts, delegated permissions, and app consent configuration. In 90 seconds you have a map of your supply chain attack surface. The 46 Azure Resource Manager controls add on with admin consent.
Is your business protected?
A free Microsoft 365 audit—the automated scan delivers a preview in 90 seconds. Find risks before they become incidents.