Three Risks. One Blind Spot.
Read on below for Edition 8 of 3VRM’s cyber briefing newsletter.
Three items caught our attention this month. A phishing wave that slips past email filtering, a breach at Ernst & Young involving a third-party support platform, and new guidance from the Australian Signals Directorate on post-quantum readiness.
On the face of it they have very little in common. One is an identity problem, one is a data problem, and one concerns cryptography that will not be broken for years yet.
Look closer and the same question sits underneath all three. Do you actually know where your dependencies sit?
Cyber security
New ghost phishing wave is breaking traditional email security
This is another example of phishing techniques evolving faster than traditional email filtering controls.
By using encrypted HTML content and Microsoft device code authentication processes, attackers can conceal malicious content until it reaches the user’s device, reducing the effectiveness of secure email gateways and traditional scanning technologies.
Our 3VRM insight: A recurring theme across recent phishing campaigns is the shift away from malware delivery and towards identity compromise. Organisations that rely heavily on email filtering alone are increasingly vulnerable. Strong multi-factor authentication, user awareness, and monitoring of unusual authentication activity are becoming far more important than signature-based email controls.
TPRM impact: Suppliers with access to corporate systems or Microsoft 365 environments should demonstrate effective controls against identity-based attacks and account takeover risks. This may include phishing-resistant multi-factor authentication, conditional access controls, and monitoring of authentication anomalies within privileged accounts.
Data privacy
Ernst & Young investigates data breach involving third-party support tickets
The reported breach involved a third-party support platform containing customer documentation and other potentially sensitive information. Attention often focuses on production systems, but support and ticketing platforms frequently contain large volumes of business, customer and operational data.
Our 3VRM insight: Support platforms are often overlooked during supplier assessments because they are viewed as administrative tooling rather than critical business systems. In practice they can contain privileged information, attachments, troubleshooting records, customer communications and personal data. Organisations should treat these platforms in the same way they would any other high-value information asset.
TPRM impact: Supplier assessments should consider support platform security, access controls, attachment handling, logging, retention practices and breach notification requirements. Where suppliers use outsourced support providers, organisations should understand what data is accessible and how it is protected throughout the support chain.
Resilience
Australian Signals Directorate: post-quantum questions to ask your vendors
The Australian Signals Directorate recently released a guidance document, as quantum computing is an area likely to become increasingly relevant for assurance activities over the next twelve months. The document provides practical questions organisations can use to assess supplier readiness for the transition to post-quantum cryptography.
Our 3VRM insight: Large-scale quantum computing remains some way off, but supplier readiness is becoming a genuine assurance consideration rather than a theoretical discussion. Many organisations do not currently know where cryptography is used within their own technology estate, let alone within their supply chain.
The most useful aspect of the guidance is its focus on understanding cryptographic dependencies, identifying hardware limitations, and obtaining realistic transition plans from suppliers.
Organisations should begin asking critical suppliers whether they maintain a Cryptographic Bill of Materials, understand where cryptography is embedded within their products and services, and have a documented roadmap for adopting post-quantum cryptographic standards.
TPRM impact: This is a strong candidate for future questionnaire enhancements. Assessment areas could include Cryptographic Bills of Materials, hardware-bound cryptography, post-quantum transition roadmaps, governance accountability, and plans for retiring legacy cryptographic standards. Suppliers unable to articulate their approach may present long-term resilience concerns.
Why should TPRM professionals care?
The common theme across all three items is supplier visibility. Whether assessing identity security, support platforms or future cryptographic readiness, organisations increasingly need to understand not just whether controls exist, but where dependencies sit within the wider supply chain.
From a TPRM perspective, three areas stand out:
- Identity security and resilience against account compromise
- Security of supplier-managed SaaS and support platforms
- Supplier preparedness for emerging technology risks, including post-quantum cryptography
These are all areas where assurance teams can, and should be, adding value through proportionate questioning.
Read the full article here.