Third-Party Risk Management: When Behaviour Shapes Resilience

Part 2: The human dynamics behind third-party incident response.

In Part 1 of this series, we explored the human behaviours that contribute to persistent third-party risk exposure, from misplaced trust and compliance fatigue to commercial pressure and organisational silos.

However, these behavioural dynamics become even more visible during real-world disruption.

Whether caused by a cyber-attack, operational outage, supplier compromise, or systemic failure, incidents involving critical third parties rarely fail solely because of technology. More often, the severity of disruption is shaped by how organisations respond under pressure.

This is where operational resilience moves beyond governance frameworks and becomes a test of communication, decision-making, leadership, and preparedness.

The illusion of preparedness

Many organisations believe they are resilient because governance structures exist on paper. Supplier due diligence has been completed, risk assessments are documented, and contractual obligations are in place.

But disruption often reveals a different reality.

Third-party incident response plans may never have been exercised collaboratively. Escalation processes can become unclear during fast-moving incidents, and organisations frequently discover that their operational dependency on suppliers is deeper than initially understood.

In some cases, suppliers that appear compliant from an assurance perspective may still struggle operationally when under pressure. The challenge is that preparedness is often assessed through documentation rather than demonstrated capability.

The Jaguar Land Rover (JLR) incident is one example of how a supplier can look secure on paper yet still expose an organisation to enormous risk. Although JLR’s suppliers appeared fully compliant by meeting standards and providing assurance supported by documented evidence, a cyberattack on one upstream partner in September 2025 resulted in a knock-on failure across JLR’s global manufacturing network. Production ground to a halt in the UK, Slovakia, India, and Brazil for weeks, ultimately costing the company an estimated £1.9 billion ($2.5B) and forcing layoffs throughout the supply chain. 

Behaviour changes under pressure

When disruption occurs, organisational behaviour changes rapidly.

Decision-making can slow down as teams seek additional approvals or avoid accountability. Commercial concerns may influence disclosure timelines, while reputational pressures can create hesitation around transparency.

At the same time, internal priorities often compete:

  • Security teams focus on containment
  • Operations teams prioritise service restoration
  • Legal teams assess liability exposure
  • Executive leadership manages customer and regulatory pressure

Without alignment, even relatively manageable incidents can escalate unnecessarily.

Importantly, these behavioural responses are rarely intentional failures. They are natural reactions to uncertainty, pressure, and incomplete information.

An effective approach for managing stakeholders starts with clear, consistent communication that provides information in the form that they have requested and expect. When stakeholders understand why something matters, not just what is happening, there is a greater chance they will feel included in the conversation. Trust is built by doing exactly what you say you will do, doing it as you said you would, and being transparent about risks and constraints rather than hiding them. Buy‑in comes when stakeholders feel heard, see their input reflected in decisions, and understand how the outcome aligns with their objectives and the organisation’s goals.

Communication often becomes the real failure point

One of the most common challenges during third-party incidents is not the initial disruption itself but the communication breakdown that follows.

Organisations may receive inconsistent updates from suppliers, unclear recovery timelines, or limited visibility into root causes. Internally, fragmented communication between risk, legal, IT, and leadership teams can further delay coordinated response efforts. For customers, regulators, and stakeholders, uncertainty can quickly erode trust. This becomes particularly challenging in highly interconnected environments where a single supplier outage can affect multiple business functions simultaneously.

The effectiveness of communication during disruption often determines whether an incident becomes a contained operational event or a broader reputational crisis.

An effective way to communicate with stakeholders is to use a simple, structured model that clearly lays out the opportunities, consequences, and available choices. Industry standards often require a comprehensive communication plan that outlines what will be communicated, how often, through which channels, to whom, and for what purpose. Organisations may also use a Benefits-Risks-Choices Model to a similar effect. By framing information this way, you help stakeholders see both the upside and the risks without overwhelming them with detail. It turns communication into a shared decision‑making process rather than a one‑way update, which is ultimately what drives alignment and long‑term support.

Operational dependency is often underestimated

Many organisations do not fully understand the extent of their dependency on third parties until services become unavailable.

Modern businesses rely heavily on interconnected suppliers, cloud providers, managed service partners, and outsourced operations. In many cases, these dependencies extend beyond direct suppliers into fourth-party ecosystems that organisations have limited visibility over. During disruption, this hidden criticality becomes highly visible. An outage affecting a single provider can quickly disrupt operations, customer service, regulatory obligations, and revenue.

The challenge is not simply identifying suppliers; it is understanding how operational resilience is affected when those suppliers fail.

Compliance alone does not create resilience

Regulatory frameworks such as DORA and NIS2, as well as operational resilience requirements, are increasing expectations for third-party risk management. However, compliance alone does not guarantee resilience.

Organisations can meet regulatory obligations while still lacking effective coordination, tested response capabilities, or clear accountability structures during incidents.

True resilience requires organisations to move beyond static assessments and towards continuous operational validation. This includes:

  • Joint resilience exercises with critical suppliers
  • Cross-functional crisis simulations
  • Clear escalation pathways
  • Executive involvement in incident preparedness
  • Ongoing reassessment of operational dependency

Resilience is ultimately built through practice, collaboration, and organisational maturity, not documentation alone.

More resilient third-party relationships

Improving resilience requires more than stronger controls. It requires stronger relationships.

Organisations that respond most effectively during disruption are often those that have already established trust, communication pathways, and shared expectations with critical suppliers before incidents occur.

This involves creating environments where issues can be escalated early, dependencies are openly understood, and resilience is treated as a shared responsibility rather than a contractual obligation.

As third-party ecosystems continue to grow in complexity, resilience will increasingly depend on how organisations collaborate under pressure – not simply how they govern during stability.

Meet Our Leadership Team.

At CRMG, our senior leadership team brings a rich history and deep expertise in cyber security. Spearheaded by consultants who are influential figures in the industry, our leaders are highly networked and well-established, with backgrounds in the ‘Big- Four’ firms.

LEARN MORE

Simon Rycroft

CO-FOUNDER AND CEO

Former Head of Consulting at the ISF. On a journey to bring accessible risk management to growing enterprises.

Nick Frost

CO-FOUNDER AND CHIEF PRODUCT OFFICER

Former Group Head of Information Risk, PwC. Motivated by the need to implement cyber risk principles for the real world!

Dan Rycroft

DELIVERY DIRECTOR

Former Head of Delivery, Cyber Security at DXC. Delivers risk-based cyber security programmes with maximum efficiency.

Matt Brett

DELIVERY LEAD – CYBER RISK SOLUTIONS

Former Portfolio Director, Tech Security & Risk, GSK. Specialises in implementing efficient, pragmatic cyber risk solutions.

Martin Tully

DELIVERY LEAD – GOVERNANCE AND COMPLIANCE

Twenty years’ experience in delivering fit-for-purpose cyber governance initiatives.

Ryan Hides

DELIVERY LEAD – THIRD PARTY RISK MANAGEMENT

Project Management and Six Sigma expertise. Specialises in turning effective third party risk management into a scalable reality.

Sarrah Ahmed

HEAD OF MARKETING

Bringing over 17+ years of marketing expertise, passionate about crafting innovative marketing campaigns.

Tom Everard

Director Risk Services

Director of Risk Services with a passion for people-focused cyber security, crisis management, and tackling insider risk.

Rebecca Stanley

Finance Manager

Focussed on ensuring everything continues to run smoothly, Rebecca collaborates across teams and with clients to manage budgets, reporting, and all things finance.

Securing What Matters Most: A Practitioner’s View

Most organisations are doing plenty of cybersecurity. The bigger question is whether they’re securing the right things. As regulatory expectations shift towards demonstrable, risk-based decision-making, understanding what matters most to the business has never been more important.

The Fundamentals Haven’t Changed – The Context Has

I’ve been having versions of this conversation in security for the 25 years I’ve worked in cyber (or what was IT security when I first started in this area), and parts of it will sound familiar. The fundamentals haven’t changed much. What has changed is the context around them, and for me, that’s worth paying attention to.

We still must comply with regulations, standards, and control frameworks, and that isn’t going away, but there’s diminishing value in aligning with controls purely for the sake of compliance, which is something we’ve been pointing out for years, even as we struggle to break away from the well-trodden approach we’ve followed for decades. Regulators, boards, and customers now expect more: evidence of a risk-based approach. They want to see that we know which parts of the business are most critical (ie your minimal viable organisation), what could disrupt them (threat and risk scenarios), and how we’re prioritising security and resilience activity accordingly.

Why Is This Still So Difficult?

That’s the right direction, and we all agree, but it’s hard to do in practice. Why? Because most security functions are still consumed by day-to-day activity, stretched resources and competing priorities. And too often we lack a clear line of sight between what the team is doing and the business processes, services, assets and dependencies that matter most. From my perspective, without that line of sight, risk assessments, penetration testing, control reviews, etc., become too generic, lack strong direction and purpose, or, even worse, focus on areas of the business that just aren’t that critical and may benefit from applying baseline controls.

Cyber Risk Doesn’t Exist in Isolation…

It’s made harder by the fact that cyber risk rarely exists in isolation. The risks we deal with now are hybrid and cut across cyber, technology risk, operational resilience, physical security, third-party management, enterprise risk, compliance, and audit, and yet, many of these functions still report vertically, with little lateral sharing. That makes it genuinely difficult to build a joined-up picture of what’s truly critical, how it’s protected, where the dependencies run, and where we’re most exposed.

The uncomfortable truth is that no one can secure everything to the same standard. So, prioritisation isn’t optional; it’s our job to perform. Yet our assurance effort often follows the wrong triggers. A new application attracts a risk assessment, a pen test, or a code review simply because it’s new, while a mission-critical system that’s underpinned the business for a decade hasn’t been tested in years. The result is a mismatch between where we point assurance and where the real exposure lives.

Start with What Matters Most

The place to start is by identifying the business’s nucleus: the critical services, processes, data, systems, people, and third-party dependencies that must be protected and kept running at all costs. This requires discussion, challenge, and consensus across business, technology, risk, and resilience teams. It won’t be perfect the first time, but skipping it because it’s hard leaves us with no defensible basis for prioritisation at all.

Once we understand what’s most critical, risk assessment starts to earn its keep. The point isn’t to generate another risk register; it’s to work out what could realistically go wrong, how likely it is, what it would cost the business, and which controls we need to prevent, detect, and respond. That’s what connects business criticality to threat exposure, control effectiveness and remediation priorities.

It also gives us a far stronger story to tell regulators, boards, and auditors, which broadly follows a clear line from what matters most to the business, through the risks we’ve identified, to the controls we’ve put in place and the investment we’ve chosen to make. It’s the difference between security as a broad compliance exercise and security as focused business protection.

The Goal

This must ultimately be our goal now in cybersecurity: a cybersecurity programme that’s more practical, more connected, and more targeted. One that’s built around understanding what the business genuinely cannot afford to lose, how those critical services and assets are exposed, and where our time, effort and investment will have the greatest impact. That means moving beyond security activities driven primarily by compliance schedules or technology change and instead focusing assurance where it matters most.

We’ll never have unlimited resources, nor will we ever eliminate every risk. But by establishing a clear line of sight between business criticality, credible threat scenarios and the controls that protect them, we can make better decisions, justify investment more effectively and build resilience where it counts.

This is what good cybersecurity should be about: not trying to secure everything equally, but making informed, defensible decisions that protect what matters most to the organisation.

 

Third-Party Risk Management: The Human Behaviours Behind Persistent Exposure

While third-party risk management frequently appears robust in governance forums, ongoing exposure suggests a more complex reality. This article explores human behaviours that influence the practical management of third-party cyber risk beyond the intentions of formal frameworks.

Third-party risk management (TPRM) is now a well-established discipline within cybersecurity and GRC. Most organisations can demonstrate defined processes, contractual controls, and assurance mechanisms to manage supplier risk, but many still struggle to effectively implement these measures, leaving vulnerabilities that third parties can exploit. Regulatory expectations have further reinforced the need for formal oversight of third parties, particularly in ensuring compliance with data protection laws and industry standards.

Yet incidents involving third parties remain a persistent threat. This suggests the challenge extends beyond framework maturity or technological capability. Human behaviour, organisational culture, and commercial pressures significantly influence the effectiveness of TPRM in practice, shaping the assessment and resolution of risks.

This two-part series explores behavioural dynamics that frequently undermine third-party cyber risk management practices.

The pressure to appear ‘secure’

Third parties operate in competitive environments where demonstrating security maturity has become a commercial necessity. Suppliers therefore face implicit pressure to present themselves as operationally robust, even when controls may still be evolving or inconsistently applied.

As a result, self-assessment questionnaires and maturity declarations can sometimes reflect aspirational practices rather than actual control effectiveness. Cultural factors reinforce this dynamic when internal teams feel compelled to align responses with contractual commitments or service-level agreements (SLAs).

The organisations issuing these questionnaires typically do so in a standardised format designed to streamline the process, recognising they may not have the capacity to review large volumes of supporting evidence or conduct detailed follow-ups with every supplier.

Consequently, customer organisations often rely heavily on declared security postures unless assurance processes include operational validation along with documentation.

Third-party providers may also feel pressure to avoid disclosing operational weaknesses, particularly when doing so could threaten contractual relationships. Without evidence-based validation or contractual audit rights, responses to control-maturity questionnaires may present an overly optimistic view of the security posture.

Ransomware and asymmetric exposure in third-party relationships

Ransomware has become the dominant third-party cyber risk scenario for many organisations. Suppliers often serve as a more accessible point of compromise, particularly when security investment and maturity differ significantly between the customer and the provider.

Compromising a single supplier can also provide attackers with access to multiple client environments, creating the potential for widespread disruptions or simultaneous extortion across several organisations.

The challenge is not purely technical. Cultural and behavioural dynamics also play a part. Suppliers may hesitate to disclose emerging threats or early-stage incidents due to concerns about reputational harm, commercial repercussions, or contractual penalties. At the same time, customer organisations may implicitly expect suppliers to resolve issues independently until escalation becomes unavoidable.

This dynamic discourages early transparency, even though earlier collaboration could significantly reduce the impact of incidents.

In practice, ransomware exposure in third-party relationships can manifest in several ways: service outages, attackers pivoting through trusted connections, weak recovery capabilities, or delayed incident disclosure driven by fear of contractual consequences.

Encouraging more open information sharing requires organisations to move beyond purely compliance-driven oversight to shared risk ownership. Maturity-based assessments, collaborative exercises, shared threat intelligence, and environments that encourage early disclosure all contribute to stronger relationships and greater resilience.

Criticality, certification and misplaced assurance

Tiering suppliers by criticality is a common feature of mature TPRM programmes. Certifications and third-party attestations are frequently used as indicators of security maturity within these tiers.

However, certifications are ultimately interpreted and implemented by individuals. The presence of a recognised standard can therefore create a sense of assurance that does not always reflect the real risk associated with a specific service, environment, or delivery model. Over time, this can lead to reduced scrutiny of suppliers whose formal credentials appear strong, even when operational exposure remains significant.

A graduated approach to attestation enables suppliers to provide assurance proportional to their criticality. Subsequently, high-impact suppliers must demonstrate stronger control maturity and provide more substantial supporting evidence, while lower-criticality suppliers are subject to proportionately lighter assurance requirements. This tiered approach aligns oversight with risk while avoiding unnecessary burden on smaller vendors.

Relationships, legacy, and reduced scrutiny

Long-standing supplier relationships, particularly those supported by strong personal connections at senior levels, often benefit from a degree of trust not afforded to newer providers. Over time, this trust can reduce the frequency or depth of security scrutiny.

This rarely reflects deliberate negligence. Instead, it demonstrates how human relationships influence organisational behaviour. Although governance frameworks may mandate consistent oversight, in practice, scrutiny is seldom applied uniformly across all suppliers.

Legacy contracts can further increase exposure. Many were written before today’s cyber, operational, and regulatory expectations existed and therefore lack modern security clauses, clear incident-reporting requirements, defined recovery obligations, or meaningful audit rights. These gaps can leave organisations with limited leverage during an incident.

A clear example occurred in mid-2023 when a zero-day vulnerability in MOVEit Transfer, a widely used secure file-transfer product, was exploited by the Clop ransomware group. Attackers breached servers operated by hundreds of service providers, exposing sensitive data belonging to thousands of organisations that had no direct relationship with the compromised software.

“The greatest enemy of knowledge is not ignorance, it is the illusion of knowledge.” — Daniel J. Boorstin.

The continued presence of third-party cyber risk does not necessarily indicate that frameworks are ineffective. Instead, it highlights how behavioural dynamics and organisational incentives shape how those frameworks operate in practice.

Many of the most significant drivers of exposure sit outside formal processes and control structures. For boards and senior leaders, it is essential to recognise that human behaviour fundamentally shapes the effectiveness of third-party risk management.

Part 2 will explore how these behavioural dynamics influence real-world resilience when critical third parties experience cyber incidents or operational disruptions.