When the MOVEit file transfer vulnerability was exploited in 2023, the immediate victims weren't limited to organizations running MOVEit. Thousands of downstream organizations were exposed through Zellis, PBI Research Services, and dozens of other service providers that used MOVEit in their own infrastructure — often without the end customer knowing. Companies that had never heard of MOVEit found their data compromised because a vendor they trusted had introduced the risk on their behalf.
That's fourth-party risk: the security exposure created not by your vendors, but by your vendors' vendors — the subcontractors, technology providers, and service partners that underpin the services you're actually buying.
The Blind Spot in Most VRM Programs
Most vendor risk management programs focus on the vendors you have direct relationships with. You conduct assessments, review SOC 2 reports, send questionnaires. You've evaluated their controls and you know what data they have access to.
What you typically don't know: which subcontractors and technology providers those vendors rely on to deliver their services to you. A managed security services provider may route traffic through a third-party SOC platform. A cloud-based HR system may process payroll through a subprocessor you've never evaluated. A software development firm may use offshore contractors with direct access to your source code.
The gap is real. Most major supply chain incidents in recent years — SolarWinds, Kaseya, MOVEit — propagated damage through the vendor relationship layer, not through attackers directly breaching end-customer environments. Your direct vendor's security controls are only as effective as the weakest link in their own supply chain.
Where Your Exposure Actually Comes From
The fourth-party attack surface varies by vendor type, but the highest-risk categories are predictable:
Technology subprocessors. Cloud services, SaaS platforms, and managed services almost always depend on underlying infrastructure from AWS, Azure, or GCP — a shared-responsibility model you can account for. The less obvious exposure is application-layer subprocessors: analytics platforms, payment processors, identity providers, and logging services that the vendor has integrated into their stack and that may have access to data you sent to the vendor.
Subcontractors and staffing. Consulting firms, managed service providers, and development shops frequently use subcontractors — sometimes offshore — with direct access to client environments or data. The question isn't whether your vendor has contractors; most do. The question is what security requirements your vendor applies to those contractors and how their access is managed.
Shared utilities and software components. The software supply chain incidents of recent years demonstrated that widely-deployed libraries and build tools create concentrated risk. When a vulnerability hits a heavily-used component, the blast radius touches every organization that depends on it through their vendor chain.
Practical Steps to Manage the Exposure
You can't audit your vendors' vendors the way you audit your vendors. The leverage point is your vendor relationship itself.
Require subprocessor transparency. Your vendor contracts should require disclosure of material subprocessors and subcontractors with access to your data or systems. At a minimum, you should know who they are. Data processing agreements under GDPR and CCPA already require this for personal data processors — apply the same standard to your operational vendors.
Flow down security requirements. If you require Tier 1 vendors to maintain SOC 2, apply MFA on all accounts, and patch critical vulnerabilities within a defined window, those requirements should flow down to the subcontractors your vendors rely on for your services. Your vendor contracts should include explicit flow-down language.
Ask vendors about their own VRM program. When assessing a critical vendor, ask directly: how do you manage fourth-party risk? What security requirements do you apply to your subprocessors? Have you had a material incident through a subcontractor in the past 24 months? Organizations with mature programs have specific answers. Those without them often can't answer at all — which is itself meaningful signal.
Use continuous monitoring for supply chain visibility. Security ratings platforms — BitSight, SecurityScorecard, UpGuard — can flag when vendors in your portfolio show connections to known-compromised infrastructure, operate subprocessors with poor security postures, or appear in breach notifications. This provides ongoing visibility without requiring manual assessment at each layer.
Right-Sizing This for a Mid-Market Team
You can't manage fourth-party risk comprehensively across every vendor relationship. You can manage it for the ones that matter most.
For Tier 1 vendors — those with access to sensitive data, critical systems, or who are deeply embedded in your operations — the investment is justified. Require subprocessor disclosure in contracts, include flow-down requirements, and build fourth-party due diligence into your annual assessment cycle.
For Tier 2 vendors, a lighter approach works: standard contractual language requiring downstream security requirements, combined with continuous monitoring alerts if a vendor surfaces in breach news.
The goal isn't comprehensive visibility into every subprocessor relationship in your supply chain. It's enough visibility into your highest-risk vendor relationships that you can respond quickly when a breach in their supply chain becomes your problem — rather than discovering it from a news alert.
Ready to build a vendor risk program that accounts for supply chain exposure? Schedule a free consultation with ProTechtive — we'll identify where your real fourth-party risk sits and build a proportionate program to manage it.