Third-Party & Supply Chain Exposure

The Questionnaire Came Back Clean.So did theirs.

Questionnaires record what a supplier says about itself, on the day they filled it in. We assess what your suppliers actually expose — without their cooperation.

5.7MQantas customers exposed — via a third party
#2 gapAPRA’s finding: weak third-party security assessment
MSP breachASD: provider compromise reached their customers
CPS 234Extends to every third party holding your data

Passive only — no systems, networks or accounts are accessed at any point.

Attestation Is Not Evidence

The standard approach to third-party cyber risk in Australia is a questionnaire. It has three structural weaknesses, and all three were on display through 2026.

It records intent, on one day

A questionnaire captures what a supplier believes about itself at the moment of completion. Environments change weekly. Certificates expire. Staging environments appear. A clean questionnaire from March says nothing about August.

It is self-assessed by the party with the incentive

The respondent is the organisation being assessed, answering questions whose answers determine whether they win or keep your business. This is not an accusation of dishonesty. It is an observation about who holds the pen.

It stops at the first tier

Your supplier’s suppliers hold your data too. Fourth-party exposure is invisible to a questionnaire and entirely visible from outside, because certificates, hostnames and email infrastructure disclose relationships that contracts never mention.

What 2026 Actually Showed

The year’s most consequential incidents did not begin at the perimeter of the organisation that ended up in the headline. They began at a supplier, a contractor, or a third-party platform holding standing access.

A third-party contact centre platform. A file storage system holding archived records. Managed service provider control panels leading to the compromise of their customers. In each case the affected organisation had a contract, and in most cases a questionnaire.

The regulatory position is unambiguousCPS 234 extends to information assets managed by related parties and third parties. CPS 230 requires management of the risks associated with service providers on which an entity materially relies. The Privacy Act does not transfer APP 11 obligations with the outsourcing. Where a supplier holds your data, their exposure is your regulatory problem.

What a Third-Party Assessment Covers

  • External attack surface per supplier — hostnames, subdomains, exposed services and administrative interfaces, drawn from certificate transparency and passive DNS
  • Technology and version fingerprinting against published vulnerability data, triaged by confirmed exploitation status rather than severity alone
  • Credential exposure where the supplier’s staff identities appear in published breach and infostealer corpora — frequently the finding that changes the conversation
  • Email authentication posture, which determines whether a supplier’s domain can be spoofed in an invoice fraud or business email compromise attempt against you
  • Fourth-party relationships disclosed by certificates, hostnames and mail infrastructure
  • Comparative scoring across the assessed supplier set, so the conversation moves from “are they secure” to “which three do we address first”

Findings are mapped to CPS 234, CPS 230, SOCI and the Australian Privacy Principles as applicable to your obligations.

Passive Only — No Systems AccessedEvery BlackFlag Advisory assessment uses exclusively passive OSINT techniques against publicly available sources. No systems, networks or accounts are accessed, probed or tested at any point. No authorisation to test is required, and nothing we do can disrupt your operations.

Because the assessment is passive and uses only public data, no supplier cooperation is required and no supplier need be told in advance. Many clients use the output to open a better-informed conversation with a vendor rather than to end one.

Who This Is For

APRA-regulated entities under CPS 230

Where you must manage risks associated with service providers on which you materially rely, and evidence that management.

Critical infrastructure operators

Where SOCI obligations extend to supply chain risk within a risk management programme.

Organisations running a vendor due diligence process

Where questionnaires come back clean and nobody can say whether that reflects reality.

Anyone who has just onboarded a supplier

The cheapest moment to assess a vendor is before the contract is signed, and the second cheapest is now.

How the Engagement Runs

Five steps. The only one that requires your time is the first and the last.

1. Scope

We agree the domains, entities or suppliers in scope and the frameworks the findings should be mapped to. Nothing else is required from you — no access, no credentials, no questionnaire to complete.

2. Passive collection

We observe what your organisation exposes using publicly available sources: certificate transparency logs, passive DNS, published vulnerability data, and public breach and infostealer corpora. No systems, networks or accounts are accessed, probed or tested at any point.

3. Analysis and triage

Findings are validated, deduplicated and prioritised against confirmed exploitation status, exploitation probability and asset exposure — not by severity score alone. Every finding carries the evidence that produced it.

4. Regulatory mapping

Each finding is mapped to the obligation it engages, so the report speaks in the language your Board, auditor, insurer or regulator already uses.

5. Delivery and walkthrough

A dual-audience report: a Board section stating the position in plain terms, and a technical section carrying reproducible evidence. We walk you through it, and we are available for the remediation questions that follow.

Frequently Asked Questions

The questions we are asked most often about assessing suppliers without their involvement.

Do you need our vendor’s permission?

No. The assessment observes only what a vendor publishes to the public internet — domains, certificates, exposed services, email authentication posture, and credentials appearing in published breach corpora. No systems, networks or accounts are accessed, probed or tested, so no authorisation from the vendor is required.

How is this different from a vendor security questionnaire?

A questionnaire records what a supplier says about itself, self-assessed, on the date it was completed. An external assessment records what is observably true on the day it is run. The two frequently disagree, and the gap between them is the finding.

Does this help with CPS 230?

CPS 230 requires an APRA-regulated entity to manage the risks associated with service providers on which it materially relies, including assessing whether a provider can deliver critical operations to the required standard. Independent evidence of a provider’s external security posture supports that assessment. It does not replace contractual or operational due diligence.

How many suppliers can be assessed?

Scope is set by engagement. A common approach is to assess the suppliers with access to your most sensitive information or your critical operations first, then extend. Scopes and packages are set out on the assessment packages page.

Scopes and packages are on the assessment packages page, or book a short call to discuss your supplier set.

You Cannot Audit Every Supplier.
You Can Observe Them.

A BlackFlag Advisory assessment gives your Board an independent, evidenced view of what your third-party providers expose — before an incident makes it an urgent question.

Request an Assessment →
Assessments
AI Governance CPS 234 Essential Eight Privacy Act & APP 11 Third-Party Risk Tranche 2 Cyber Which one do I need? →
Intelligence
All briefings Romania land registry Tranche 2 commenced ASD advisories, 2026
Practice
GRC Partnerships Pricing Privacy
Start
Threat Scan Enquire Sample report