Attestation Is Not Evidence
The standard approach to third-party cyber risk in Australia is a questionnaire. It has three structural weaknesses, and all three were on display through 2026.
It records intent, on one day
A questionnaire captures what a supplier believes about itself at the moment of completion. Environments change weekly. Certificates expire. Staging environments appear. A clean questionnaire from March says nothing about August.
It is self-assessed by the party with the incentive
The respondent is the organisation being assessed, answering questions whose answers determine whether they win or keep your business. This is not an accusation of dishonesty. It is an observation about who holds the pen.
It stops at the first tier
Your supplier’s suppliers hold your data too. Fourth-party exposure is invisible to a questionnaire and entirely visible from outside, because certificates, hostnames and email infrastructure disclose relationships that contracts never mention.
What 2026 Actually Showed
The year’s most consequential incidents did not begin at the perimeter of the organisation that ended up in the headline. They began at a supplier, a contractor, or a third-party platform holding standing access.
A third-party contact centre platform. A file storage system holding archived records. Managed service provider control panels leading to the compromise of their customers. In each case the affected organisation had a contract, and in most cases a questionnaire.
What a Third-Party Assessment Covers
- External attack surface per supplier — hostnames, subdomains, exposed services and administrative interfaces, drawn from certificate transparency and passive DNS
- Technology and version fingerprinting against published vulnerability data, triaged by confirmed exploitation status rather than severity alone
- Credential exposure where the supplier’s staff identities appear in published breach and infostealer corpora — frequently the finding that changes the conversation
- Email authentication posture, which determines whether a supplier’s domain can be spoofed in an invoice fraud or business email compromise attempt against you
- Fourth-party relationships disclosed by certificates, hostnames and mail infrastructure
- Comparative scoring across the assessed supplier set, so the conversation moves from “are they secure” to “which three do we address first”
Findings are mapped to CPS 234, CPS 230, SOCI and the Australian Privacy Principles as applicable to your obligations.
Because the assessment is passive and uses only public data, no supplier cooperation is required and no supplier need be told in advance. Many clients use the output to open a better-informed conversation with a vendor rather than to end one.
Who This Is For
APRA-regulated entities under CPS 230
Where you must manage risks associated with service providers on which you materially rely, and evidence that management.
Critical infrastructure operators
Where SOCI obligations extend to supply chain risk within a risk management programme.
Organisations running a vendor due diligence process
Where questionnaires come back clean and nobody can say whether that reflects reality.
Anyone who has just onboarded a supplier
The cheapest moment to assess a vendor is before the contract is signed, and the second cheapest is now.
How the Engagement Runs
Five steps. The only one that requires your time is the first and the last.
1. Scope
We agree the domains, entities or suppliers in scope and the frameworks the findings should be mapped to. Nothing else is required from you — no access, no credentials, no questionnaire to complete.
2. Passive collection
We observe what your organisation exposes using publicly available sources: certificate transparency logs, passive DNS, published vulnerability data, and public breach and infostealer corpora. No systems, networks or accounts are accessed, probed or tested at any point.
3. Analysis and triage
Findings are validated, deduplicated and prioritised against confirmed exploitation status, exploitation probability and asset exposure — not by severity score alone. Every finding carries the evidence that produced it.
4. Regulatory mapping
Each finding is mapped to the obligation it engages, so the report speaks in the language your Board, auditor, insurer or regulator already uses.
5. Delivery and walkthrough
A dual-audience report: a Board section stating the position in plain terms, and a technical section carrying reproducible evidence. We walk you through it, and we are available for the remediation questions that follow.
Frequently Asked Questions
The questions we are asked most often about assessing suppliers without their involvement.
Do you need our vendor’s permission?
No. The assessment observes only what a vendor publishes to the public internet — domains, certificates, exposed services, email authentication posture, and credentials appearing in published breach corpora. No systems, networks or accounts are accessed, probed or tested, so no authorisation from the vendor is required.
How is this different from a vendor security questionnaire?
A questionnaire records what a supplier says about itself, self-assessed, on the date it was completed. An external assessment records what is observably true on the day it is run. The two frequently disagree, and the gap between them is the finding.
Does this help with CPS 230?
CPS 230 requires an APRA-regulated entity to manage the risks associated with service providers on which it materially relies, including assessing whether a provider can deliver critical operations to the required standard. Independent evidence of a provider’s external security posture supports that assessment. It does not replace contractual or operational due diligence.
How many suppliers can be assessed?
Scope is set by engagement. A common approach is to assess the suppliers with access to your most sensitive information or your critical operations first, then extend. Scopes and packages are set out on the assessment packages page.
Scopes and packages are on the assessment packages page, or book a short call to discuss your supplier set.