Cybersecurity
Supply Chain Attacks: The Risk Growing Faster Than Any Other
You can secure every system you own and still get breached through a vendor you trusted. Here's why that risk is accelerating.
Most small business security conversations focus on the business's own systems — its laptops, its email, its network. That's necessary, but it's no longer sufficient. A growing share of breaches now start somewhere else entirely: a vendor, a software integration, or a connected app that had legitimate, trusted access to your systems — until it didn't. Industry research from IBM's X-Force team found that major supply chain and third-party breaches have quadrupled over the past five years, alongside a 44% year-over-year increase in attacks exploiting public-facing applications.
What a supply chain attack actually looks like
Rather than attacking your business directly, an attacker compromises something your business already trusts and connects to — and rides that trusted connection in. A few real patterns:
- Compromised OAuth tokens. Many SaaS tools connect to each other using OAuth — the "Sign in with Google," "Connect to Slack"-style permissions most businesses grant without much thought. If the connecting app itself gets compromised, attackers can use that token to access every system it was authorized to touch, without ever needing your password.
- Compromised software updates. Legitimate software vendors occasionally get breached themselves, and a routine update pushed to thousands of customers becomes the delivery mechanism for malware — the victim's own IT team installed it, believing it was routine.
- Compromised open-source packages. Modern software — including the tools your vendors build on — relies heavily on open-source components. A single compromised package can quietly propagate into every product that depends on it.
- Vendor account compromise. A vendor with legitimate remote access to your systems (an IT contractor, a POS provider, a booking platform) gets breached themselves, and their access becomes the attacker's access.
Why small businesses underestimate this risk
It's intuitive to think about securing what you own and easy to forget about what you've connected. Every app a business authorizes — accounting software linked to a bank account, a scheduling tool connected to email, a marketing platform with CRM access — expands what's sometimes called the "attack surface" beyond the business's own walls. Most SMBs have never actually inventoried which third-party apps have access to what, which makes it hard to know what's actually at risk.
The question isn't just "is our system secure" — it's "how many other companies' security failures could become our problem."
What to actually do about it
- Inventory your connected apps. Most businesses are surprised by how many third-party integrations have accumulated access over time — old tools nobody uses anymore often still have live permissions.
- Review permissions, not just presence. A tool that only needs to read your calendar shouldn't have access to send email on your behalf. Over-scoped permissions are common and rarely reviewed after initial setup.
- Remove what you don't use. Every unused integration with live access is risk with zero business benefit.
- Ask vendors about their own security practices before granting deep access — especially for tools touching financial data, customer data, or email.
- Apply the same patching discipline to public-facing applications (websites, customer portals, booking systems) that you'd apply to internal systems — these are increasingly a top exploitation target.
- Use conditional access and monitoring so unusual activity from a connected app or vendor account gets flagged, not just unusual activity from a human login.
The bottom line
You can't personally audit every vendor's security team, and you shouldn't try to. What you can do is control what has access to your systems in the first place, review it periodically, and treat every connected third party as part of your actual attack surface — because increasingly, that's exactly what it is.
Not sure what has access to your systems?
We help Brevard County businesses inventory connected apps and vendor access, and close the gaps that don't need to be open.
Schedule Free Assessment