third-party-risk
Safeguard articles tagged "third-party-risk" — guides, analysis, and best practices for software supply chain and application security.
55 articles
Every SaaS Tool Nobody Approved Still Has Access
Someone signed up with a company card, connected it with broad OAuth scopes, used it for a quarter, and stopped. The subscription lapsed. The integration did not. Adopting a tool costs nothing; removing one requires someone to remember it exists.
Every Connected App Holds a Credential Nobody Reviews
A user clicks approve in about four seconds and an application you did not write holds a token to their data, refreshing itself indefinitely. In most products nobody can list them afterwards.
A Vendor Just Told You They Were Breached
The notification is vague, late, and does not say whether you are affected. It starts several clocks, and one of them may be a 72-hour regulatory deadline that runs from when you became aware, not when their investigation finishes.
Diligence Tells You What You Bought. Integration Is Where the Risk Arrives.
Most acquisition security effort happens before close and produces a report. Your exposure actually changes in the ninety days afterwards, when the pressure is to connect everything quickly and the security questions are marked answered.
How to Actually Read a Vendor's SOC 2 Report
You skim the front, see an unqualified opinion, approve the vendor. The value is in four sections most reviewers never reach, and one of them lists the controls you are required to perform for the vendor's controls to work.
The Contractor Offboarding Nobody Ever Did
Every offboarding process is triggered by a termination event in a directory. A contractor's engagement ending produces an invoice, not a directory change, so nothing downstream fires and the account stays live.
The Seven Artifacts Every Enterprise Security Review Asks For
The customer security review is the most expensive gate in enterprise software sales and the most predictable. The same seven artifacts get requested in roughly the same order, and preparing them early turns nine weeks into two.
Target (2013): How an HVAC Vendor Became the Path to 40 Million Cards
A factual retrospective on the 2013 Target breach, in which attackers used credentials stolen from a third-party refrigeration contractor to reach the retail network and deploy point-of-sale malware.
Third-party risk assessment for insurtech SaaS platforms
A practical playbook for running an insurtech third-party risk assessment across vendors, APIs, and integrations before they touch policyholder data.
Third-party risk management for retail supply chain and l...
A practical, step-by-step framework for assessing and monitoring retail logistics software vendor risk, from SaaS onboarding to inventory system offboarding.
Third-party risk management for OT/ICS vendors in utilities
A step-by-step guide to OT ICS vendor risk management for utilities: assessing, auditing, and monitoring SCADA and industrial control system vendors.
Medtronic and AdaptHealth: The Third Party Was the Vulnerability
3.8 million people notified by Medtronic. PII, PHI and insurance billing credentials exfiltrated at AdaptHealth after social engineering against a third-party contractor. Neither breach needed a software vulnerability — both needed a trusted outsider with a session.
Self-healing security runs on Safeguard.
Your first fix PR is minutes away.
No sales call required, even your agent can complete the purchase over MCP.