Third-Party Risk

Vendor breaches, TPRM program failures, concentration risk, and supply chain due diligence.

The Key Was on the Laptop

A 300-employee building supply distributor lost $1.4 million when a compromised warehouse laptop walked through an always-on tunnel to their MSP-hosted servers. One MSP hosted the servers. Another managed the laptops. The EDR caught the attack on Day 0. Nobody was watching. Three contracts, three denials, and a gap nobody owned.