M ManySignal

Attack Surface: Third-Party Risk

Third-party and vendor access risk

Your managed service provider has admin access to 200 systems. Their credentials were compromised at 2 AM on a Tuesday. ManySignal detected the anomalous access pattern and suspended the vendor session before the first lateral movement.

Attack surface map

Vendor access is privileged access you don't directly control

Managed service provider access

T1199

MSP compromise gives attackers admin access to all MSP clients

Vendor remote access (VPN/RDP)

T1133

Credential compromise, persistent access beyond engagement

SaaS integrations

T1550.001

Third-party OAuth apps with broad data access

Contractor identity accounts

T1078

Orphaned accounts post-engagement, shared credentials

API integrations

T1552

Vendor API keys with production data access

Supply chain software

T1195.002

Vendor software with privileged local access

Top 5 detection rules

1
Vendor access outside contract scope
Vendor session accessed system or data category not in their contracted access list
2
Vendor authentication anomaly
Vendor credentials used from geography inconsistent with vendor's known office locations
3
Contractor account still active post-engagement
Account flagged as contractor active after contract end date from HR/procurement system
4
Vendor bulk data access
Vendor session downloaded data volume exceeding expected operational need by 5x
5
MSP-to-client lateral movement
Authentication from shared MSP jump host to multiple client environments in rapid succession
Vendor monitoring model
Vendor identity tagging
  • IdP group: vendor-[vendor-name]
  • Domain: @vendorname.com accounts
  • Contract scope: systems + data categories
  • Engagement dates: start and end from procurement
  • Risk tier: from third-party risk platform
Behavioral controls
  • Access scope enforcement with alert on violation
  • Off-hours access requires supervisor approval
  • Session recording for privileged vendor access
  • Automatic session termination post-engagement
  • Data download volume limits with anomaly alerts

Related use cases

Third-party risk FAQ

How does ManySignal monitor third-party vendor access to the environment?

ManySignal monitors all identity provider authentication events for vendor user accounts (identified by domain, group membership, or attribute tags). Vendor sessions are compared to their contractual access scope: expected systems, expected hours, expected data categories. Deviations — off-hours access, access to systems outside the vendor's scope, bulk data downloads — trigger alerts enriched with the vendor's contract context.

Can ManySignal detect when a vendor's own environment has been compromised?

Yes. Indicators of vendor compromise include: authentication from unusual geographic locations, changes to access patterns inconsistent with contract scope, use of unexpected tools or user agents, and activity patterns that match known attack TTPs (reconnaissance, lateral movement). ManySignal also monitors threat intelligence for compromise notifications related to specific vendor organizations.

How does ManySignal handle vendor access that doesn't go through your identity provider?

ManySignal monitors for direct access patterns that bypass the identity provider: direct database connections from external IPs, SSH access from vendor IP ranges, VPN connections using vendor-assigned credentials. These are flagged as higher risk than IdP-authenticated sessions because they lack MFA enforcement and session policy controls.

Does ManySignal integrate with third-party risk management platforms?

Yes. ManySignal integrates with OneTrust, ServiceNow GRC, Archer, and similar platforms to pull vendor risk ratings, contract access scope definitions, and ongoing assessment results. This context is used to adjust alert severity: a suspicious access event from a high-risk vendor with overdue security assessment is scored higher than the same event from a low-risk vendor with clean recent assessment.

How does ManySignal generate vendor access reports for compliance and audit purposes?

ManySignal's vendor access report covers any configured time period: all vendor authentication events, access scope vs. contractual entitlement, any anomalous behavior detected, and containment actions taken. Reports are formatted for SOC 2 Type II auditor review (vendor management controls, CC9.2), ISO 27001 Annex A.15 (supplier relationships), and internal governance board review. Reports can be auto-generated on a monthly or quarterly schedule.

What happens when ManySignal detects that a vendor's credentials have been used from an unexpected location?

The detection fires an alert immediately with the vendor context attached: vendor name, access scope, contract status, and historical access patterns. The Triage agent evaluates whether the location anomaly is consistent with vendor team travel patterns. For confirmed anomalies, the response workflow options include: suspend the vendor's SSO session, require re-authentication with additional verification, or revoke temporary access credentials — all from the ManySignal case view.

Does ManySignal help assess the security posture of third-party vendors before granting them access?

ManySignal's focus is monitoring active vendor access, not pre-access security assessments. For pre-access vendor risk scoring, ManySignal integrates with third-party risk platforms (BitSight, SecurityScorecard, UpGuard) and can pull vendor risk ratings as context for access decisions. Once a vendor is granted access and active in the environment, ManySignal's continuous behavioral monitoring provides ongoing assurance that access is being used within its intended scope.

How does ManySignal handle vendors that access the environment via shared accounts or shared credentials?

Shared credentials are a significant risk because they prevent individual user attribution. ManySignal flags shared credential usage (multiple simultaneous sessions from different geographic locations, session switching patterns inconsistent with a single user) and can correlate shared account activity with the list of individuals known to have the credentials. The recommendation workflow suggests migrating vendors to individual SSO-federated accounts with proper attribution.

Monitor vendor and contractor access like privileged user access

Contract-scoped behavioral monitoring — catch the compromised MSP credential before it becomes a full breach.