Third-Party Access to Systems
Third-party access to systems describes which external vendors, suppliers or service providers hold network or system access into an organisation's IT environment, and under what controls, a frequent source of indirect cyber exposure.
- Category
- IT/Cyber
- Data type
- Text
- Risk drivers
- Severity, Frequency, Accumulation
- Underwriting impact
- Premium, Condition/Warranty, Exclusion
Typical proposal-form questions
- Which external vendors, suppliers or managed service providers have network or remote access to the organisation's systems, and for what purpose?
- How is third-party access technically controlled and monitored (e.g. dedicated accounts, time-limited access, logging, jump hosts), and is it segregated from general employee access?
- Are cyber security requirements contractually imposed on vendors with system access, and is compliance verified?
Evidence
- Third-party access register or vendor inventory
- Vendor risk management or third-party due diligence policy
- Contracts including cyber security clauses for vendors with system access
Why it matters for underwriting
Attackers increasingly target the weakest link in a chain of connected organisations rather than attacking a well-defended target directly, and a managed service provider, software vendor or maintenance contractor with standing access into a client’s network is a well-documented pathway for exactly this kind of indirect compromise. A single compromised vendor with broad, unmonitored access can affect many client organisations simultaneously, making third-party access both a severity driver for any individual insured and an accumulation driver across the insurer’s portfolio where several policyholders share the same vendor. Underwriters therefore need to understand not just the insured’s own controls but the number, nature and access scope of external parties that can reach into its environment, since this exposure often sits outside the insured’s direct operational control yet remains within its risk profile.
Capturing the attribute and evidence
Proposal forms ask insureds to describe which external vendors, suppliers or managed service providers hold network or system access, the purpose and scope of that access, and how it is technically controlled, for example through dedicated named accounts, time-limited or on-demand access rather than standing credentials, activity logging, and routing through a monitored jump host rather than a direct connection. Underwriters request the organisation’s third-party access register or vendor inventory, its vendor risk management or due diligence policy describing how vendors are assessed before being granted access, and contracts demonstrating that cyber security obligations, such as minimum control standards and breach notification duties, are imposed on vendors contractually. Concentration in a small number of critical vendors with broad access is noted specifically as a distinct exposure.
Effect on coverage, premium and conditions
A well-governed vendor access programme, with narrowly scoped, time-limited, logged and contractually secured access, supports standard terms and pricing. Broad, standing or poorly monitored access granted to numerous vendors without contractual security requirements typically results in a condition requiring implementation of stronger access controls within an agreed period, or a sublimit or coinsurance requirement on losses originating from a third-party access point rather than a direct attack on the insured’s own systems. Heavy reliance on a single vendor with extensive, unmonitored access to critical systems can lead to a specific exclusion for losses traceable to that vendor, or, for the most severe cases, declinature pending remediation.
Mitigation measures
Maintaining a current register of all vendors with system access, including the specific scope and business justification for that access, is the foundational control, since access that is not tracked cannot be reviewed or revoked when no longer needed. Applying least-privilege principles, time-limited or just-in-time access rather than permanent standing credentials, and routing all vendor connections through a monitored jump host with full activity logging are standard technical recommendations. Contractually requiring vendors with system access to meet defined minimum security standards, including prompt breach notification obligations, and periodically verifying that access still corresponds to an active business need, are recommended governance practices to close this exposure over time.