trampolim.net
PT EN

Trampolim · Technology weekly

The Week in Tech

Issue 03Week of May 11–17, 202616 stories
Security

A supplier attack exposes the link nobody audits

Customers assess their own systems and inherit the security posture of whoever they hired.

A supplier attack exposes the link nobody audits
Security · May 11–17, 2026

The period's incidents reinforce a problem internal risk assessment can't reach: a company's exposure also depends on the security posture of the suppliers it hired.

Each organisation assesses its own network, its own systems and its own team. What almost never enters the calculation is that much of the operation passes through third-party services, and their security isn't auditable from outside.

The asymmetry is structural. Contracts usually carry a generic security promise, and customers have no way to verify internal practice, credential policy or incident history.

What can be demanded is different and concrete: notification deadlines in case of incident, scope of what will be disclosed, audit rights, and a clear definition of what data the supplier holds and for how long.

For small operations, that's the available lever. You can't audit the supplier, but you can choose one that accepts a fast-notice clause, and that separates learning from your supplier from learning from the press.

Book a call