5 min read

Third-Party Cyber Risk: What Your Firm Needs to Consider

Published on

10 September 2026

Law firms, accountancy practices and insurance businesses are built on trust.

Clients hand over personal details, financial information, confidential documents and other sensitive data with the expectation that it will be handled carefully and securely.

Protecting that information is therefore an important part of running your business. But there’s one area of cybersecurity that’s easily overlooked: the organisations outside your firm that may also have access to your systems or data.

From cloud software and document management platforms to outsourced IT providers and specialist industry applications, most professional services businesses depend on a growing number of third parties.

Each relationship can bring enormous benefits, but it can also become part of your wider cyber risk.

Your Cybersecurity Doesn’t Exist in Isolation

Think about how many external services your firm uses during an ordinary working day.

A law firm might rely on practice management software, document-sharing platforms and specialist conveyancing systems. An accountancy practice may use cloud accounting software, payroll systems and tax applications. An insurance business could depend on customer management platforms, policy administration software and other specialist systems.

Add Microsoft 365, cloud storage, external IT support, contractors and other suppliers, and the number of third parties involved can quickly grow.

The important question isn’t simply whether you trust these organisations.

It’s what access do they have, and how is that access being protected?

You can put strong cybersecurity controls around your own organisation, but if sensitive information is also accessed, processed or stored elsewhere, those relationships need to form part of your cybersecurity thinking too.

Who Has Access to Your Client Information?

A useful first step is simply establishing who can access what.

You may know which major software platforms your firm uses, but what about smaller applications introduced for a particular project? Are there former contractors who still have accounts? Does an external supplier have access to systems that it no longer needs?

Over time, access can accumulate.

Businesses should periodically review the third parties they work with and consider:

  • What information can they access?
  • Why do they need that access?
  • How do they access it?
  • Who within the supplier’s organisation can see the information?
  • Is that access still required?

This isn’t about assuming every supplier represents a threat. It’s about understanding your exposure so you can manage it appropriately.

Limit Access to What’s Actually Needed

One useful cybersecurity principle is least privilege.

In simple terms, this means users should only have access to the systems and information they genuinely need to do their job.

The same principle can be applied to third parties.

If a supplier only needs access to one particular system, there may be no reason for it to have broader access to your environment. If a contractor needs information for a temporary project, that access shouldn’t necessarily remain indefinitely.

Limiting unnecessary access can help reduce the potential impact if an account or supplier is ever compromised.

For professional services firms handling confidential client information, good access control should be a fundamental part of protecting that trust.

What Happens When a Supplier Relationship Ends?

Businesses tend to think carefully about giving a new supplier access.

Removing that access can receive less attention.

When a contract finishes or you move to another provider, it’s important to consider what gets left behind.

Are user accounts disabled? Have integrations been removed? Are shared folders still accessible? Are API connections or remote-access permissions still active? Does the former provider retain any of your information?

This is particularly important when businesses have used the same systems for several years and different suppliers have come and gone.

Keeping a clear record of third-party access makes it much easier to review and remove permissions when they’re no longer required.

Five Cybersecurity Questions to Ask Your Suppliers

You don’t need to become a cybersecurity expert before speaking to a supplier.

A few straightforward questions can provide valuable insight into how seriously an organisation approaches security.

1. What Cybersecurity Controls Do You Have in Place?

Ask how the supplier protects its systems, accounts and the information it holds.

The answer should give you a better understanding of whether cybersecurity forms part of the organisation’s normal operations rather than being treated as an afterthought.

2. Do You Hold Cyber Essentials or Another Relevant Certification?

Cybersecurity certifications can provide additional reassurance that a supplier has considered recognised security controls.

Cyber Essentials, for example, is a UK Government-backed scheme designed to help organisations protect themselves against common cyber threats.

Certification shouldn’t necessarily be the only factor you consider, but it can be a useful part of your supplier assessment.

3. Do You Use Multi-Factor Authentication?

Passwords can be stolen, guessed or compromised.

Multi-factor authentication (MFA) adds another layer of security by requiring an additional form of verification before access is granted.

If a supplier has access to sensitive systems or information, understanding how it protects user accounts is an important question.

4. Who Can Access Our Information?

Not everyone working for a supplier should automatically need access to your data.

Ask how access is granted, controlled and reviewed within the supplier’s organisation.

For firms dealing with confidential legal, financial or insurance information, knowing who can access client data — and why — should be a priority.

5. What Happens If You Experience a Cyber Incident?

No organisation can guarantee that it will never experience a cyber incident.

What’s important is how prepared it is to detect, respond to and recover from one.

Ask suppliers what procedures they have in place and how they would communicate with you if an incident potentially affected your systems or information.

Finding out after an incident occurs is too late to start asking these questions.

Don’t Just Ask Once

Cybersecurity shouldn’t be treated as a question you ask when signing a contract and then forget about.

Businesses change. Technology changes. Suppliers introduce new systems, employees and processes. Your own relationship with a supplier may change too.

A provider that originally had limited access could gradually become deeply integrated into your business.

That’s why third-party access should be reviewed periodically.

Ask whether the supplier still needs the same permissions, whether the information being shared is still necessary and whether anything has changed that could affect your cyber risk.

Protecting More Than Data

For law firms, accountants and insurance businesses, cybersecurity isn’t simply an IT issue.

It’s closely connected to client confidence.

People trust professional services firms with information they may not share with many other organisations. A client isn’t necessarily concerned with whether their information sits on your own server, in a cloud application or with another service provider.

They simply expect you to protect it.

Understanding third-party cyber risk is therefore about more than protecting individual systems. It’s about maintaining control over where information goes, who can access it and how that access is secured.

How Confident Are You in Your Supply Chain?

You don’t need to stop using third-party technology or external providers. Modern professional services businesses couldn’t operate effectively without them.

Instead, the goal should be to understand your dependencies and manage the cyber risks appropriately.

Know which organisations have access to your systems and data. Limit that access where possible. Ask suppliers sensible cybersecurity questions. Review permissions regularly. And make sure access is removed when it’s no longer needed.

Your firm’s cybersecurity doesn’t stop at the edge of your own network.

If you’re a law firm, accountancy practice or insurance business and you’re unsure where third-party access could be creating cyber risk, speak to Ashdown Solutions.

Our team can help you understand your cybersecurity requirements and identify practical steps to strengthen your organisation’s protection.

BOOK A CALL WITH THE ASHDOWN SOLUTIONS TEAM