Third-party and supply-chain risk in M&A

OT vendors, critical dependencies and permanent access: mapping and monitoring what you inherit.

When you assess a target, you also assess the web of suppliers, partners and services it depends on. Few companies today operate alone: software runs on third-party cloud platforms, critical processes flow through managed providers, production depends on externally supplied components and control systems. You buy the target and, in effect, you buy its supply chain.

In M&A, third-party risk is often the least examined, because it sits one step beyond the legal boundary of the company you are buying. Yet a compromised critical supplier, a contract that exposes sensitive data, or a dependency with no alternatives can weigh on value as much as an internal weakness.

The deal’s perimeter doesn’t end at the target

Diligence tends to stop at the systems the target owns. Attackers do not. Compromises through software and managed-service providers have become an ordinary way in precisely because they bypass the defended perimeter: hit a trusted supplier and you reach all of its customers.

That is why mapping third parties is part of diligence, not an appendix. The question is not only «how secure is the target», but «who does the target depend on to operate, and what happens if one of those suppliers fails or is breached».

Mapping critical dependencies

Not all suppliers matter equally. The useful work is identifying the few dependencies whose interruption or compromise would halt a revenue-generating process or expose regulated data. It is usually a short list: the main cloud platform, the provider running the ERP or payments, the service production depends on.

For each critical dependency you need a few precise answers: what data it handles, what level of access it has to the target’s systems, what contractual guarantees exist in the event of an incident, and how hard it would be to replace. Difficulty of replacement is often the most underrated factor.

It is worth mapping fourth-party dependencies too where they are visible: the critical supplier that, in turn, rests on a single infrastructure shared by many. You don’t need to chase every branch, only to recognise the few points of concentration hidden behind different suppliers, because that is where a single failure travels furthest.

OT vendors and cyber-physical systems

In industrial companies, supply-chain risk takes a particular form. Control systems — OT — and externally supplied components have long lifecycles, are updated rarely, and were often designed when connectivity was not a security concern. A supplier that keeps remote access to a plant for maintenance is, in effect, a permanent door into the production environment.

In diligence this means looking not only at the target’s IT security, but at who has access to its OT environments, how that access is controlled and segmented, and which suppliers could introduce risk directly into physical processes. The consequences here are not only data: they are production continuity and, in some sectors, human safety.

Concentration and access rights

Two dimensions deserve specific attention. The first is concentration: if a single supplier underpins several critical processes, its failure is a systemic risk to the target, not an isolated incident. The second is access rights: many suppliers hold permanent, broad and poorly monitored access to customer systems, often well beyond what the service requires.

A third-party access granted years earlier and never reviewed is one of the most common and least visible exposures you will find. It is worth inventorying, because these are also among the easiest to reduce right after close.

From inventory to monitoring

Mapping dependencies once is not enough: the supply chain changes. The value of diligence lies in turning the initial inventory into something the acquirer can maintain — a list of critical suppliers with their level of access and risk, folded into the third-party management process after the deal.

The Day 1 plan should include the supplier actions that cannot wait: reviewing the broadest third-party access, confirming the contractual incident-notification clauses, and making sure that dependencies with no alternatives have at least a continuity plan.

The takeaway

A deal’s risk does not end at the target’s boundary. Map the few genuinely critical dependencies, look closely at OT vendors and permanent third-party access, and turn the inventory into monitoring that survives close. The supply chain you inherit is part of what you are buying.

From reading to deciding

Turn this into a decision you can defend.

A confidential 30-minute conversation to apply it to your situation — or start from a practical resource.