
In July 2025, Qantas became the latest high-profile victim of a cyberattack. Customer data from its loyalty program was compromised via an outsourced call centre provider, not Qantas’s own systems.
This breach highlights a fundamental truth: cybersecurity risk doesn’t stop at your firewall. Whenever you give a partner access to your systems or data, you inherit their vulnerabilities. That’s third-party risk.
But the story doesn’t end there. Many of your suppliers rely on their own suppliers: subcontractors, cloud platforms, or offshore BPOs. If one of those is compromised, you could be exposed without even knowing they exist. That’s fourth-party risk.
Third and Fourth Party: Both Are Overlooked
Most organisations acknowledge third-party risk in some form, but often only superficially. A quick check for ISO certifications, a signed NDA, maybe a line in the contract about “appropriate security measures.”
But as the Qantas breach shows, this isn’t enough. The call centre had privileged access to customer data; the attackers bypassed multi-factor authentication by targeting staff directly.
Now consider a fourth-party scenario: What if that call centre provider outsourced its IT helpdesk, or used another subcontractor for data storage? Suddenly, your exposure extends to people and systems you’ve never assessed. These “hidden links” in your supply chain are often invisible and therefore unmanaged.
Both layers matter. A breach at your direct supplier can have the same devastating impact as a breach at a supplier’s supplier, but the latter is even harder to anticipate or respond to.
Why These Risks Are Growing
- Complex outsourcing chains: Modern businesses rarely handle everything in-house; services are layered across multiple vendors.
- Expanded attack surface: Every integration, data flow, or shared login adds potential entry points for attackers.
- Evolving threat tactics: Cybercriminals increasingly target vendors rather than end organisations, knowing defences are often weaker there.
- Regulatory pressure: Under laws like the Australian Privacy Act, you may still be responsible for breaches caused by partners.
Rethinking How You Manage Supplier Risk
Addressing these risks requires a shift from vendor-by-vendor thinking to ecosystem thinking. Key elements include:
- Transparency: Ask every supplier who else is involved in delivering their service. Don’t assume you know everyone with access to your data.
- Flow-down security: Your security expectations must extend to subcontractors. Contracts should obligate suppliers to enforce your standards with any partners they use.
- Ongoing oversight: Third-party risk isn’t a one-off assessment; vendors’ circumstances change. Build in regular reviews and request evidence of their own vendor management.
- Incident readiness: Plan for breaches beyond your perimeter. Ensure reporting timelines, escalation paths, and response plans include third and fourth parties.
- Minimising exposure: Restrict vendor access to only what’s necessary. The less they hold, the less there is to lose if something goes wrong.
What we do at Fuse:
Our Vietnam team provides offshore support, but unlike many outsourcing models, we fully own and operate this team. That means we maintain complete control over data, systems, and processes—no external providers or hidden subcontractors. This setup gives us stronger security and compliance, ensures a more consistent customer experience, and provides a foundation for long-term scalability. Offshoring can be a powerful strategic advantage—but only when treated as an integrated extension of your business, not just a cost-cutting exercise.
Stay ahead of threats that can affect your business