High
Financial Services
Critical ICT Providers
Critical third-party oversight becomes a live supervisory regime
DORA oversight of critical ICT third-party providers is now a continuing supervisory track in the EU, while the UK
announced that its financial regulators would begin overseeing the first designated Critical Third Parties on
13 July 2026. The UK designations cover Amazon Web Services EMEA SARL, Google Cloud EMEA Limited, Microsoft Ireland
Operations Ltd, and Oracle Corporation UK Limited.
The message for TPRM teams is clear: cloud and infrastructure concentration is no longer only an internal risk appetite
question. Supervisors are treating it as a system-level resilience issue.
Recommended actions
- Map services delivered by designated CTPPs / CTPs to critical or important functions.
- Refresh exit planning, substitution constraints and portability evidence for cloud and data infrastructure.
- Align DORA Article 28-30 clauses with supplier-side evidence requests and subcontracting disclosure.
- Prepare board reporting on concentration across EU and UK critical third-party regimes.
High
CRM
Integration Risk
Third-party CRM integration incident shows lateral data exposure
Digital Science disclosed a June supply-chain security incident involving a third-party provider integrated with its
CRM platform. The exposure window was short, but the accessed information included business contact data and sales
opportunity metadata.
This is a useful reminder that supplier risk is not limited to production systems or regulated data. CRM integrations
often carry relationship maps, contract dates, account metadata, procurement context and other information that can
support phishing, vendor impersonation or competitive intelligence.
Recommended actions
- Inventory third-party CRM integrations and their scopes, tokens and synchronization permissions.
- Review whether sales metadata, contact lists and contract fields are covered in vendor incident scenarios.
- Set least-privilege integration scopes and short-lived tokens where supported.
- Include CRM and marketing technology providers in phishing and impersonation threat modelling.
High
Third-Party Software
Accountability
Software supply chain accountability is moving into partner and MSP relationships
Public guidance from NCSC and threat research from Google / Mandiant both point to the same operational baseline:
organizations must understand how dependencies are introduced, updated, isolated and monitored. That requirement will
increasingly flow down to managed service providers, software vendors and channel partners.
A supplier that manages code, infrastructure, endpoints, cloud workloads or deployments on behalf of customers is now
also managing a software supply chain risk surface.
Recommended actions
- Add software dependency and SBOM evidence to onboarding for software and MSP suppliers.
- Require suppliers to explain how they slow or review automatic dependency updates in critical environments.
- Ask for credential storage, build runner isolation and package registry controls as assurance evidence.
- Define notification triggers for compromised dependency, maintainer account or CI/CD pipeline events.