Third-party and supply chain
You can outsource the work. You cannot outsource the risk. Cloud shared responsibility, IRAP evidence, ISM procurement — and the vendor update channel that pushes your next plugin build.
ASD's cloud shared-responsibility guidance for executives is the sentence boards skip: you always keep some responsibilities, and you carry the risk to your data's confidentiality, integrity, and availability. A compromise can still be your financial, reputational, and legal problem. A contract that says 'the CSP is secure' does not move that.
The same logic applies to managed service providers, CI/CD, RMM consoles, and the database operator behind a booking brand. If a third party holds the data or the admin plane, their vulnerability is an access path into you. Quest Apartment Hotels' 2026 statement described unauthorised access arising from a vulnerability through a third-party service provider. That is the pattern, not a one-off.
ISM procurement and outsourcing controls expect IRAP assessment of outsourced cloud and managed services on a cycle, and they expect you to understand residual risk. ACSC's cloud FAQ: ask for the IRAP assessment including detailed residual risks; international certificates are not a substitute for ISM alignment. Visibility of subcontractors is part of the shared-responsibility test — 'we use a hoster' is not a threat model.
Open-source is a supply chain too. The AFP, with WAPF and the FBI, charged two West Australian men on 26 August 2026 over an alleged syndicate that inserted malicious code into software on a public repository, then let other developers pull it in. Police put the impact at more than 1,000 organisations globally, more than 500,000 credentials, and at least 300 GB of data, with remediation costs in the hundreds of millions of dollars. The FBI statement in that release names the group TeamPCP. Inventory direct dependencies, CI tokens, and who can publish to the registries you consume. A pin to a version is not a review of the maintainer.
Update channels are a supply chain too. When a premium plugin, panel extension, or desktop updater is hosted on the vendor's own site, a break-in there is equivalent to a malicious release: customers who click update install the attacker's build. The Admin Menu Editor Pro incident of 14 September 2026 is the pattern in miniature — malicious Pro builds 2.35 and 2.36 pushed from a compromised distribution host to about 230 customers and at least 1,500 WordPress sites, with a web shell and a hidden admin user. Hosting control-panel backup plugins sit in the same class: a privilege-escalation bug in the plugin (Acronis CVE-2026-87886 on cPanel/WHM and Plesk integrations) is an access path into every tenant the panel manages. Inventory who can publish to the update URLs you trust, prefer signed or attested releases where they exist, and treat auto-update from the vendor site as a privileged control — not a convenience toggle.
On the desk: inventory who can touch identity, backups, and personal information. Write the shared-responsibility split before the incident, not during it. Put NDB and, if you are in, SOCI reporting in the same runbook as the vendor's status page. When the third party is breached, your clock still starts.
See also:
Fact source: ACSC, cloud shared responsibility (executive guidance).
