Effective Handling of Third-Party Supplier Incidents

Kasturi Puramwar

BSidesSF 2025 — Here Be Dragons · Day 2 · Main

Overview

Kasturi Puramwar, incident response manager at Equinix, laid out a comprehensive cross-functional framework for handling third-party supplier incidents — arguing that the IR team alone cannot manage them effectively without structural partnerships with supply chain management, TPRM, legal, and a formal risk governance committee. The core insight: preparation done before an incident determines whether the response is coordinated or chaotic. ---

Watch on YouTube

Visual summary for Effective Handling of Third-Party Supplier Incidents by Kasturi Puramwar
Visual summary for Effective Handling of Third-Party Supplier Incidents by Kasturi Puramwar

Key moments

  1. 2:29 Stat: 61% of orgs had a breach via third party — 49% increase from prior year
  2. 4:00 Fourth-party risk: your supplier's supplier breach can cascade to your organization
  3. 5:00 IR alone is insufficient: supply chain, TPRM, legal, and privacy must all collaborate
  4. 6:30 Preparation phase: define cross-functional stakeholders before an incident occurs
  5. 7:30 Supply chain mgmt role: centralized vendor inventory with business relationship owners
  6. 9:00 SLA in contracts: timely breach notification clauses must be established pre-incident
  7. 10:00 Vendor risk scoring tools: pre-assess critical vendor posture before incident strikes
  8. 11:30 SAQ framework: standardized pre-onboarding security questionnaires classify supplier risk

Effective Handling of Third-Party Supplier Incidents

Speaker: Kasturi Puramwar

Conference: BSidesSF 2025 — April 26-27, 2025, San Francisco

YouTube: Watch on YouTube

Reading time: ~7 minutes

TL;DR

Kasturi Puramwar, incident response manager at Equinix, laid out a comprehensive cross-functional framework for handling third-party supplier incidents — arguing that the IR team alone cannot manage them effectively without structural partnerships with supply chain management, TPRM, legal, and a formal risk governance committee. The core insight: preparation done before an incident determines whether the response is coordinated or chaotic.

Introduction

When a supplier is breached, the incident response team is often the last to know and the first expected to act. They may not have the contracts, the supplier contacts, the data classification records, or the authority to make containment decisions that impact business operations. The result — documented repeatedly across industries — is gut-based decision-making, case-by-case improvisation, and incident responders taking on responsibility for business consequences they were never equipped to own.

Puramwar's talk at BSidesSF 2025 addressed this directly. Drawing on seven years of incident response experience at Equinix, including handling third-party supplier incidents in a global infrastructure environment, she described the organizational architecture that makes a coordinated response possible: who needs to be involved, what agreements need to be in place before incidents occur, and how risk-based decisions can be made systematically rather than under pressure.

The broader context: a Prevalent survey found that 61% of organizations experienced a breach involving a third party in the prior year — a 49% increase from the year before. And fourth-party risk (the suppliers your suppliers use) adds another layer of exposure that most programs have not begun to address.

The Cross-Functional Preparation Model

▶ Watch: Cross-functional stakeholders — supply chain, TPRM, legal, IR (08:45)

Puramwar's argument is that third-party incident response requires at minimum four organizational functions working in partnership: the IR team, the third-party risk management (TPRM) program, the legal and privacy office, and supply chain management. Each has a distinct role that the others cannot substitute for.

Supply chain management maintains the centralized vendor inventory, assigns business relationship officers (BROs) to each supplier, manages contracts, and knows when renewals occur. In an incident, the BRO is the bridge between the IR team and the supplier — a critical path that IR teams rarely have directly. Puramwar emphasized that security language should be embedded in supplier contracts at onboarding: timely notification SLAs, definitions of what constitutes an incident, requirements around data impact reporting. Building the relationship as a two-way street — explicitly committing to notify suppliers if your organization is compromised — creates the reciprocal trust that accelerates information sharing when it matters.

The TPRM team conducts pre-onboarding risk assessments, maintains risk profiles and scores for critical vendors, and classifies suppliers by the nature of their access (physical security, insider risk, data processing, privacy). They are positioned to run proactive questionnaires before incidents occur and have the tooling to integrate risk profiles with contractual data. The most actionable output of TPRM work for incident response: knowing in advance what your critical vendors are, what data they process, and what your backup plan is if any of those services goes offline.

The legal and privacy office owns contractual obligation analysis and regulatory reporting requirements. When a breach potentially affects customer data, whether and when notification is required depends on regional law (HIPAA, GDPR, CCPA, and others), the specific data categories involved, and the contractual terms with affected customers. The IR team cannot make those determinations without legal partnership.

Threat Intelligence as Early Warning

▶ Watch: Threat intel integration and pre-triage before escalation (17:30)

Puramwar advocated for integrating threat intelligence as a proactive supply chain monitoring layer. Threat actors increasingly publish stolen data when organizations do not comply with ransom demands, creating a public signal that an organization's data may have been compromised before the supplier issues any formal notification. A continuous monitoring capability that tracks mentions of the organization's data across dark web forums, data leak sites, and other intelligence sources can detect supplier incidents independently of the supplier's own disclosure timeline.

Critically, this intelligence should not flow directly to the IR team without pre-triage. Puramwar described having the threat intel team vet whether a monitored indicator actually relates to a supplier with a relationship to the organization — using TPRM tooling and the vendor inventory — before escalating. This reduces IR team burnout from acting on alerts that turn out to have no organizational relevance, and ensures that when an escalation does occur, it already carries some preliminary analysis.

The Incident Response Flow and the Supply Chain Risk Management Committee

▶ Watch: Reactive SAQ, analysis flow, and STRM committee structure (24:00)

Once an incident is confirmed as genuine and relevant, Puramwar's framework kicks into a structured flow:

  1. Severity classification using a third-party-specific severity matrix (not a generic IR matrix). The criteria that determine P1 vs. P2 vs. P3 for a supplier incident differ from an internal incident — business continuity, contractual obligations, regulatory exposure, and media interest all factor in.
  1. Reactive SAQ deployment. The same questionnaire infrastructure used for proactive vendor assessment is adapted for reactive use. A rapid questionnaire goes to the supplier immediately to gather first-party data on what happened, what data was affected, and what their remediation timeline looks like.
  1. Analysis with the BRO. The business relationship officer provides the missing context the IR team lacks: how the systems are connected, what data flows exist, what contractual obligations apply. This is the step where the IR team discovers whether a particular software service was used to process customer data and whether notification obligations are therefore triggered.
  1. The Supply Chain Risk Management (STRM) Committee is invoked for P1 and P2 incidents. This is a standing cross-functional body — not convened ad hoc — comprising representatives from procurement, legal, compliance, a business unit leader, the CISO, IT, IR, and business continuity. When containment controls could impact business operations, this committee reviews the remediation plan, accepts the risk, and provides explicit sign-off before the IR team acts.

The rationale for the committee structure is accountability. Containment decisions — "should we cut connectivity to this vendor?" — have financial, operational, and reputational consequences that should not rest on a single incident responder's shoulders. The committee provides both the breadth of expertise and the organizational authority to make those calls cleanly, with documented sign-off that protects everyone involved.

Criteria for Containment and Risk-Based Decisions

▶ Watch: Containment strategy, risk acceptance, and business impact criteria (31:10)

Puramwar outlined the factors the STRM committee weighs when deciding whether to disconnect from a supplier, apply compensating controls, or continue monitoring:

  • Business impact: Would disconnection cause revenue loss? Which business operations depend on this supplier? Is there a backup option?
  • Financial impact: What is the estimated cost of breach exposure versus the cost of service disruption?
  • Regulatory and legal exposure: Do reporting requirements mandate action within a specific timeframe?
  • Reputational impact: Is there media interest in this incident? Could inaction become a public story?

For lower-severity incidents (P3 through P5), the STRM committee is not convened. The IR team monitors, applies compensating controls if warranted, and tracks vendor remediation progress. The escalation threshold is designed to concentrate governance energy where the business stakes are highest.

She also addressed the common scenario where suppliers simply do not respond during their own incident. In those cases, the STRM committee can make containment decisions based on available threat intelligence and internal analysis — the committee's authority does not depend on supplier cooperation.

Recovery and the Feedback Loop

After an incident is resolved, Puramwar was emphatic about one step that organizations routinely skip: formal communication to business stakeholders when containment controls are removed. In multiple cases she observed, stakeholders had been told to stop using a service, received no follow-up communication, and continued not using it for months after the incident had been resolved — simply because no one had closed the loop. The feedback loop is not administrative overhead; it builds the trust that makes future incident response faster.

Notable Quotes

"It shouldn't happen that we wanted to do a communication but we don't know who is responsible for what. Develop the runbook accounting all of these things." — Kasturi Puramwar (▶ 22:15)

"Containment decisions cannot be left to one incident responder. If it is going to impact business operations, it has to be a committee." — Kasturi Puramwar (▶ 29:40)

"Strengthening the supplier relationship is a two-way street. If something happens on our side, we are going to be timely informing you." — Kasturi Puramwar (▶ 11:00)

Key Takeaways

  • IR teams cannot manage third-party incidents alone. Supply chain management, TPRM, legal, and the IR team each own distinct capabilities; the framework only works when all four are integrated in advance.
  • The business relationship officer is the missing link. BROs assigned to each critical supplier provide the access, context, and supplier relationships that IR teams need but rarely have directly.
  • Proactive SLAs in contracts reduce incident response time. Negotiating notification timelines, data impact reporting requirements, and breach definitions at onboarding removes ambiguity when it matters most.
  • A formal STRM committee depersonalizes high-stakes containment decisions. When a decision could cost the business revenue, having a cross-functional body with explicit sign-off authority protects the IR team and produces better outcomes.
  • Close the loop after recovery. Informing stakeholders when containment controls are lifted is not optional — it builds the organizational trust that makes future collaboration faster.

Reviews

Dr. Zero (Offensive Security Researcher) — SOLID

Methodical and complete cross-functional IR framework for third-party incidents. The Supply Chain Risk Management Committee structure for P1/P2 containment decisions is the most useful specific idea. Heavy on process diagrams, light on things that would surprise a senior IR practitioner.

Heather Calloway (CISO) — STRONG ACCEPT

Puramwar describes the organizational architecture that makes third-party incident response function rather than collapse — cross-functional preparation, standing governance committees, contractual SLAs established before incidents occur. The Supply Chain Risk Management Committee model addresses a problem most IR teams have encountered and haven't solved.

→ Top-rated talks at BSidesSF 2025 — Here Be Dragons

All talks from BSidesSF 2025 — Here Be Dragons