Knowledge / practitioner au-compliance hardening

Third-party and supply chain

You can outsource the work. You cannot outsource the risk. Cloud shared responsibility, IRAP evidence, and ISM procurement sit on the same desk as the incident.

ASD's cloud shared-responsibility guidance for executives is the sentence boards skip: you always keep some responsibilities, and you carry the risk to your data's confidentiality, integrity, and availability. A compromise can still be your financial, reputational, and legal problem. A contract that says 'the CSP is secure' does not move that.

The same logic applies to managed service providers, CI/CD, RMM consoles, and the database operator behind a booking brand. If a third party holds the data or the admin plane, their vulnerability is an access path into you. Quest Apartment Hotels' 2026 statement described unauthorised access arising from a vulnerability through a third-party service provider. That is the pattern, not a one-off.

ISM procurement and outsourcing controls expect IRAP assessment of outsourced cloud and managed services on a cycle, and they expect you to understand residual risk. ACSC's cloud FAQ: ask for the IRAP assessment including detailed residual risks; international certificates are not a substitute for ISM alignment. Visibility of subcontractors is part of the shared-responsibility test — 'we use a hoster' is not a threat model.

Open-source is a supply chain too. The AFP, with WAPF and the FBI, charged two West Australian men on 26 August 2026 over an alleged syndicate that inserted malicious code into software on a public repository, then let other developers pull it in. Police put the impact at more than 1,000 organisations globally, more than 500,000 credentials, and at least 300 GB of data, with remediation costs in the hundreds of millions of dollars. The FBI statement in that release names the group TeamPCP. Inventory direct dependencies, CI tokens, and who can publish to the registries you consume. A pin to a version is not a review of the maintainer.

On the desk: inventory who can touch identity, backups, and personal information. Write the shared-responsibility split before the incident, not during it. Put NDB and, if you are in, SOCI reporting in the same runbook as the vendor's status page. When the third party is breached, your clock still starts.

Fact source: ACSC, cloud shared responsibility (executive guidance).