The recent cyberattack on UK multinational retailer Marks & Spencer (M&S) has once again highlighted the urgent need for organizations to reassess how they manage third-party access. As investigators continue to examine the breach, early indications suggest it originated through a third-party IT provider whose credentials were compromised using social engineering tactics. The financial fallout is already estimated at a minimum of £300M ($405M). The reputational cost is harder to measure but equally significant.
This incident adds to a growing list of supply-chain attacks in the past decade, including Target in 2013, NotPetya in 2017, SolarWinds in 2020, Kaseya in 2021, and MOVEit in 2023. The common thread across these breaches is the exploitation of weak third-party access controls. Organizations can no longer afford to overlook the cybersecurity posture of external partners, contractors, and vendors. These actors often enjoy high levels of access to internal systems but without the appropriate access controls.
What makes third-party access so dangerous is the expanded attack surface. Every vendor added to an ecosystem increases the number of access points into internal systems. Many of these partners require access to sensitive data or applications, yet lack adequate protection measures such as multifactor authentication (MFA), strong password hygiene, or network segmentation. Attackers understand this and routinely target weaker links as entry points to gain access to better-protected environments.
The reality is that excessive and persistent third-party access is still common. Too often, contractors retain access after projects are completed, or employment is terminated. Without strict controls and automated de-provisioning, organizations are exposed to avoidable risks. Moreover, compromised credentials continue to be a leading cause of data breaches, as seen not only with M&S, but also recent incidents involving the London Metropolitan Police and Cloudflare.
Many organizations also lack continuous monitoring of third-party sessions. Without detailed logs and anomaly detection, malicious activities can go unnoticed for weeks. Add to this the fact that third-party onboarding is frequently rushed without thorough risk assessment, and it becomes clear why supply-chain attacks remain a popular strategy for cybercriminals.
Regulators have taken notice. Laws and frameworks like the EU’s Digital Operational Resilience Act (DORA), Australia’s Prudential Standard on Operational Risk Management (CPS 230), and the US Department of Defense’s Cybersecurity Maturity Model Certification (CMMC), among others, are reshaping accountability. Each framework places explicit emphasis on third-party identity governance. They demand auditable, risk-based access controls and ongoing oversight. These are not theoretical recommendations. Compliance deadlines are here or rapidly approaching. Organizations can no longer afford to treat third-party IAM as a secondary concern. Failure to address it can result not only in data loss and service disruption, but also in regulatory fines and legal liability.
The attack on M&S reveals the real-world consequences of weak controls. Easter weekend services were disrupted, forensic investigations were launched, and questions about operational resilience were raised publicly. The suggestion that the attackers used social engineering to target the IT helpdesk of a third-party contractor shows how attackers exploit trust relationships in partner ecosystems.
If organizations want to protect themselves from the growing wave of supply chain attacks, they need to move beyond perimeter-based thinking. A modern third-party IAM strategy should incorporate identity lifecycle management, federated identity models, policy-based access, least-privilege enforcement, and real-time monitoring. Strong authentication must become non-negotiable for all users, including third parties.
At KuppingerCole, we recommend adopting the Identity Fabric approach. This model supports frictionless, governed access for all types of identities across modern business IT environments. It is modular, scalable, and designed for both human and non-human identities. By embedding Zero Trust principles into the Identity Fabric, organizations can ensure that no user or system is implicitly trusted, regardless of location or function.
The M&S CEO acknowledged that the company had invested in cyber tools over the past two years, which may have limited the impact. But clearly, even well-prepared organizations are vulnerable if third-party risks are not addressed comprehensively.
Now is the time to act. The cost of inaction is not just financial. It includes regulatory exposure, operational disruption, and erosion of customer trust. To avoid becoming the next cautionary tale, enterprises must elevate third-party access governance from an IT project to a board-level priority.
For expert guidance on strengthening third-party identity and access management, KuppingerCole’s Advisory Team is ready to help. When it comes to supply-chain attacks, preparation is the best defense.