Ask a business owner to list their security risks and they’ll describe their own systems: their computers, their server, their email. Almost nobody mentions the accounting platform, the marketing agency with admin access to the website, or the IT tool that updates itself automatically overnight. Attackers noticed that blind spot a while ago.

The trend line is stark. IBM’s X-Force team reports that major supply chain and third-party breaches have quadrupled over the past five years, and it has become one of the defining attack patterns of 2026. The logic from the attacker’s side is pure efficiency: why breach a thousand companies one at a time when compromising a single trusted software provider or service firm delivers access to all of its customers at once?

Trust is transitive, and so is compromise

Recent incidents made the pattern plain. Attackers compromised authorization tokens at one software vendor and used that trusted connection to walk into the customer environments of hundreds of downstream companies. Nobody at those companies clicked anything. Their own defences were never tested. The breach arrived through a connection they had approved, from a supplier they had every reason to trust.

Every integration your business runs works the same way. The app connected to your Microsoft 365. The bookkeeper with remote access. The website plugin that updates silently. Each one is a door, and you are trusting someone else’s security team, which may not exist, to guard it.

The part small businesses miss: you’re the vendor too

Here’s the angle that gets overlooked. If you serve larger clients, you are somebody’s supply chain risk. Law firms, manufacturers, and finance companies are now sending security questionnaires to their suppliers, asking pointed questions about MFA, backups, incident response, and insurance. We’ve watched businesses lose contracts they’d held for years, not because their work slipped, but because they couldn’t answer.

This cuts both ways, and one direction is an opportunity. The small firm that can demonstrate real security controls stands out in a bidding process against competitors who go quiet when the questionnaire arrives. Security has become a sales asset, which is a sentence we could not have written ten years ago.

What reasonable diligence looks like

Nobody expects a thirty-person company to audit Microsoft. The standard we hold clients to is proportionate. Keep an inventory of every vendor and application with access to your systems or data, because you cannot manage doors you haven’t counted. Grant the least access each vendor actually needs, and remove it the day the relationship ends. Ask your critical vendors the same questions your clients will ask you. Prefer suppliers who can show their homework. And make sure your monitoring watches third-party connections, not just your own users, because the next unusual login may come through a partner.

The perimeter of your business stopped being your office wall a long time ago. In 2026 it isn’t even your own network. It’s the sum of everyone you’ve decided to trust. Choose deliberately, check occasionally, and be the vendor on the list that gives your clients no reason to worry.