A third-party platform supporting tax services was compromised — a clear reminder that your security perimeter extends to every vendor with access to your data.
Days ago, EY announced a security breach that occurred through a third-party platform used to support tax services provided to clients. Attackers accessed the system between 28 March and 12 April 2026 and downloaded documents containing sensitive personal and financial data belonging to a number of the firm's clients — before the breach was discovered several weeks later.
This is precisely why Third-Party Risk Assessment must happen before connecting or integrating with any external party — and why ongoing monitoring after onboarding is non-negotiable. In the financial sector especially, frameworks such as SAMA CSF and NCA ECC controls exist for a reason: risk does not stop at the organization's own boundary. It extends to every third party with access to its data or systems.
What a third-party security assessment should cover
- Cyber maturity: Does the provider have an effective information-security program, documented policies and clear incident-management processes — or only certificates without real application?
- Certifications and attestations: ISO 27001 and SOC 2 Type II are positive signals, but never enough alone. Confirm that the certificate scope actually covers the service or system you will use.
- Independent external assessments: Reports from neutral parties give a more objective picture than vendor self-assessments.
- Penetration testing & vulnerability assessment: An old report is not enough. Tests should be periodic, critical findings closed, and retests should prove remediation.
- Periodic review: Assessment cannot stop at contracting. Review frequency should reflect service nature, data sensitivity and access rights granted. The more sensitive the data — or the deeper the integration — the more frequent the reviews must be.
Bottom line
An organization may have a strong internal security posture and still be breached through the weakest link in its supply chain. Third-party risk assessment is not a compliance formality — it is a core line of defense for data, systems and business continuity.

