Your company may have the best firewall on the market and still suffer a data breach without anyone ever having accessed your network. All it takes is for one of your vendors to have exposed credentials or a misconfigured server.
This is, in essence, the risk of the digital supply chain—that is, the exposure you inherit from every application, cloud service, or integration you connect to your business, even if you don’t manage it directly.
What exactly is digital supply chain risk?
When we talk about digital supply chain risk, we’re referring to the vulnerabilities that enter your organization through third parties such as the invoicing software your finance department uses, the CRM where you upload customer data, or the logistics provider that has access to your ERP. Each of these points is a gateway that you don’t control, but for which you are held accountable.
This isn’t a new problem, but in the past, a company typically had five or six critical suppliers. Today, with software as a service, APIs, and outsourcing, the list easily exceeds a hundred, and a large portion of it isn’t even tracked.
Why a Supplier’s Shortfall Becomes Your Problem
Here’s the nuance that many companies overlook: legally—and in the eyes of your customers—it almost never matters who made the mistake, but rather who is ultimately responsible for the data. And we’re not just talking about a financial penalty, but also the reputational damage that will follow the company.
According to an analysis by Cipher (Supply Chain Attacks: 2025 Analysis and 2026 Trends), by 2025, 22.5% of all reported security breaches involved a supplier or third party—twice as many as the previous year. And yet, most organizations continue to assess their cybersecurity solely from the inside.
The Most Common Blind Spots in Your Supply Chain
Most third-party security breaches result from oversights that build up over time and that no one stops to review:
- Subdomains and Forgotten Assets: test environments or old websites that are still active and unpatched.
- Leaked credentials: employee or vendor passwords circulating on the deep web following a third-party breach.
- Unreviewed third-party access: integrations and permissions granted once and never audited.
- Shadow IT: applications that a team procures without going through the IT department.
- Mentions on underground forums: Information about your company circulating on the dark web without your knowledge.
Any of these points can become the source of an incident if no one monitors them constantly.
From the Annual Audit to the CTEM Approach
For years, the standard response to this risk was one-time on an ad hoc basis or vendor audit once a year. The problem is that months can pass between reviews, during which the attack surface can change completely.
| Focus | Frequency | What it detects | Main limitation |
| Annual Audit
|
On time, once a year | Snapshot of the security status | Outdated within weeks |
| Periodic Penetration Testing
|
Every 6–12 months | Known technical vulnerabilities | Does not cover third parties or new assets |
| CTEM (Continuous Threat Exposure Management)
|
Continuous | Actual exposure, compromised credentials, forgotten assets, vendor risk | Requires a specialized tool |
CTEM (Continuous Threat Exposure Management) is based on a different concept: cybersecurity isn’t a test you pass once a year; it’s a process that must be monitored every day. Instead of waiting for the next audit, the goal is to have constant visibility into what is at risk, where, and how urgently action is needed.
This is where Enthec comes in, with its cyber-surveillance solutions designed specifically for this approach. Kartos, its enterprise platform, continuously monitors an organization’s exposed digital footprint and that of its critical suppliers. It detects leaked credentials, forgotten domains, and mentions on underground forums before they turn into an incident.
For those who manage their own exhibitions as professionals or freelancers, Enthec also offers Qondar, designed to monitor digital identity on an individual level.
What Your Company Can Do Starting Today
There’s no need for a radical change overnight, but it’s a good idea to start moving in this direction:
- Take a real inventory of your critical suppliers and what data or access each one has.
- Ask those vendors what security controls they implement and whether they are willing to share that information.
- Replace one-time reviews with continuous monitoring of your company’s and your value chain’s exposure.
- Prioritize based on impact, because not all suppliers require the same level of scrutiny.
Frequently Asked Questions
What is the difference between third-party risk and digital supply chain risk?
Third-party risk focuses on each individual supplier—their controls, certifications, track record, and so on. Digital supply chain risk is broader; it encompasses the entire network of technological dependencies through which an incident can spread.
How is the risk of a digital supplier measured?
It combines public information—such as exposed domains, leaked credentials, or reputation—with security questionnaires and, when possible, continuous monitoring of its exposure surface using cyber-surveillance tools.
Does CTEM replace penetration testing?
No, it complements it. Penetration testing remains useful for testing specific controls at a given time. The CTEM provides continuous monitoring between those one-off tests.
What size of company needs to monitor its digital supply chain?
Any company that relies on external suppliers to operate—which, these days, is practically any company with an online presence, regardless of its size.
If you want to know how much exposure your company and your critical suppliers have today, you can request a Kartos demo and see firsthand what it finds in your digital landscape.


