Knowledge / practitioner au-compliance hardening

Third-party and supply chain

You can outsource the work. You cannot outsource the risk. Cloud shared responsibility, IRAP evidence, and ISM procurement sit on the same desk as the incident.

ASD's cloud shared-responsibility guidance for executives is the sentence boards skip: you always keep some responsibilities, and you carry the risk to your data's confidentiality, integrity, and availability. A compromise can still be your financial, reputational, and legal problem. A contract that says 'the CSP is secure' does not move that.

The same logic applies to managed service providers, CI/CD, RMM consoles, and the database operator behind a booking brand. If a third party holds the data or the admin plane, their vulnerability is an access path into you. Quest Apartment Hotels' 2026 statement described unauthorised access arising from a vulnerability through a third-party service provider. That is the pattern, not a one-off.

ISM procurement and outsourcing controls expect IRAP assessment of outsourced cloud and managed services on a cycle, and they expect you to understand residual risk. ACSC's cloud FAQ: ask for the IRAP assessment including detailed residual risks; international certificates are not a substitute for ISM alignment. Visibility of subcontractors is part of the shared-responsibility test — 'we use a hoster' is not a threat model.

On the desk: inventory who can touch identity, backups, and personal information. Write the shared-responsibility split before the incident, not during it. Put NDB and, if you are in, SOCI reporting in the same runbook as the vendor's status page. When the third party is breached, your clock still starts.

Fact source: ACSC, cloud shared responsibility (executive guidance).