Risk no longer stops at your perimeter. It lives in your suppliers, your cloud providers and the small vendor with a standing connection to your network. Supply-chain exposure has quietly become one of the most material — and least governed — risks African enterprises carry, and the gap between how serious it is and how seriously it is managed keeps widening.
Most organisations have spent a decade hardening their own controls. Far fewer have extended that scrutiny to the third parties operating inside them, even though those third parties now hold data, hold access, and hold the power to interrupt operations.
You inherit your suppliers' weaknesses
Every integration is a trust relationship, and every trust relationship is an attack surface. A supplier with weak controls is, in practice, your weak control — their compromise becomes your incident, their breach your breach, their downtime your downtime. Boards that scrutinise their own posture often have no view at all of the third parties operating inside their walls, sometimes with privileged and persistent access.
The exposure is rarely the marquee vendor with a mature security programme. More often it is the long tail — the small, embedded supplier nobody risk-assessed, connected years ago for a reason nobody remembers, still holding a key to a door that matters.
Govern access by exposure, not by habit
The discipline that closes this gap is unglamorous and effective: know who your third parties are, what they can reach, and how much it would hurt if they failed. From there, scrutiny can be tiered to exposure rather than spread evenly and thinly across everyone.
- A live inventory of third parties and exactly what each can access
- Risk-tiering so the depth of scrutiny matches the scale of exposure
- Contractual security and POPIA obligations that actually bite
- Continuous monitoring, not point-in-time questionnaires filed and forgotten
A board issue, not a procurement footnote
Supply-chain risk has outgrown the procurement function that historically owned it. Under POPIA, accountability for personal information does not transfer with the processing — the organisation remains answerable for what its operators do with the data it entrusts to them. That alone moves the question from the contract file to the board agenda.
You can outsource the service. You cannot outsource the risk.
Make it someone's number
What changes outcomes is ownership. Supply-chain risk that belongs to everyone belongs to no one; supply-chain risk with a named owner, a budget and a metric gets managed. The organisations that have taken this seriously can answer, on demand, how many third parties hold sensitive access, how those parties are tiered, and what is being done about the ones that matter most.
Treating supply-chain risk as a procurement footnote is no longer defensible — to a regulator, to a board, or to the customers whose data sits with parties they have never heard of. It belongs on the board agenda, with an owner, a budget and a number attached.



