TL;DR

Current advisories show attackers succeeding in the layer you do not control: government and industry sources report exploitation of network devices, unpatched Microsoft Exchange servers, and abused PaperCut zero-days. That makes supplier security a contract-evidence problem, not a questionnaire problem. The matrix below turns each fact into the vendor question to ask, the clause to negotiate, and the dated artifact to demand.

What changed

Three source-backed facts define the current third-party picture:

lilMONSTER has not scanned, tested, or observed any of these environments. Every claim above belongs to the cited sources.

Why it matters for business trust

Insurers, customers running tenders, auditors, and boards increasingly ask not "do you have a vendor policy?" but "show me the evidence your suppliers patch." These facts change specific decisions:

  • The ACSC advisory changes who you hold accountable for edge devices. If a supplier or MSP administers your firewalls and VPNs, the advisory moves patch accountability from implicit to contractual.
  • The Exchange number changes how you read questionnaire answers. A supplier ticking "we patch promptly" is indistinguishable from the organisations behind those 22,000 servers; only dated patch evidence distinguishes you from the tail.
  • The PaperCut case changes your application inventory scope. Data theft via print management software shows that low-visibility vendor applications — not just flagship platforms — carry breach-relevant risk that customers and insurers will ask about after an incident.

The common failure is a point-in-time assessment: a signed questionnaire captures intent on one day and proves nothing about the week a zero-day lands.

Evidence to produce now

Third-Party Evidence Request Matrix — use one row per supplier per relevant trigger:

Trigger (source) Vendor question to ask Contract control to write Evidence to request (artifact)
Network-device exploitation advisory (ASD ACSC) Who administers our internet-facing network devices, and what is your patch SLA for critical government advisories? Named obligation: acknowledge and patch critical advisories within an agreed window; notify us of exposure Asset list naming your edge devices; the admin of record; dated change tickets for the last critical advisory
Zero-day exploitation of vendor applications (PaperCut, BleepingComputer) Which third-party applications in your environment hold or touch our data, and how will you notify us of vendor security updates? Notification clause: advise affected customers of vendor security updates within an agreed number of business days Application inventory with versions for your instances; a sample dated update notification; the patch ticket for the most recent vendor fix
Unpatched exposed systems (Exchange, BleepingComputer) What proves our systems or your shared platforms are not part of the unpatched tail? Periodic exposure attestation backed by patch completion reports against named advisories Current version/build report for internet-facing and shared systems; patch completion report mapped to the specific advisory

30-minute review procedure: (1) List your top ten suppliers and mark who administers edge devices or shared applications. (2) Send the matching matrix row as an evidence request, not a questionnaire. (3) Record who returned dated artifacts versus policy statements — that split is your real supplier risk register. This procedure is lilMONSTER's original contribution; it is a review exercise, not a test of any supplier system.

FAQ

Doesn't a SOC 2 report or certification cover this? No. Certifications attest to control design at a point in time. They do not evidence that a specific advisory — the ACSC device campaign or the PaperCut zero-day — was actioned on your instances within days.

What if a supplier refuses to provide patch evidence? Treat refusal as a data point, not a dead end: record it, apply risk acceptance at the right management level, and make evidence delivery a contract renewal condition.

We're mostly cloud-hosted — does this apply? Partly. Cloud shifts responsibility but does not remove it: SaaS suppliers still run applications that get zero-days (the PaperCut pattern), and someone still administers the edge devices your traffic crosses (the ACSC pattern). The matrix rows just point at different suppliers.

How fast should a contract patch SLA be? That is your negotiation, informed by how quickly exploitation follows disclosure — the PaperCut case shows abuse of zero-days before and after patching, per BleepingComputer. Set windows you can verify with dated tickets.

Conclusion

The strongest position this quarter is not a better questionnaire — it is three timed, evidence-backed obligations with your critical suppliers: named edge-device accountability with patch tickets, an application inventory with update notifications, and exposure attestations backed by version reports. Run the 30-minute review, send the matrix rows, and file the artifacts where your insurer, auditor, and next tender can reach them. If you want help drafting the evidence requests and contract clauses for your supplier list, book a consultation at https://consult.lil.business/ — scoping, access, and rules of engagement are agreed in writing before anything touches a live system.

References

  1. Joint advisory on the exploitation of network devices by Russian state-sponsored cyber actors — ASD ACSC
  2. Nearly 22,000 Microsoft Exchange servers vulnerable to hijack attacks — BleepingComputer
  3. Recently patched PaperCut zero-days used in data theft attacks — BleepingComputer