The questionnaire was never the risk assessment
Most vendor risk programs run on the same mechanism: a security questionnaire, sent annually or at onboarding, asking a supplier to self-report its controls. The supplier’s security team fills it out, often reusing answers from the last version with light edits, and the responses get filed as evidence of due diligence. This process satisfies an audit requirement. It does not tell you much about the supplier’s actual exposure on the day you read the answers, or on any day after.
A questionnaire is a snapshot of what a vendor says about its intentions, captured at a single point in time, through a process the vendor controls end to end. It says nothing about a staging server the vendor’s engineering team spun up last month, an expired certificate on a customer-facing login page, or a database left open by a configuration change nobody reviewed. Those are the things that actually get exploited, and none of them show up in a questionnaire response.
Why the gap matters more than it used to
Third-party risk has grown in proportion to how deeply integrated vendors have become. Modern supply chains involve SaaS platforms with standing access to corporate data, managed service providers with credentials into internal systems, and software dependencies pulled in from external repositories. A compromise anywhere in that chain can become a compromise of the organisation itself, and the organisation frequently has no visibility into the vendor’s security posture beyond what the vendor chooses to disclose.
This dynamic has played out repeatedly across major incidents where the initial point of compromise was not the target organisation at all, but a supplier several steps removed from it. In each case, the affected organisation had a vendor risk process in place. What it lacked was current, external visibility into the specific systems that were actually vulnerable.
What external assessment actually looks at
An external assessment of a supplier does not require any cooperation from the supplier, and that is precisely its value — it evaluates what is actually reachable from the outside, which is the same vantage point an attacker would use. This includes the supplier’s exposed infrastructure: subdomains, open ports, exposed admin interfaces, and certificates nearing expiry. It includes signals of hygiene, such as whether known vulnerabilities in internet-facing software have been patched within a reasonable window, and whether email authentication is configured correctly enough to resist domain spoofing. And it includes exposure signals that predate any formal assessment, such as whether credentials tied to the supplier’s domain have already surfaced in breach data.
None of this requires the supplier to answer a single question. It can be assessed continuously, updated automatically as the supplier’s external footprint changes, and compared over time to see whether a vendor’s posture is improving or degrading — something a once-a-year questionnaire structurally cannot show.
Where this fits alongside the questionnaire
External assessment is not a replacement for the questionnaire process; it is a correction to its biggest weakness, which is that it only measures what the vendor is willing to report. Used together, the two approaches cover different failure modes. The questionnaire captures policy and process — whether the vendor has an incident response plan, whether staff receive security training, whether data is encrypted at rest. External assessment captures execution — whether those policies are actually reflected in what is deployed and reachable right now.
A vendor can score well on a questionnaire and still be running an exposed staging environment with a known critical vulnerability, because the questionnaire was never designed to catch that. External assessment closes exactly that gap, and it does so without adding to the vendor’s workload or waiting on their next response cycle.
Making it operational
The practical starting point is prioritisation, not universal coverage. Rank suppliers by the depth of access they have — a payroll processor with access to employee financial data warrants a different level of scrutiny than a vendor providing office supplies — and apply continuous external assessment first to the tier with the deepest access or the broadest data exposure.
From there, the assessment becomes an ongoing input rather than a point-in-time exercise: a rising number of exposed assets, a newly unpatched critical vulnerability, or fresh credential exposure tied to a supplier’s domain should trigger a conversation well before the next scheduled review. Vendor risk managed this way stops being a compliance artifact filed once a year, and starts functioning as what it was always meant to be — an accurate, current picture of where your risk actually extends beyond your own perimeter.
Written by Jamal Hashi, CyberPost Advisory.