What Leverage Cyber Maps
Third-party risk analysis builds a structured picture of your extended attack surface across four relationship categories:- Subsidiary and acquisition domains — every domain and hostname associated with entities your organization owns, operates, or acquired, assessed independently for their exposure profile and scored against your primary organization’s security baseline
- Key technology vendors — hosting providers, identity management platforms, payment processors, cloud infrastructure providers, and other vendors whose systems process your data or whose compromise would create a direct path to your environment
- Partner portals and API integrations — externally accessible portals, API endpoints, and integration touchpoints that your organization has established with business partners, assessed for authentication strength, exposure, and credential risk
- Board and executive cross-entity relationships — where executives or board members serve roles across multiple organizations, Leverage Cyber identifies shared identity infrastructure that could create lateral exposure between entities
The Third-Party Attack Chain
Sophisticated attackers routinely use weaker entities in a corporate ecosystem as a stepping stone to reach higher-value targets. This approach is effective because it sidesteps the strong perimeter controls that large organizations invest heavily in, in favor of connected entities that receive far less security investment. A realistic attack scenario unfolds as follows:- An attacker identifies your organization as their target but finds your primary perimeter well-defended.
- Passive reconnaissance reveals a subsidiary operating under a separate brand — a recent acquisition with its own domain, its own email infrastructure, and its own IT team.
- The subsidiary’s DMARC policy is set to
p=none, and its VPN login portal is exposed on a subdomain. - Breach data shows two employees of the subsidiary — including one with IT administrator access — had credentials exposed in a third-party SaaS breach.
- The attacker credential-stuffs the VPN portal using the breached credentials and gains authenticated access to the subsidiary’s internal network.
- From inside the subsidiary’s network, the attacker moves laterally through a trust relationship to your primary environment — a site-to-site VPN or shared Active Directory federation that exists specifically because the entity was acquired.
- The breach is ultimately attributed to your primary organization because the data exfiltrated carries your customer records.
Reading Third-Party Findings
Each third-party finding in your report includes the following fields:
Findings are sorted by the severity of the connection to your primary organization. An exposed service at a subsidiary with a site-to-site VPN trust ranks higher than the same finding at a vendor with only outbound data export access.
Common Third-Party Risks
Recently acquired company with unpatched systems
Recently acquired company with unpatched systems
Acquisition timelines rarely allow for a complete security assessment and remediation cycle before integration work begins. The result is that the acquired entity’s systems — running their own patch cadence, their own endpoint controls, and their own monitoring — are connected to the parent organization’s environment before the parent’s security standards have been applied. Leverage Cyber identifies specific unpatched or end-of-life services visible on the acquired entity’s external footprint and flags them in the context of any integration touchpoints established with the parent.
Partner with exposed API keys referencing your systems
Partner with exposed API keys referencing your systems
API keys that reference your organization’s systems — issued to partners for integration purposes — occasionally appear in public code repositories, paste sites, or breach compilations when partner-side developers mishandle secrets. If an attacker obtains a valid API key issued to one of your partners, they can interact with your systems under that partner’s authorized identity. Leverage Cyber monitors for exposed credentials and API keys that reference your organization’s domains and API endpoints, regardless of which organization they were originally issued to.
Subsidiary with no DMARC (enables parent domain spoofing)
Subsidiary with no DMARC (enables parent domain spoofing)
A subsidiary operating without a DMARC enforcement policy creates brand spoofing risk that extends to the parent organization. Attackers exploit subsidiaries with weak email authentication to send phishing campaigns that impersonate the parent company — using the subsidiary’s domain in routing headers while displaying the parent’s brand name in the visible
From field. Recipients, and many email security tools, see an email that appears to come from your organization when the actual authentication failure is occurring on a domain managed by a separate team. Leverage Cyber surfaces email security gaps at subsidiary domains with the same depth of analysis applied to your primary domains.M&A due diligence is one of the highest-value use cases for Leverage Cyber’s third-party risk module. Before a deal closes, you can commission an external assessment of the acquisition target’s attack surface — covering domains, email security, breach exposure, shadow IT, and their own third-party relationships — using only publicly available data that requires no access to the target’s systems or cooperation from their security team. Understanding the security debt you are acquiring before the transaction is signed fundamentally changes your negotiating position and your post-close integration planning. Contact your Leverage Cyber account team to initiate a pre-acquisition assessment.