> ## Documentation Index
> Fetch the complete documentation index at: https://docs.leveragecyber.io/llms.txt
> Use this file to discover all available pages before exploring further.

# Third-Party Risk: Subsidiaries, Partners, and Supply Chain

> How Leverage Cyber maps subsidiaries, acquired entities, technology vendors, and partners whose security exposure extends directly to your attack surface.

Your attack surface does not end at your primary domain. It extends to every company connected to yours — subsidiaries operating under their own brands, entities acquired in the past three years and only partially integrated, SaaS vendors whose compromise would give an attacker access to your data, and technology partners whose systems communicate with yours daily. Attackers exploit these relationships deliberately, targeting the weakest link in a corporate ecosystem to reach the most valuable one. Leverage Cyber maps the full constellation of entities around your organization and assesses each one using the same passive reconnaissance methodology applied to your primary footprint.

## What Leverage Cyber Maps

Third-party risk analysis builds a structured picture of your extended attack surface across four relationship categories:

* **Subsidiary and acquisition domains** — every domain and hostname associated with entities your organization owns, operates, or acquired, assessed independently for their exposure profile and scored against your primary organization's security baseline
* **Key technology vendors** — hosting providers, identity management platforms, payment processors, cloud infrastructure providers, and other vendors whose systems process your data or whose compromise would create a direct path to your environment
* **Partner portals and API integrations** — externally accessible portals, API endpoints, and integration touchpoints that your organization has established with business partners, assessed for authentication strength, exposure, and credential risk
* **Board and executive cross-entity relationships** — where executives or board members serve roles across multiple organizations, Leverage Cyber identifies shared identity infrastructure that could create lateral exposure between entities

Each third-party entity in your report is mapped to its relationship type, its connection to your primary organization, and the specific findings that create risk for you — not just risk for them.

## The Third-Party Attack Chain

Sophisticated attackers routinely use weaker entities in a corporate ecosystem as a stepping stone to reach higher-value targets. This approach is effective because it sidesteps the strong perimeter controls that large organizations invest heavily in, in favor of connected entities that receive far less security investment. A realistic attack scenario unfolds as follows:

1. An attacker identifies your organization as their target but finds your primary perimeter well-defended.
2. Passive reconnaissance reveals a subsidiary operating under a separate brand — a recent acquisition with its own domain, its own email infrastructure, and its own IT team.
3. The subsidiary's DMARC policy is set to `p=none`, and its VPN login portal is exposed on a subdomain.
4. Breach data shows two employees of the subsidiary — including one with IT administrator access — had credentials exposed in a third-party SaaS breach.
5. The attacker credential-stuffs the VPN portal using the breached credentials and gains authenticated access to the subsidiary's internal network.
6. From inside the subsidiary's network, the attacker moves laterally through a trust relationship to your primary environment — a site-to-site VPN or shared Active Directory federation that exists specifically because the entity was acquired.
7. The breach is ultimately attributed to your primary organization because the data exfiltrated carries your customer records.

This is not a hypothetical scenario. Supply chain and subsidiary-pivot attacks account for a significant and growing share of enterprise breach incidents. Leverage Cyber surfaces the conditions that make this chain possible before an attacker can execute it.

## Reading Third-Party Findings

Each third-party finding in your report includes the following fields:

| Field                     | Description                                                                                                                                                                                             |
| ------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| **Entity Name**           | The name of the third-party organization — subsidiary brand name, vendor name, or partner organization                                                                                                  |
| **Relationship Type**     | How the entity connects to your organization: `Subsidiary`, `Acquired Entity`, `Technology Vendor`, `Business Partner`, or `Executive-Linked Entity`                                                    |
| **Exposure Type**         | The specific risk category identified: `Credential Exposure`, `Email Spoofing Risk`, `Exposed Service`, `Misconfigured Integration`, or `Vulnerable Asset`                                              |
| **Connection to Primary** | The mechanism by which this entity's exposure creates risk for your primary organization — e.g., shared identity federation, inbound API access, domain trust relationship, or customer data processing |

Findings are sorted by the severity of the connection to your primary organization. An exposed service at a subsidiary with a site-to-site VPN trust ranks higher than the same finding at a vendor with only outbound data export access.

## Common Third-Party Risks

<Accordion title="Recently acquired company with unpatched systems">
  Acquisition timelines rarely allow for a complete security assessment and remediation cycle before integration work begins. The result is that the acquired entity's systems — running their own patch cadence, their own endpoint controls, and their own monitoring — are connected to the parent organization's environment before the parent's security standards have been applied. Leverage Cyber identifies specific unpatched or end-of-life services visible on the acquired entity's external footprint and flags them in the context of any integration touchpoints established with the parent.
</Accordion>

<Accordion title="Vendor portal using shared or default credentials">
  Partner and vendor portals — extranet sites, supplier dashboards, and integration management consoles — frequently use shared login credentials distributed to multiple users at the partner organization. Shared credentials cannot be revoked for individual users, are rarely rotated, and often appear in breach data because one of the many people who held the credential used it on another service that was subsequently breached. Leverage Cyber identifies vendor portal exposure and correlates it against breach data to flag cases where a shared credential is likely compromised.
</Accordion>

<Accordion title="Partner with exposed API keys referencing your systems">
  API keys that reference your organization's systems — issued to partners for integration purposes — occasionally appear in public code repositories, paste sites, or breach compilations when partner-side developers mishandle secrets. If an attacker obtains a valid API key issued to one of your partners, they can interact with your systems under that partner's authorized identity. Leverage Cyber monitors for exposed credentials and API keys that reference your organization's domains and API endpoints, regardless of which organization they were originally issued to.
</Accordion>

<Accordion title="Subsidiary with no DMARC (enables parent domain spoofing)">
  A subsidiary operating without a DMARC enforcement policy creates brand spoofing risk that extends to the parent organization. Attackers exploit subsidiaries with weak email authentication to send phishing campaigns that impersonate the parent company — using the subsidiary's domain in routing headers while displaying the parent's brand name in the visible `From` field. Recipients, and many email security tools, see an email that appears to come from your organization when the actual authentication failure is occurring on a domain managed by a separate team. Leverage Cyber surfaces email security gaps at subsidiary domains with the same depth of analysis applied to your primary domains.
</Accordion>

<Note>
  M\&A due diligence is one of the highest-value use cases for Leverage Cyber's third-party risk module. Before a deal closes, you can commission an external assessment of the acquisition target's attack surface — covering domains, email security, breach exposure, shadow IT, and their own third-party relationships — using only publicly available data that requires no access to the target's systems or cooperation from their security team. Understanding the security debt you are acquiring before the transaction is signed fundamentally changes your negotiating position and your post-close integration planning. Contact your Leverage Cyber account team to initiate a pre-acquisition assessment.
</Note>
