How to secure collaboration with external stakeholders

  • Defence
  • Cyber
  • Cybersecurity

© Ercom-Illustrator

  • Type Insight
  • Published

Every modern business relies on external partners to thrive, yet these collaborations can open the door to significant cybersecurity risks. As attackers increasingly target vulnerable service providers or subcontractors to breach stronger defenses, protecting your organisation’s sensitive information becomes more complex. How can you foster seamless teamwork with external stakeholders without compromising security? Read on to discover the key challenges and essential strategies for safeguarding your business in today’s interconnected landscape.

Every business must collaborate daily with external stakeholders. But today, this collaboration is a risk factor: 35% of cybersecurity incidents in 2025 were linked to a third party. In large enterprises, incidents involving an external actor account for as much as 43% of cyberattacks with a significant impact.

The rise of this method is easy to explain: rather than attacking a well-protected organisation head-on, cybercriminals now prefer to target a more vulnerable service provider, supplier or subcontractor first, in order to reach their primary target.

CIOs and CISOs therefore face a new challenge: how can they secure exchanges with third parties without slowing down collaboration?

The actors in external collaboration

To manage the risks linked to external collaboration, it is first necessary to identify all the stakeholders your company interacts with. IT service providers work directly on your IT infrastructure and information system: they have significant access rights and are therefore a prime target. Your suppliers also play a crucial role, as they provide essential goods or services to your business and regularly exchange sensitive commercial or contractual information.

Your subcontractors handle part of your production or operations, sometimes with access to your internal tools. This also includes temporary contributors such as freelancers working for your organisation. Consulting firms or auditors may work on strategic documents or have access to your financial data. Customers and prospects often interact via portals, file-sharing spaces or electronic signature tools.

Each of these actors exchanges information with your company through different communication channels: emails, video conferencing, file sharing, business applications, messaging tools, and so on. The multiplication of these contact points expands your attack surface, and some channels may escape your monitoring, unlike your internal systems, which are continuously supervised and updated.

Why external collaboration weakens your security chain

Collaboration with external third parties is based on trust. However, trust does not replace control, especially in cybersecurity. In practice, it is often difficult to maintain direct control over third parties’ security practices.

Unlike internal employees, external actors are not subject to your security policy. They use their own tools, networks and passwords. Their level of cyber maturity often differs from yours. A service provider using the same password across all applications, a supplier delaying the deployment of a security patch, or a subcontractor whose workstation is infected with malware are all situations that are difficult to anticipate and control. A simple phishing email sent from a compromised prospect’s mailbox may be enough to deceive your teams.

In addition, access proliferation is a major issue. Each new partner is granted accounts and access rights to certain company resources. These permissions are sometimes configured too broadly for the sake of convenience. When collaboration ends, IT departments are not always notified in time, and access rights are revoked late. As a result, doors remain open within your information system, sometimes for months.

Cybercriminals know how to identify and exploit these weaknesses. By compromising a third party with legitimate access to your environment, they can infiltrate it quietly without triggering any alerts. These “lateral” or “supply chain” attacks are now one of the most dangerous intrusion vectors.

The consequences of a third-party security incident

In the event of a third-party-related incident, the most immediate risk is the leakage or theft of sensitive data exchanged with that external party. This may include commercial or strategic data, personal customer data, or intellectual property such as patents. Such information can be resold on the black market, publicly released, or used to carry out further attacks.

Another major risk is unauthorised intrusion into your information systems. When a third party with legitimate access to certain resources is compromised, attackers may infiltrate your system. If the compromised third party is your IT service provider, the consequences can be particularly severe, as cybercriminals may escalate privileges and take control of your most critical assets.

Such an incident may also damage customer trust and harm your brand reputation, particularly if personal data has been stolen.

Finally, your organisation may face legal liability. The GDPR requires data controllers to ensure that their processors provide adequate security guarantees. The NIS2 Directive extends this principle to the entire digital supply chain. In the event of a third-party incident, the commissioning organisation may be held responsible and sanctioned.

Best practices for securing external collaboration

To secure collaboration with external stakeholders, you should first formalise your cybersecurity requirements contractually with each of them. You can also include third parties in your cybersecurity awareness programmes so that they reach a similar level of cyber maturity as your internal staff.

Access management is also essential to mitigate supply chain risks. The principle of least privilege should be applied: each third party should only have the minimum access rights required to perform their tasks.

It is also possible to implement Zero-Knowledge cryptography, which ensures that only the user holds access to their own data. This mechanism prevents any unauthorised access, including from the solution provider itself. However, it is important never to store anything server-side in a way that would expose it to third parties.

This Zero-Knowledge approach raises a practical question: how can access recovery be enabled if a user loses their credentials? The user can designate a Trustee: a trusted person who receives a notification to authorise password recovery, without ever having access to the data itself.

You can also apply the two-person rule (Two-man rule), requiring at least two authorised individuals to act jointly in order to access certain critical resources, making unilateral compromise impossible.

In parallel, it is important to implement proactive monitoring of access and data flows. Continuous monitoring and alert configuration help detect suspicious activity and prevent compromises before they occur.

Finally, the choice of collaboration tools also plays an important role. Exchanges with third parties should rely on end-to-end encrypted solutions, whether for file sharing, messaging, audio calls or video conferencing.

Security incidents involving external actors are now the third most common attack vector, behind phishing and vulnerability exploitation. Ercom helps organisations secure their supply chain through two sovereign solutions that integrate end-to-end encryption. Cryptobox secures file sharing at a Restricted Distribution level approved by the ANSSI (renewal in progress). Citadel Team is a communication platform that ensures the confidentiality and integrity of messaging, audio and video exchanges, enabling secure collaboration with third parties.

  • Defence

Frugal AI: the key to embedding artificial intelligence in combat optronics

Insight
  • Research & innovation

Thales and ELI-NP Renew their partnership with a new maintenance support contract for the World-Class 10-Petawatt Laser System

Insight
  • Cybersecurity

Thales researchers explain why the defence against the quantum threat starts now

Insight
  • Cybersecurity

Game On: How Bot Attacks Are Threatening the Digital Fan Experience

Insight
  • Research & innovation

From Mars to nuclear fusion, Thales stretches the frontiers of high-power laser technology

Insight
  • Defence

How to stop the use of unsecured attachments without hampering your teams’ productivity

Insight
  • France

Thales and DCI join forces to revolutionise operational command

News in Brief
  • Air defence

On Thales’ missile optronics and electronics repair lines, augmented maintenance is becoming a reality

Insight
  • Europe

Thales launches OT XDR capability to improve visibility across IT and OT environments

News in Brief