Serving Colorado's Counties

Technical Update vol. 30 no. 27 - Cybersecurity Insights: Third-Party Risks

July 7, 2026

Cybersecurity threats continue to evolve, and attackers are increasingly targeting counties through the vendors, software providers, and third-party systems they rely on every day. These incidents, often called supply chain attacks, occur when cybercriminals compromise a trusted outside partner to gain access to county systems or information.

For counties, third-party relationships are essential for daily operations. Outside vendors may support payroll, benefits administration, financial systems, public records, cloud storage, software platforms, and other critical services. While these partnerships create efficiencies, they can also introduce cybersecurity risks if proper safeguards are not in place.

UNDERSTANDING VENDOR RISKS

Third-party cybersecurity incidents can happen in several ways. A vendor may experience a data breach, a software provider may have a vulnerability exploited, or an attacker may use compromised vendor credentials to access connected systems.

Common risks include:

  • Unauthorized access to sensitive information
  • Exposure of employee or resident data
  • Disruption of essential services
  • Financial fraud or payment redirection
  • Loss of access to critical systems

Because counties manage sensitive information, including PII, financial records, and employee data, understanding vendor security practices is important to reducing risk.

STRENGTHENING VENDOR OVERSIGHT

Cybersecurity should be considered throughout the vendor relationship, from selection and contracting to ongoing monitoring.

Counties should consider:

  • Reviewing vendor cybersecurity policies and security practices
  • Understanding what information vendors can access
  • Limiting access to only what is necessary
  • Requiring multi-factor authentication
  • Confirming data backup and recovery processes
  • Reviewing notification requirements in the event of a breach
  • Removing vendor access when contracts or services end

Vendor agreements should clearly define expectations for protecting information, reporting incidents, and managing access.

SHARED RESPONSIBILITY FOR CYBERSECURITY

Even when an outside provider manages information, counties still have a responsibility to understand how data is protected. Employees also play an important role by following cybersecurity best practices when interacting with vendor platforms. 

Employees should:

  • Use strong, unique passwords
  • Report unusual system activity
  • Verify unexpected vendor requests
  • Avoid sharing login credentials
  • Follow county technology policies

Cybercriminals often exploit trusted relationships, making awareness and communication essential.

WHAT THIS MEANS FOR COUNTIES

Third-party vendors are valuable partners, but cybersecurity risks do not stop at county systems. As cyber threats become more sophisticated, counties should regularly evaluate vendor relationships, access permissions, and data protection practices. Strengthening vendor oversight can help reduce data breaches, service interruptions, financial impacts, and potential claims affecting counties and CAPP. By treating cybersecurity as a shared responsibility between counties, employees, and trusted partners, counties can better protect information, control costs, and maintain essential services. For questions or additional cybersecurity resources, please contact CTSI at 303.861.0507.

News & Updates

Technical Update vol. 30 no. 27 - Cybersecurity Insights: Third-Party Risks

Cybersecurity threats continue to evolve, and attackers are increasingly targeting counties through the vendors, software providers, and third-party systems they rely on every day. These incidents, often called supply chain […]

Read More
Technical Update vol. 30 no. 26 - 2026 Workers’ Compensation Legislation Overview

The 2026 legislative session introduced several updates to Colorado’s workers’ compensation system focused on modernization, compliance, workplace protections, and administrative processes. While these changes vary in scope, counties should understand […]

Read More
Technical Update vol. 30 no. 25 - County Vehicle Use

County vehicles are essential tools for delivering services and supporting community programs. In some cases, counties may consider allowing vehicles to transport participants, volunteers, or individuals involved in county-supported activities, […]

Read More
Technical Update vol. 30 no. 24 - Navigating ADA Compliance

More than three decades after the passage of the Americans with Disabilities Act (ADA), accessibility remains an important responsibility for county governments. The ADA is a civil rights law designed to […]

Read More
June 2026 Health Awareness
Read More