What Active Focus monitors

The Key to Successful Third-Party Management in the SaaS Space

Your suppliers hold your data, and when one of them is breached, it becomes your problem. In a SaaS-heavy world, third-party vendors and subcontractors are part of your attack surface — and the biggest fear for most organisations is simple: sensitive, proprietary data leaking because *someone else* was compromised.

The governance basics still matter — clear contracts that spell out security requirements, regular assessments of your vendors, and enforcing strong, unique passwords with multi-factor authentication so a reused password can’t unlock your services. River Security regularly supports customers in assessing their vendors against exactly these expectations. But contracts and questionnaires only tell you what a vendor claims. They don’t tell you when one has actually been compromised.

River Security monitoring third-party exposure across a customer’s attack surface

Where Active Focus helps

Active Focus closely monitors third parties so they don’t quietly put you at risk. We gather intelligence from Cyber Threat Intelligence (CTI) vendors who continuously scan the dark web, and use it to stay ahead of emerging exposure. When a third party is compromised, we work fast to get hold of the data, vet it, and comb through it for anything that puts you at risk.

This is not theoretical. We have repeatedly found third-party accounts inside customer systems protected by weak or leaked passwords — accounts that gave us, and would have given a real attacker, easy entry. Catching those before they are abused is the whole point.

The most effective thing you can do is share your list of providers with us. With that list, we combine our monitoring with your knowledge of the supply chain and cover it together.

We do this to ourselves, too

River Security runs Active Focus against our own supply chain. The graphs below show two of the several third-party providers we depend on — SendGrid, which we use for email delivery, and Domeneshop, one of our domain registrars — each mapped automatically against our own attack surface.

Active Focus attack graph of SendGrid, showing the DKIM and mail subdomains connecting the third-party provider to riversec.eu

Active Focus attack graph of Domeneshop, showing the domains, subdomains, IP addresses and applications linking the registrar to River Security

Each of these providers is far more than a logo on a vendor list. It is a live web of domains, subdomains, DNS records, IP addresses and integrations woven into our own infrastructure — SendGrid signs mail on our behalf through DKIM records under riversec.eu; Domeneshop controls DNS for domains we rely on. A misconfiguration or compromise at either one could directly affect River Security and, through us, our customers.

That is why we need continuous assurance that every provider is in good security standing — not a point-in-time questionnaire, but an ongoing check that each one is correctly configured (for example, valid SPF and DKIM records for a mail provider), free of dangling or forgotten records that could be hijacked, and not quietly becoming the weakest link an attacker could use to reach us. Active Focus keeps that picture current, so we hold our own suppliers to exactly the standard we help our customers demand of theirs.

Third-party management is attack surface management

Because Active Focus already collects a wide range of data — IP addresses, ownership records, email configurations and more — we understand a great deal about the third parties you rely on. That visibility turns third-party management from a paperwork exercise into something grounded in what your suppliers actually expose to the internet.

See how Active Focus works Talk to an expert