• Reassess the cybersecurity posture of vendors and partners.
• Apply least-privilege principles on third-party integrations.