29 July 2026
Suburban Secure reflects on the Queensland Audit Office's third-party cyber risk report
The Queensland Audit Office has released Report 13: 2025–26, Managing third-party cyber security risks, examining how three public sector entities manage the cyber risk that comes with using IT vendors, accounting firms, marketing businesses and consultants. Suburban Secure has published a full reflection on what it found.
The findings are worth sitting with: testers reached administrator-level access to critical systems, including finance and payroll platforms, in at least two of the three entities audited, by exploiting how third-party access had been configured. Of 36 vendor contracts reviewed, only 2 required the vendor to report cyber security incidents back to the entity, and none addressed the security practices of the vendor’s own suppliers.
Our reflection makes the case that this isn’t just a public-sector story. The same patterns — vendor access broader than necessary, no register of who holds risk on an organisation’s behalf, and contracts silent on security — show up constantly in small businesses, charities and schools too. The difference is that a government department at least has an audit cycle checking in. Most smaller organisations don’t, which is exactly why these gaps tend to go unnoticed for years rather than surfacing in a report.
The full article walks through all seven of QAO’s recommendations and turns them into practical questions any organisation can ask about its own vendors right now, without needing a government-scale audit function to get started.