third & fourth party

Supply Chain Exposure

Vendor risk weighted by concentration and data access, not questionnaire score. Shared fourth parties are the contagion channel: SecurePay appears behind three separate suppliers.

tier
7 of 7 suppliers
dependency graph

Northstar supplier topology

Northstar Financialroot entity
tier 1
tier 2
tier 3
tier 1 · Payment orchestration

SecurePay

critical
predicted risk
93
posture
44 (-29)
concentration
91%
incidents 12m
2
data access
Cardholder data, settlement instructions
fourth parties
AWS us-east-1CloudflareTwilio

CVE-2026-48217 affects 62 Northstar gateway nodes. Vendor patch 7.4.4 released 21 Aug; Northstar adoption 0%.

contagion

Concentration findings

  • SecurePay is a fourth-party dependency behind Meridian Payments and Quillmark Docs
    a single vendor compromise touches 3 supplier relationships
  • 91% of payment orchestration flows through one supplier
    no viable failover within the modelled window
  • Aurora IT holds privileged access to 6,800 endpoints without JIT elevation
    largest single blast radius in the estate
linkage

Predictions with vendor origin

  • PRD-4417BlackFrost exploitation of CVE-2026-48217 in Northstar payment tier87%
  • PRD-4402Credential-stuffing surge against Northstar retail banking portal74%
  • PRD-4371Ransomware detonation via managed service provider Aurora IT41%