third & fourth party
Supply Chain Exposure
Vendor risk weighted by concentration and data access, not questionnaire score. Shared fourth parties are the contagion channel: SecurePay appears behind three separate suppliers.
tier
7 of 7 suppliersdependency graph
Northstar supplier topology
Northstar Financialroot entity
tier 1
tier 2
tier 3
tier 1 · Payment orchestration
SecurePay
critical
predicted risk
93
posture
44 (-29)
concentration
91%
incidents 12m
2
data access
Cardholder data, settlement instructions
fourth parties
AWS us-east-1CloudflareTwilio
CVE-2026-48217 affects 62 Northstar gateway nodes. Vendor patch 7.4.4 released 21 Aug; Northstar adoption 0%.
contagion
Concentration findings
- SecurePay is a fourth-party dependency behind Meridian Payments and Quillmark Docsa single vendor compromise touches 3 supplier relationships
- 91% of payment orchestration flows through one supplierno viable failover within the modelled window
- Aurora IT holds privileged access to 6,800 endpoints without JIT elevationlargest single blast radius in the estate
linkage
Predictions with vendor origin
- PRD-4417BlackFrost exploitation of CVE-2026-48217 in Northstar payment tier87%
- PRD-4402Credential-stuffing surge against Northstar retail banking portal74%
- PRD-4371Ransomware detonation via managed service provider Aurora IT41%