Managing third-party cyber security risks
Report 13: 2025–26. Tabled date: 2026-03-26. 7 recommendations published as HTML.
Tabled Report 13: 2025–26
- Tabled date
- 2026-03-26
- Report year
- 2025-26
Entities audited
- Department of Customer Services, Open Data and Small and Family Business
- Department of Housing and Public Works
Recommendations
QAO's text Addressed to: review and, where needed, update their identity and access management controls. This
review and, where needed, update their identity and access management controls. This should include:- ensuring third parties only have the minimum permissions and access needed to perform their job
- ensuring access controls operate consistently across the IT environment
- ongoing monitoring to ensure identity and access management controls are working as intended.
QAO's text Addressed to: ensure their monitoring and alert controls appropriately identify and alert suspicious activity by users, including third parties. This
ensure their monitoring and alert controls appropriately identify and alert suspicious activity by users, including third parties. This should include appropriate logging and alerting controls across their entire IT environment to detect suspicious activity, such as the injection and execution of scripts and exfiltration of data.QAO's text Addressed to: all public sector entities and local governments
review and, where needed, update their IT policies and procedures to ensure they provide appropriate guidance about identifying, assessing, and monitoring third‑party cyber security risks and developing mitigation controls.QAO's text Addressed to: all public sector entities and local governments
identify their supply chain and third-party cyber security risks, assess the impact and likelihood of the risks, and ensure mitigation controls are effective.QAO's text Addressed to: review and, where needed, strengthen their procurement and contract management practices to better manage third-party cyber security risks. This
review and, where needed, strengthen their procurement and contract management practices to better manage third-party cyber security risks. This should include:- clearly documenting the expectations and security requirements of third parties
- ensuring contracts have appropriate clauses, such as a requirement for third parties to report cyber security incidents and vulnerabilities
- monitoring third-party cyber security risks in contracts to ensure the level of risk is appropriate and the mitigation controls remain effective
- ensuring staff have the right knowledge and skills to manage third-party cyber security risks during procurement and throughout the lifecycle of the contract.
QAO's text Addressed to: the Department of Customer Services, Open Data and Small and Family Business
strengthens its leadership role to help entities manage their third-party cyber security risks by:- updating its cyber skills framework to include third-party cyber security
- collecting and analysing information from entities about how they manage their third-party cyber security risks as part of their information and cyber security (IS18) annual returns, or other mechanisms
- assessing supply chain risk across the public sector and the maturity of public sector entities to manage these risks
- coordinating training, simulations, and other capability-building activities focused on gaps across the public sector
- publishing its supply chain risk framework and other better practice guidance
- following up with entities to confirm they have acted on advice for high risk third-party cyber threats and vulnerabilities.
QAO's text Addressed to: assesses whether public sector entities are aware of and have implemented its guidance about managing third-party cyber security risks during procurement. This
assesses whether public sector entities are aware of and have implemented its guidance about managing third-party cyber security risks during procurement. This should include providing advice and training pathways to help state government entities strengthen their procurement practices where necessary.
Authoritative report — Queensland Audit Office
Source: Queensland Audit Office, CC BY 4.0
Catalogue snapshot 2026-10-09
© The State of Queensland (Queensland Audit Office) 2026
Report metadata arranged into a catalogue. Recommendations reproduce QAO's words with HTML formatting simplified; no model summaries. Responses and PDF bodies are excluded.
Report pages checked individually. Recommendations and body-derived entities are withheld for licence exceptions. Images, logos and multimedia are excluded.
No endorsement by the State of Queensland or Queensland Audit Office is implied.