Transitive Trust in Third-Party Cyber Risk
Abstract
Third-party vendors, including analytics platforms, cloud services, identity providers, and software suppliers, have become embedded in digital service delivery. These arrangements enable scale and specialization, but they also move customer data and security-relevant practices into environments that customers rarely see, select, or evaluate. This paper examines this problem through a document analysis of the November 2025 OpenAIMixpanel security incident. The incident is used as an illustrative case to examine how a security event in a vendor environment can become a governance and accountability problem for the focal organisation that holds the customer relationship. Drawing on organisational trust research and agency theory, the paper argues that third-party cybersecurity risk involves both a trust relationship and a delegation problem. Customers place trust in the visible service provider, while the provider depends on vendors whose security practices are only partially visible and controllable. To explain this relationship, the paper develops the concept of transitive trust, in which customer trust in a digital service depends on the security practices of third-party vendors authorized by that service provider. The paper then presents the Fortress and Gatekeeper framework, which explains why cybersecurity governance boundaries should be understood in terms of trust and data flows, rather than formal organizational ownership alone. The analysis develops four propositions concerning vendor integration, metadata exposure, vendor assurance, and data proliferation. The paper contributes to cybersecurity governance scholarship by explaining how delegated data processing can create customer-facing accountability and by identifying implications for vendor tiering, data classification, contractual design, continuous assurance, and data minimization.