[ ← Back to Sequenxa Intelligence ]

Sequenxa Intelligence · Analysis

[ Due Diligence ]

Vendor Due Diligence Is Not Executive Due Diligence

A vendor can clear every item on a due diligence checklist and still be the wrong company to let near your executives. Due diligence answers a procurement question. It was never built to answer the intelligence one. Here is the difference, and the six signals that tell you a relationship needs a deeper look before you expand trust.

R.J. FinneganPublished June 18, 2026Updated July 27, 20268 min read
 Vendor Due Diligence Is Not Executive Due Diligence

In May 2025, a joint advisory from CISA, the NSA, the FBI, and several international partners told executives at logistics and technology companies to operate on the assumption that a Russian military intelligence unit was already trying to get in.

Not the security team. Executives.


The advisory named GRU Unit 26165, the group also tracked as APT28 or Fancy Bear, and described a campaign that had been running against Western logistics and tech firms since 2022. The instruction was blunt. Posture your defenses with a presumption of targeting. Read that again. A presumption. Federal agencies were telling the people who approve budgets and sign partnership deals to assume the adversary was already interested in the companies they do business with.


That gap is what this article is about. The distance between a vendor that passes review and a relationship that is safe to expand.


What vendor due diligence is actually for


Vendor due diligence answers a procurement question. Is this a real company we can transact with? It confirms the entity exists, files its taxes, carries the right insurance, holds the certifications it claims, and can produce documentation of its security controls. That work is necessary. It is also narrow by design.


A clean diligence file tells you the company can pass an audit. It does not tell you who actually owns it now, who it shares staff with, or what it would be worth to someone trying to reach you through it. Those questions sit outside the form. We covered the structural version of this in vendor risk assessment is not supply-chain intelligence, and the part where the answer changes after onboarding in third-party access is a counter-intelligence problem.


Here is the part most programs miss. The risk a third party carries is not a fixed property of the vendor. It is a property of the access you grant them.

A cleaning contractor and a fractional general counsel can both pass the same diligence checklist. One of them sits in the room when you decide whether to acquire a competitor. Treating those two relationships with the same review is how organizations get surprised.


Executive due diligence starts where the procurement question ends. It asks what this relationship could become if the person on the other side of it wanted to hurt you, or if someone took control of them later and did.


The 2026 threat reporting points at people, not paperwork


If the threat were mostly about whether a vendor patches its servers, the questionnaire would be enough. It is not, and the reporting from the last year keeps pointing at the same place. People and relationships.


In February 2026, Google's Threat Intelligence Group published an analysis of threats to the defense industrial base. The standout finding was not a new piece of malware. It was that the direct targeting of employees and the exploitation of the hiring process had become a central theme across defense and aerospace firms. North Korean IT workers, Iranian actors spoofing recruitment portals, contractors targeted on their personal email. GTIG described a threat that centers on personnel and routinely operates in places enterprise security tools cannot see.


A month later, Microsoft Threat Intelligence showed how cheap that targeting has become. Its March 2026 report described North Korean operations it tracks as Jasper Sleet and Coral Sleet using AI to mass-produce fabricated identities. Face-swapping software to drop a worker's face into a stolen identity document. AI-generated headshots for resumes, the same photo reused across personas with small changes. Voice-changing software during interviews to mask an accent and pass as a Western candidate. The resume looked clean. The headshot looked real. The interview sounded right. None of it was true.


That is the uncomfortable point for anyone who relies on presentation as a proxy for legitimacy. A polished profile is now something an adversary can manufacture on a budget. This is the same problem we wrote about in what identity verification services actually validate. Confirming that a document is genuine and a face matches is not the same as confirming the person is who they claim to be, or that they are working for who you think.


And the ones who get in tend to stay. Mandiant's M-Trends 2026, released in March, put global median dwell time at 14 days, up from 11. The cases driven by espionage and North Korean IT workers ran far longer, with a median of 122 days. Serious adversaries are patient, and they often persist through the assets and relationships an organization never flagged as intelligence-sensitive in the first place.


Put those four reports next to each other and the pattern is hard to miss. The pressure has moved to the human edge of the organization, where a counterparty's credibility can be manufactured and a quiet relationship is exactly the kind of place an adversary likes to sit and wait. A controls questionnaire was never built to detect any of that.


Vendor diligence and executive due diligence answer different questions


It helps to be precise about the three reviews that get collapsed into one. They are not the same work, and they do not answer the same question.


Most organizations run the first two well and never run the third. That is a reasonable default for the bulk of a vendor book. You cannot run corporate intelligence on every supplier, and you should not try. The failure is not skipping executive due diligence everywhere. It is failing to recognize the handful of relationships where skipping it is the actual exposure.


Six signals a third party needs intelligence-led review


Not every vendor warrants this. The question is which ones do. A relationship moves into intelligence-led territory when one or more of these is true:

• The relationship grants standing access to executives, their calendars, travel, devices, or communications.

• The third party can see or shape strategic decisions before they are public, including acquisitions, legal strategy, major hires, or financing.

• Ownership is opaque, has changed recently, or traces back through jurisdictions that resist verification.

• The vendor sits at a chokepoint in your data or logistics flow, where one compromise reaches many systems at once.

• The counterparty's credibility rests on documents and a digital presence you have not independently verified.

• The relationship is expanding through renewal, deeper integration, or more credentials, without a fresh look at who you are actually dealing with now.

If you read that list and a specific vendor came to mind, that is the one to look at first. The signal is usually already there. What is missing is the decision to act on it before, rather than after.


A clean questionnaire cannot catch a fabricated counterparty


The difference between a security questionnaire and an intelligence review is the difference between asking and verifying.


A questionnaire collects what the counterparty tells you about itself. It is self-reported, point-in-time, and only as honest as the party filling it out. For an ordinary vendor, that is a fair trade. The work is cheap and the risk is bounded. For a high-trust relationship, the same trade is dangerous, because the entity most motivated to lie on the form is the one you most need the truth about.


Intelligence-led review does not ask the counterparty to grade itself. It establishes ownership independently, traces the people behind the entity, checks the digital footprint against the claims, and looks at how the relationship actually behaves rather than how it describes itself. When the Microsoft and GTIG reporting tells you that resumes, headshots, portals, and even interview voices can be synthetic, the only response that holds up is verification you control. This is the core of counter-intelligence work and the broader supply chain intelligence function. Confirm what is real instead of trusting what is presented.


Intelligence evidence and questionnaire evidence are not interchangeable. One is a record of what someone wanted you to believe. The other is a record of what you were able to confirm.


What to ask before you expand access


Before approving access, a renewal, deeper proximity, or a new dependency on a high-trust third party, the questions worth answering are short and specific.


Who owns this entity today, and how do we know that independently of what they told us? What would this relationship be worth to someone trying to reach our executives or our strategy? If this counterparty were compromised or replaced tomorrow, how long would it take us to notice, and what would they reach first? Has anything material changed since the last time we actually looked, not since the last time we filed the paperwork?


If you cannot answer those without going back to the vendor's own questionnaire, you have not done executive due diligence. You have done vendor due diligence and hoped it was enough.


Frequently asked questions


What is executive due diligence?


Executive due diligence is an intelligence-led review of a high-trust third party that focuses on what the relationship could become in the hands of an adversary. It looks at hidden ownership, the people behind the entity, independently verified credibility, and the access the relationship grants, rather than only confirming controls and compliance.


What is the difference between vendor due diligence and executive due
diligence?


Vendor due diligence confirms a company is legitimate, insured, and able to document its controls. Executive due diligence asks a different question. What strategic exposure does this specific relationship create, and could it be turned against us? The first is a procurement check. The second is a security and intelligence judgment about access and proximity.


Can a vendor pass due diligence and still be a security risk?


Yes. A vendor can clear every checklist item and still be a serious risk if it has standing access to executives, visibility into strategic decisions, opaque ownership, or a credibility built on documents you have not independently verified. Passing diligence confirms the paperwork is in order. It does not confirm the relationship is safe to expand.


When does a third party need intelligence-led due diligence?


A third party needs intelligence-led review when it gains access to executives, can see or shape decisions before they are public, sits at a chokepoint in your data or logistics flow, has opaque or recently changed ownership, or is expanding its access without a fresh look at who it actually is now.


Who needs executive due diligence?


Chief security officers, CISOs, general counsel, risk executives, family office principals, and any decision-maker approving high-trust third parties. It applies whenever a relationship grants a counterparty unusual access, influence, proximity, or strategic dependency that ordinary vendor review was never built to assess.


Sources

Author and review

R.J. Finnegan

R.J. is the founder of Sequenxa Corporation. With a deep understanding of behavior analytics, research, and cyber warfare, R.J. brings a unique perspective in his writings.

Content type: Analysis. Last updated July 27, 2026. Read Sequenxa's research methodology and publication boundaries.

Provenance

Sources cited in this brief

Related entity pages

Vendor Due Diligence Is Not Executive Due Diligence