Cyber security

Vetting Third-Party Apps and Integrations: A UK Checklist

Most small businesses run on a handful of core systems with a web of apps connected to them: e-signature, accounting, practice management, scheduling, marketing and, increasingly, AI note-takers and assistants. Each connection is convenient. Each one also gets its own access to your data, which carries on working whether or not anyone remembers it’s there.

Few companies check. The government’s Cyber Security Breaches Survey 2025/2026 found that only 15% of UK businesses reviewed the risks posed by their immediate suppliers, and 6% looked at their wider supply chain.

Why integrations are a risk

An integration usually connects through an API, with permissions granted once, often by a single user clicking “Accept”. After that:

  • It has its own access. Changing someone’s password doesn’t always stop it. A connected app can keep reading email or files until its access is removed.
  • The supplier’s security becomes yours. If the supplier is breached, attackers may be able to use the connections it holds.
  • You stay responsible for the data. Under UK GDPR, if the app processes personal data for you, you’re still the controller, and you need a proper contract with the supplier.

The NCSC approach, in brief

The NCSC’s supply chain security guidance sets out 12 principles in four stages: understand the risks, establish control, check your arrangements, and keep improving. For a small business, that comes down to knowing what’s connected and why, setting minimum standards before anything is connected, checking those standards are met, and reviewing regularly.

The checklist

Use this before you connect any app to Microsoft 365, your practice or accounting software, or anything that holds client data.

  1. Know who the supplier is. Is it an established company you can contact, with clear terms and a named place of business? Free apps from unknown developers deserve the most suspicion.
  2. Ask for security evidence. Cyber Essentials or Cyber Essentials Plus is a good start, and the NCSC points to it as a way to gain assurance about suppliers. For apps handling client data, ask about ISO 27001, independent penetration testing and whether they have a way for researchers to report vulnerabilities.
  3. Check the permissions it asks for. The NCSC advises granting only the permissions an integration needs. An app that reads your calendar shouldn’t also get your mailbox and files. Be wary of anything asking for access to “all” mailboxes or sites.
  4. Control who can say yes. Microsoft recommends letting users consent only to apps from verified publishers, with an admin consent workflow for everything else. The NCSC says high-risk integrations should need admin approval.
  5. Check how people sign in. Single sign-on with your Microsoft account and multi-factor authentication are best. Avoid shared logins, and make sure any API keys are stored securely and changed regularly.
  6. Ask about encryption. Data should be encrypted when it travels between systems and when it’s stored. Ask the supplier, or check their security documentation.
  7. Find out where the data goes. Where is it stored and processed? If personal data leaves the UK, the ICO’s international transfer rules apply.
  8. Get the contract right. Where the supplier processes personal data for you, UK GDPR requires a contract with specific terms, covering security, sub-processors, audits and what happens to the data at the end. Check the supplier will tell you promptly about a breach.
  9. Plan for problems and for leaving. What happens if the service goes down? Can you export your data? How do you disconnect it cleanly, and does the supplier delete your data afterwards?
  10. Review it regularly. The NCSC advises checking whether integrations are still needed and removing access when they’re not, and making sure their activity is covered by your monitoring. Put a review in the diary every three to six months, and whenever a supplier is bought, changes its terms or adds new sub-processors.

Checking what’s already connected

In Microsoft 365, the Microsoft Entra admin centre lists the enterprise apps people have signed in to and the permissions they’ve been granted. Look for any you don’t recognise, remove anything nobody uses, and question anything with wide access.

AI tools deserve particular care, because many ask for broad access to email and documents to be useful. Our post on using AI without weakening your cyber security covers those, and our guide to securing your supply chain looks at suppliers more widely.

From our work

Our standard Microsoft 365 set-up blocks third-party apps by default. That alone stops a lot of attacks, and a lot of permissions nobody knew had been granted. When someone asks for an app to be allowed, we ask what it’s for and what it needs access to. You’d be surprised how often the client decides they don’t need it after all, or finds that a member of staff was trying to reach something they shouldn’t.

David Gilbey, Just Gilbey IT Solutions

Get a second opinion

Our Cyber Security service starts by looking at the risks to your systems and data, then sets up Microsoft 365 to best practice and monitors your accounts around the clock.

Questions people ask

What is an API integration?

A connection that lets one piece of software read or change data in another, such as an e-signature app saving documents into SharePoint, or accounting software pulling in bank transactions. Each connection has its own access, separate from any person’s login.

How do I see which apps are connected to our Microsoft 365?

In the Microsoft Entra admin centre, under Enterprise apps, you can see the apps people have signed in to and the permissions they’ve been granted. Microsoft also explains how to review and revoke those permissions.

Should suppliers have Cyber Essentials?

It’s a good sign, and the NCSC points to Cyber Essentials as a way to gain assurance about suppliers. For apps that handle client data, also ask about ISO 27001, independent security testing and where the data is stored.

Sources

More on cyber security

All cyber security articles