Cyber procurement is becoming an identity governance issue. As enterprises move critical software, cloud services and data exchanges into procurement channels, the security question is no longer limited to whether a supplier is reputable. It also concerns which people, service accounts and machine identities can access purchasing systems, how that access changes over time, and whether the organisation can prove that decisions were properly controlled. Linda Siegert’s perspective on the cyber-procurement nexus highlights the convergence between third-party risk, digital trust and identity lifecycle management.

The problem is that procurement ecosystems often sit outside the traditional IGA boundary. Supplier portals, contract platforms, invoice systems and integration services may be administered by separate teams, while external users retain access after projects end or responsibilities change. Shared credentials and unmanaged service identities can create a path from a supplier relationship into financial systems. Without joined-up governance, access reviews become periodic paperwork rather than a continuous control.

An IGA programme should begin by mapping procurement identities to business relationships. Every external user, integration account and automated process needs an accountable owner, a defined purpose and an end date. This creates the foundation for joiner, mover and leaver controls that include contractors and suppliers, not just employees. It also makes it possible to distinguish a legitimate purchasing workflow from anomalous access to sensitive records.

Segregation of duties is another central control. A user who can create a supplier, approve a purchase and release payment represents a materially different risk from one who can only view a contract. Policy-based access models can enforce those boundaries while allowing exceptions to be documented and reviewed. Risk signals such as unusual geography, dormant accounts or sudden privilege elevation should trigger additional verification before access is granted.

The practical priority for security and procurement leaders is shared visibility. Identity governance administration must connect supplier data, HR records, contracts and application entitlements so that access reflects the current commercial relationship. That makes cyber procurement measurable: who has access, why they have it, who approved it and when it should end.