Independent reporting: why your IT provider should not judge its own work
Published on July 3, 2026 · Updated on August 4, 2026
Many organizations receive their security reports through their IT provider: the same party that builds the servers, manages the firewall and runs the updates. It feels logical and efficient. But ask the question an auditor asks: who is judging whose work here?
This article is about that question. Why reporting through your managing party weakens your evidence, why it counts double under NIS2, and what independent reporting means in practice.
In short
- A managing party reporting on its own environment is judging its own work. Two mechanisms are at play: the incentive to soften findings, and the blind spot for choices you made yourself. Both are structural, even at honest firms.
- Independent assurance strengthens the third line in the common "three lines of defence" model; a report from your managing party can be useful first- or second-line material, but does not fill that line.
- Under NIS2 this counts double: your IT provider is itself a supplier in the chain you must manage.
- Independent reporting means: directly to the client, without the managed party in between.
- Ask yourself: does your auditor currently get evidence, or a filtered summary?
The butcher judging his own meat
An IT provider presenting scan results about infrastructure it built itself is in an impossible position. Every vulnerability that makes the report raises the question why it is there: should the provider not have prevented it? Every finding is implicit criticism of its own work.
That does not mean providers lie. It means the incentive to soften a finding, reclassify it, or "quickly fix it before the client sees it" is structurally present. This is exactly why separation of duties exists in every mature control environment: the accountant does not audit their own books, and the inspector does not work for the butcher.
Alongside that incentive, a second and subtler mechanism is at play: the blind spot. Whoever designs an environment judges it through the same assumptions they built it with. A port that was once deliberately opened, an exception that was "temporary", a component that has "always been there": those are exactly the choices the builder notices least, because to them they are self-evident. A measurement from the outside does not start from those assumptions and therefore sees things that remain invisible from within. This holds regardless of skill: even an excellent team has blind spots in its own work.
The third line of defence
This principle is well established. Many organizations structure their risk management along the "three lines of defence" model. The first line is execution: the teams that manage the environment and make daily choices. The second line is risk management and compliance: internal oversight that sets frameworks and looks over their shoulder. The third line is independent assurance: a party that stands apart from execution and establishes whether the whole holds up.
Independent reporting belongs in that third line, and its value lies precisely in the distance from execution: the judgment comes from outside the line that did the work. Strictly speaking, the third line in this model is the internal audit function; a measurement by a party outside the organization sits beyond even that and strengthens the third line as external assurance: the independence is then a degree sharper, because the measurer is not part of the organization's own lines at all. A report from your managing party can be perfectly good first- or second-line material (valuable for steering internally), but it does not fill the third line, because it lacks the independence that defines that line. Internal and independent reporting therefore sit side by side, each serving its own function.
When internal reporting does suffice
Not every situation calls for an external measurement, and saying so plainly is part of an honest picture. If your managing party reports purely so that you can steer and prioritize internally (which vulnerabilities do you tackle this sprint), then an internal report is fine for that. As long as no outside party asks for evidence, independence is not a goal in itself.
Independent reporting starts to weigh the moment an external assurance question arises: an auditor testing your duty of care, a large customer requesting evidence under the NIS2 supply chain duty of care, or an insurer wanting to see your security posture. If you have no NIS2 obligation, no chain position in which a customer questions you, and no auditor or insurer asking for evidence, internal material will do. So the trade-off is: as soon as someone outside your organization has to be able to rely on the report, the question of who produced it starts to count.
Why this counts double under NIS2
The NIS2 supply chain duty of care requires you to demonstrably manage risks at your suppliers. Your IT provider is not just the party that can help you with that: it is one of those suppliers itself, and often the most critical one. What your large customer may ask about this is covered in what does your large customer expect under the NIS2 duty of care.
Demonstrating supply chain due care with a report from the party that report is (partly) about weakens your evidence exactly where it needs to be strong. The auditor is not the only one who looks at this. A large customer questioning you under its own supply chain duty of care wants to be able to lean on your report demonstrably, without an interested party having compiled it. Otherwise it inherits your conflict of interest. A cyber insurer asks for independent evidence for a different reason: it prices risk and wants to see a security posture that is not coloured by the party that benefits from everything looking fine. Where the auditor mainly looks at the design of the separation of duties, for those two it is more about the reliability of the figure their decision rests on. For many auditors and buyers, independent reporting therefore weighs more heavily than a report that arrives through the managed party. The question to ask yourself: do I currently receive my security reports through the party that manages my environment, and would my auditor consider that sufficient?
What independent reporting means
Reporting independently goes beyond a different logo on the report. It comes down to three things:
- Direct delivery. The report goes from the measuring party straight to the client. The managing party can read along if the client wants, but never sits in the line as a filter.
- Traceable findings. The client can verify per finding how and when it was established, without relying on the interpretation of an interested party. How that works is covered in forensically grounded evidence.
- Verifiability. In production, reports are digitally signed (PAdES) and carry an RFC3161 timestamp; a signing failure does not block delivery, but where the seal is present a third party can verify the report independently. The independence lies in two things: the timestamp independently establishes that the report already existed at that moment, and the integrity check shows that any change after signing breaks the signature, so tampering is evident. See how to check whether a security report is real.
Your IT provider remains just as valuable: it fixes the findings. The roles are simply separated. Measuring and remediating are two different things, and it is exactly that separation that makes the remediation credible. And the reverse holds just as much: independence without measurement is still paper. Independent reporting weighs because it rests on an actual measurement rather than on a statement.
How Exposentry safeguards this itself
Claiming independence is easy; organizing it is the real work. Exposentry is a Hasecon service, and Hasecon also provides implementation, maintenance and development services around OpenKAT, such as on-premise installations and custom modules. Founder Edward Hasekamp also contributes to OpenKAT itself as a collaborator. It is precisely that involvement that makes the separation of duties matter, which is why it is laid down in writing:
- Reports always go directly to the client, even when another party brought in the customer.
- If Hasecon does OpenKAT work for the same client or in the same environment, that overlap is stated explicitly in the report.
- Hasecon does not issue security reports on scanned environments outside of Exposentry: there is only one reporting channel.
- For active supply chain verifications, Hasecon does not perform remediation or management work in the verified environment.
This policy is part of our terms and conditions, so your auditor does not have to guess.
The test for your own situation
Take your latest security report and ask three questions. Who produced it? Does that party manage (part of) the environment it covers? And did the report reach you directly, or through that party? With two "yes" answers on the latter questions, the report remains usable, but it stands weaker as evidence towards an auditor, customer or insurer than you think.
Written by Edward Hasekamp, founder of Exposentry and collaborator on the open-source OpenKAT project. See the project on GitHub and the profile at github.com/hasecon. Exposentry provides EU-sovereign, forensically substantiated vulnerability monitoring based on OpenKAT. More articles in the Knowledge base.