Once you have your team assembled, your incident response plan needs to be built and tested so it can be used when an incident happens. Here are a few things you need to have prepared for third-party risks:
Access to contact the right person at your vendors
If a third-party system is acting maliciously, you don't have time to file a support ticket and hope your vendor gets to it later. Document who your security contacts are at each vendor, what escalation paths they have, and what SLAs they've agreed to around communicating during an incident.
An inventory of critical third-party systems
Know who has access to your environment and what data they can access. If you don't know what your third parties have, you won't know the full extent of a compromise.
Clearly defined escalation criteria
Your team needs to know what constitutes a suspected compromise versus a confirmed incident. Who has the authority to make containment decisions, such as cutting off vendor access?
Tabletops
Practice your response to a vendor compromise. What access can you suspend immediately? How will you go about collecting evidence, and who will share it with outside entities such as law enforcement?