Your security program stops at your firewall. Your risk does not.
For years, vendor risk was the slide nobody read. It sat between “patch management” and “user training” in the board deck, everyone nodded, and the meeting moved on. That is no longer a defensible position.
Verizon’s 2026 Data Breach Investigations Report, published May 19, 2026, found that 48% of breaches now involve a third party, up from 30% the year before. That is a 60% year-over-year increase. Almost half the time, the failure that reached your data did not happen on a system you own, patch, or monitor.
What is third-party risk management?
Third-party risk management is the practice of identifying every outside organization that can reach your data or your network, judging how much damage each one could do, and holding them to a security standard you have agreed to in writing. It covers far more than the vendors you think of as “IT.”
Walk your own environment and count. Your payroll processor holds every employee’s Social Security number. Your CRM holds your entire customer list. Your accounting firm has read access to your books. The marketing tool somebody connected to Microsoft 365 last spring still holds a standing consent grant in your tenant, quietly issuing itself fresh access until an admin revokes it. Your MSP has administrative rights to every endpoint you own.
Each of those is a door into your business that you did not build and cannot inspect. When one of them is breached, you inherit the consequences: notification obligations, regulator questions, customer churn, and an incident response bill you did not budget for.
The blast radius is measurable. Black Kite’s 2026 Third-Party Breach Report found that a single vendor compromise now reaches an average of 5.28 downstream companies, the highest figure they have recorded. Their analysis named 719 victim organizations and estimated a further 26,000 that were never publicly disclosed.
The third-party data breach nobody tells you about on time
Here is the part that reshapes your incident response plan. Black Kite measured a median detection time of 10 days for these breaches, but a median disclosure delay of 73 days, with the average stretching to 117 days. That average was 76 days the year before.
Think about what that means in practice. In the slower half of cases, a vendor holding your customer data can be compromised in March, understand what happened by April, and tell you in July. Through those months you are operating on the assumption that your data is fine. Your own logs show nothing unusual, because the theft happened somewhere else entirely. Your breach notification clock starts running from a date you had no way to know.
You cannot fix that with a tool. You fix it in the contract, before you sign.
How do you assess a vendor’s security?
You assess a vendor’s security by inventorying who has access, tiering them by what they can actually reach, and asking the top tier for documented evidence rather than reassurance. Most small and mid-sized organizations have nobody whose full-time job is vendor risk. The work still has to happen, and it can be scoped to something a busy IT manager can finish.
- Start with an inventory. Pull your accounts payable list, your SaaS billing, and your connected-application list. In Microsoft 365 that is the Entra admin center under Enterprise applications. In Google Workspace it is Admin console, then Security, Access and data control, API controls. That last category is where the surprises live, because employees connect third-party apps without a purchase order. We covered how attackers abuse that consent flow in OAuth phishing. You are building one list of every organization that can reach your data.
- Tier the list. Do not treat it evenly. Your janitorial service and your payroll processor are not the same risk. Sort vendors by what they can touch: those holding regulated data or personal information, those with administrative or API access to your systems, and everyone else. The first two tiers get real scrutiny. The third gets a note in the file.
- Ask for evidence, not adjectives. For your top tier, request a SOC 2 Type II report, an ISO 27001 certificate together with its Statement of Applicability, or a completed vendor security questionnaire. Read the scope before you read the findings. A SOC 2 covers only the trust services criteria the vendor selected and only the service line it names, and an ISO certificate on its own tells you a management system exists, not which controls are inside it. What you are trying to learn is whether MFA is enforced on their administrative accounts, how quickly they patch, whether your data is encrypted at rest, and whether any of the work is subcontracted to a fourth party you have never heard of. A vendor who cannot answer those questions has told you something useful.
- Put the notification window in the contract. Name a number of hours, not “promptly.” Add a right to be told about any breach affecting your data even when the vendor’s counsel is not yet certain it is reportable. This one clause does more for your response time than any product you can buy.
- Re-check annually, and on trigger. A SOC 2 report covering 2025 tells you about 2025. Set a calendar reminder, and reassess any vendor that changes ownership, migrates to a new platform, or turns up in the news.
One more finding from the 2026 DBIR belongs in your vendor questionnaire. Vulnerability exploitation became the single largest breach entry point at 31%, passing stolen credentials for the first time in nineteen years. When you ask a vendor how fast they patch, ask specifically about their internet-facing systems, and ask what their own software supply chain looks like. The dependencies buried in a vendor’s code are as much your exposure as their firewall rules.
Where iFlock fits in your vendor risk management program
Vendor risk is a governance problem before it is a technical one, which is why it stalls at organizations that are otherwise well defended. Nobody owns it, so it never gets done.
Our compliance and risk management practice is built for exactly this work: assembling the vendor inventory, setting the tiering criteria, drafting the questionnaire and the contract language, and owning the annual review so it does not quietly lapse. Our audit readiness practice maps that program to whatever framework you answer to, whether that is PCI DSS, a customer’s security addendum, or a cyber insurance application that now wants to know how you vet suppliers.
On the technical side, vulnerability management produces the patching evidence your own customers are starting to ask you for. And our managed security services provide the monitoring that shortens your side of the detection window on the day a vendor’s problem becomes yours.
You cannot audit your way to a vendor with perfect security. What you can do is know which doors exist, decide which ones deserve scrutiny, and make sure someone tells you quickly when one of them is forced.
Start your vendor risk review
A free security assessment from iFlock is a straightforward way to find out where your defenses actually stand today. And if the vendor list is the part that worries you, say so when you book. Building that inventory and the review process around it is work we do.
Book yours at iflockconsulting.com/contact-us or call 1-833-4-HAXORS (1-833-442-9677).
Fly with confidence.
Sources
Subscribe To Our Newsletter
Get updates and learn from the best
More To Explore