Third-Party Risk Is Now the Defining Cybersecurity Challenge
A guide for business leaders navigating vendor risk, compliance obligations, and the decisions that determine your exposure.
by Larry J. Hershman, CISSP and Doc Blackburn, CISSP
The Number That Should Change How You Think About Cybersecurity
61 percent.
That is the share of organizations that experienced a data breach caused by a third party in the past twelve months, according to the Ponemon Institute’s 2025 Third-Party Risk Management (TPRM) Study. Not a phishing attack. Not an unpatched server sitting in your own data center. A breach caused by a vendor your organization chose, contracted, trusted, and gave access to your data. Verizon’s 2025 Data Breach Investigations Report, which analyzes confirmed breach incidents rather than surveying organizations, found that third-party involvement in breaches doubled year over year, from 15 percent to 30 percent. Two different ways of measuring the same problem, both moving in the same direction.
The more troubling number is this: fewer than one in three of those organizations had a formal vendor risk management program in place when the breach occurred.
That gap is not accidental. Organizations have spent heavily on cybersecurity for years, improving firewalls, endpoint protection, and employee awareness, while third-party risk has often received far less attention and third-party breach rates keep rising, because most organizations have hardened everything except the relationships they depend on most.
The IBM 2024 Cost of a Data Breach Report put a dollar figure on it: breaches involving third parties cost an average of $4.29 million. Nearly $300,000 more than breaches that started internally.
The numbers say it all. The question is whether your organization is listening.
More than six in ten organizations experienced a third-party breach last year. Fewer than one in three had a vendor risk program in place when it happened.
What This Actually Looks Like
Statistics can describe a pattern. The three incidents below show what it costs when that pattern plays out in the real world. Each one followed the same architecture: a vendor with access, an organization without adequate oversight, and consequences that landed on the client.
Ascension Health: Vendor Access Without Accountability
In May 2024, an IT vendor with access to Ascension Health’s systems inadvertently downloaded a malicious file, triggering a ransomware attack that disrupted electronic health records and clinical operations across 140 hospitals. Staff reverted to paper. Elective procedures were postponed. Emergency patients were diverted. By the time it was over, 5.6 million patients had their protected health information compromised. The core failure was not technical. A vendor had been granted system access without the monitoring controls that would have contained the damage.
PowerSchool: The Risk Nobody Audited
In January 2025, attackers used compromised credentials to access PowerSchool’s customer support portal and extract student and teacher records from districts across the United States and Canada. PowerSchool serves more than 60 million students across 18,000 school districts. Most affected districts had no vendor risk program that required PowerSchool to demonstrate security controls or MFA on administrative access as a condition of the relationship. The vendor was large, ubiquitous, and trusted implicitly. That was the entire risk assessment.
CDK Global: When Your Software Vendor Is Your Business
In June 2024, CDK Global, the dominant software platform serving more than 15,000 automotive dealerships across North America, suffered a ransomware attack that took its dealer management system offline for nearly three weeks. CDK paid an estimated $25 million ransom. Dealerships lost an estimated $1 billion in aggregate revenue. Most had never assessed CDK’s security posture or built any contingency for CDK unavailability. Their dependency was total. Their preparation was nonexistent. For dealers subject to the FTC Safeguards Rule, the operational loss came with regulatory exposure on top of it.
These are not edge cases. They are the visible surface of a much larger problem. Two years ago, the Ponemon third-party breach figure was 49 percent. The trend is not slowing.
What the Compliance Frameworks Require
If the statistics alone don’t move you, the regulatory frameworks will. For most organizations operating in regulated industries, third-party risk management is not a best practice. It is a requirement.
CMMC. HIPAA. PCI DSS v4.0. The FTC Safeguards Rule. NIST CSF 2.0. Across all of them, the expectation is the same: you cannot hand your compliance obligations to a vendor and walk away. When you give a vendor access to your data, your systems, or your regulated operations, you remain accountable for what happens. The relationship does not transfer your risk. It creates new risk. And the frameworks expect you to manage it.
What regulators and auditors want is not a questionnaire sitting in a folder. It is evidence of a program. Documented decisions. Evaluated findings. Ongoing oversight. A risk register that can be produced on demand, not assembled in a panic after something goes wrong.
The insurance market has reached the same conclusion. Cyber insurance premiums for organizations without documented TPRM practices increased an average of 28 percent in 2024. Underwriters are now requiring evidence of vendor oversight as a condition of coverage. Some are denying claims outright where due diligence was absent. The cost of not having a program is no longer hypothetical.
Do You Know Your Risk Tolerance?
Here is a question most business leaders cannot answer honestly: how much third-party risk is your organization willing to accept?
That is not a rhetorical challenge. It is the foundational question of any vendor risk program, and the answer has to come from leadership. Not from IT. Not from legal. From the people who understand what this organization can absorb if something goes wrong.
Start here. Answer these honestly.
- If your most critical vendor went completely dark for 72 hours, could your organization keep operating? At what cost? What would you tell your clients?
- If a vendor experienced a breach involving data you entrusted to them, what are your notification obligations? To patients, customers, or regulators? Within what timeframe?
- If a regulator, insurer, or plaintiff attorney asked you today to produce documentation of your vendor risk decisions, what could you actually show them?
- Does your cyber insurance policy cover third-party breach scenarios? Do you understand the exclusions?
If you cannot answer these questions with confidence, your risk tolerance is not a decision you have made. It is a gap you have not noticed yet.
How to Properly Solve This
The most common reason SMBs do not have a vendor risk program is a simple misconception: that TPRM requires enterprise-scale resources. It does not. It requires structure, judgment, and documentation. That is it.
A right-sized program for a regulated SMB has four components. None of them require a dedicated risk team. All of them require a decision to treat vendor risk as a real business priority, not a compliance checkbox to revisit once a year.
Know Who Your Vendors Are
This sounds obvious. It is rarely done. Most organizations know their major IT providers. They often have no idea how many SaaS applications their employees have connected to company data, which vendors can reach their network, or which ones would create serious disruption if they disappeared tomorrow. The starting point is a complete vendor inventory. Every relationship. Every access path. Every data type involved. Not a one-time project. An ongoing record.
Tier Vendors by Risk, Not by Relationship
Not every vendor warrants the same level of scrutiny. The vendor processing your payroll is not the same risk profile as the vendor delivering your office supplies. Treating them equally is not due diligence. It is theater. Tiering vendors by criticality and data access allows you to concentrate resources where the actual exposure lives and apply a lighter touch where it does not.
Conduct Evidence-Based Reviews
The purpose of a vendor review is to assess whether a vendor can be reasonably trusted with an organization’s data and obligations. As part of our TPRM service, we review available evidence such as SOC 2 Type II reports, cyber insurance coverage, incident response documentation, contractual protections, and other relevant security information. The goal is to provide a documented finding and rationale that supports an informed vendor risk decision, rather than relying solely on a questionnaire or vendor assertion.
Monitor. Do Not Just Onboard.
A vendor risk program that only runs at onboarding is not a program. It is a single decision you have mistaken for ongoing oversight. Vendor services evolve. SLAs change. Providers get acquired. They add subprocessors. Their SOC report expires with new exceptions. Their security team turns over. Effective monitoring means a structured reassessment cycle, attention to material changes, and documentation that proves you were paying attention throughout the relationship, not just at the start of it.
A vendor risk program that lives only at onboarding is not a program. It is a one-time decision you have mistaken for ongoing oversight.
How UTRS InfoSec Helps You Build and Run This Program
Most SMBs in regulated industries are not ignorant of vendor risk. They know it is a problem. What they lack is the structure to manage it and the capacity to build that structure without pulling leadership away from everything else demanding their attention.
That is exactly what our Third-Party Risk Advisory Service is designed to solve. We help you establish and operate a practical vendor risk management program, and we manage the vendor due diligence and assessment process on your behalf. Your leadership gets the protection and documentation they need. They do not need to hire an entire risk team to get it.
What We Do
- Vendor Inventory and Tiering: We help identify your critical vendors, map their data access and system connections, and tier them by risk and criticality against your specific compliance obligations, whether that is HIPAA, CMMC, PCI DSS, FTC Safeguards, or a combination of frameworks.
- Evidence-Based Assessments: We have questionnaires aligned to your actual regulatory environment, conduct outreach to your vendors, and evaluate responses against the evidence that matters. SOC 2 reports. Cyber insurance. Incident response plans. Contractual protections. We do not just collect documents. We interpret them.
- Risk Register and Documentation: Every assessment produces a documented finding and recommendation. The output may include a risk register built to answer the questions regulators, auditors, and insurers ask. Produced before you need it, not assembled after something goes wrong.
- Ongoing Managed Monitoring: For clients who need a continuous program, we transition the initial assessment into a managed advisory service. We track vendor risk posture over time, manage reassessment cycles, flag material changes, and keep your documentation current so you are never caught flat-footed.
The Question That Matters
Third-party risk is not theoretical. It is the attack surface your adversaries have learned to exploit. It is the compliance gap your auditors are trained to find. It is the liability your insurer is weighing before they honor a claim.
The organizations best positioned for what is coming are not the ones who have eliminated vendor risk. That is not possible. They are the ones who have made a deliberate decision to understand it, manage it, and document it. So the question that matters is:
Can we rely on this vendor, with our data, under our obligations, and defend that decision?
About UTRS InfoSec LLC
UTRS InfoSec LLC provides vCISO services, compliance advisory, and third-party risk management to regulated organizations across healthcare, financial services, defense contracting, legal, higher education, and professional services. Our offensive security practice delivers penetration testing, application security assessments, and red team engagements that identify exploitable weaknesses before an adversary does. Our managed detection and response capability provides continuous monitoring, threat hunting, and incident response across endpoints, identity, and cloud environments, so the gaps we find get watched and the threats that matter get contained. Our advisors bring more than 25 years of experience translating complex security obligations into decisions that business leaders can understand, implement, and defend. To learn more about our Third-Party Risk Advisory Service or to discuss your organization’s vendor risk posture, visit utrsinfosec.com or contact us directly.