Security Tools

Vendor Risk Management in 2025

Third-party involvement in breaches doubled year-over-year — from 15% to 30%, per Verizon's 2025 DBIR. Here's what's actually driving vendor risk in 2025-2026, and why leading teams are replacing annual questionnaires with continuous monitoring.

By Inventive HQ Team

Vendor risk management matters more in 2025 than it did even two years ago because the numbers moved fast: third-party involvement in data breaches roughly doubled year-over-year, from about 15% to 30%, according to Verizon's 2025 Data Breach Investigations Report — one of the sharpest single-year jumps in the report's history. Supply-chain compromises also take longer to catch and cost more to clean up than almost any other breach type: an average of $4.91 million and 267 days to identify and contain, per IBM's 2025 Cost of a Data Breach report. Regulators noticed too — the EU's DORA has been binding law for financial entities since January 2025, and it just named 19 companies "critical" to the entire sector's stability.

None of that means the old "60% of breaches involve a third party" line you'll still see repeated on the web is accurate for 2025 — it isn't, and it doesn't need to be for the point to stand. The verified, current numbers are alarming enough on their own. What follows is what actually changed, why it changed, and what a vendor risk program built for 2025-2026 looks like in practice — not the version built for 2019.

Loading interactive tool...

The expanding attack surface

Every vendor you contract with sits inside a much larger, mostly invisible web: their own subcontractors, the cloud infrastructure they run on, and — increasingly — the third-party AI models and tools they've quietly built into their product. Most vendor risk programs only see the first layer.

Your organization's expanding third-party attack surface A central organization surrounded by three rings of vendor nodes: a known Tier 1 ring of direct vendors, a Tier 2 ring of subcontractors that fades into view, and an outer Tier 3 ring of shadow IT and AI tools that flickers to represent its largely unknown status, with pulses radiating outward from the center to represent monitoring reach. Most of your vendor ecosystem is outside security's direct view YOUR ORG Tier 1 — direct vendors you contract with and (usually) assess Tier 2 — their subcontractors (4th parties) — rarely assessed Tier 3 — shadow IT & shadow AI tools — usually invisible to security entirely

The outward pulses in the diagram aren't decorative — they represent what continuous monitoring is meant to do: reach past the vendors you formally track and pick up signal from the layers most programs never look at.

Advertisement

What's actually driving the urgency

Four things changed at once, and together they explain why "we send a questionnaire once a year" stopped being defensible.

Four forces driving vendor risk management urgency in 2025 and 2026 Four cards: breach involvement roughly doubling from 15 to 30 percent between the 2024 and 2025 Verizon DBIR reports, average supply-chain breach cost of 4.91 million dollars and 267 days to contain per IBM's 2025 report, DORA and NIS2 regulatory enforcement beginning in 2025 and 2026, and 19 providers named critical under DORA in November 2025. Four forces driving VRM urgency in 2025-2026 Breach involvement is doubling 15% (2024) 30% (2025) Share of breaches involving a third party, Verizon DBIR 2024 vs. 2025 editions. Source: Verizon 2025 DBIR Cost and dwell time are highest $4.91M average supply-chain breach cost 267 days avg. time to identify and contain Source: IBM Cost of a Data Breach 2025 Regulation now has teeth DORA binding for EU financial entities since Jan 17, 2025 NIS2 issuing administrative penalties starting 2026 Source: DORA (EU 2022/2554), NIS2 Directive Concentration risk is now named 19 providers designated "Critical ICT Third-Party Providers" under DORA, incl. AWS, Microsoft, Google Cloud, Oracle, SAP, IBM. Source: ESAs CTPP list, Nov 18, 2025

Third-party involvement in breaches is rising sharply. Verizon's 2025 DBIR — built from more than 22,000 real incidents — found third-party involvement in breaches roughly doubled year-over-year, from about 15% to 30%. SecurityScorecard's 2025 Global Third-Party Breach Report, using a separate methodology across 1,000 breaches, put the 2024 figure at 35.5% (up 6.5 points from 2023) and found 41.4% of ransomware attacks now start through a third party. Different studies, different exact numbers — same clear trend line, moving in the wrong direction.

When it goes wrong, it goes wrong expensively and slowly. IBM's 2025 Cost of a Data Breach report puts the average supply-chain compromise at $4.91 million, with an average of 267 days to identify and contain — longer than any other breach category the report tracks. That dwell time is the real story: these breaches exploit a trust relationship, not a technical flaw, so they don't trip the alarms a normal intrusion would.

Regulators stopped treating this as a best practice and started treating it as law. The EU's Digital Operational Resilience Act (DORA) has applied to financial entities since January 17, 2025, mandating a formal ICT third-party register, pre-contractual risk assessment, and specific audit-rights and exit-strategy clauses in vendor contracts — with fines up to 2% of global annual turnover. NIS2 imposes parallel supply-chain security obligations across 18 sectors and began issuing administrative penalties in 2026. If you sell into the EU or bank with someone who does, these requirements already reach you indirectly even if you're not directly regulated.

Concentration risk has a name and a list now. In November 2025, EU regulators published the first official list of Critical ICT Third-Party Providers (CTPPs) under DORA — 19 companies, including AWS, Microsoft, Google Cloud, Oracle, SAP, and IBM, now subject to direct regulatory inspection because so much of the financial sector depends on them. Whether or not you're EU-regulated, the underlying question is worth asking of your own stack: how many of your critical functions quietly depend on the same handful of providers?

The old approach doesn't cover this anymore

A once-a-year questionnaire made sense when the main goal was documenting that due diligence happened. It doesn't hold up against a threat landscape moving this fast.

PracticeLegacy approach (pre-2023)2025-2026 approach
Assessment cadenceAnnual questionnaire, filed and mostly forgottenContinuous control monitoring layered on top of periodic deep-dives
Vendor visibilityFirst-party vendor list onlyMapped into subcontractors and 4th parties for critical vendors
Evidence sourceSelf-attested answers, taken at face valueSelf-attestation cross-checked against independent security ratings and breach monitoring
AI exposureNot assessed at allExplicit questions on embedded AI, model provenance, and data use
Regulatory backingContractual best practiceBinding law — DORA (EU finance, since Jan 2025), NIS2 (penalties from 2026)
Concentration riskRarely trackedActively mapped and, for finance, named by regulators (19 CTPPs, Nov 2025)
What to actually doTier vendors by business impact, put continuous monitoring on your top tier now, add AI-specific questions at onboarding, and map subcontractor/cloud concentration before a regulator — or an outage — makes you do it under pressure.

Notice that continuous monitoring augments questionnaires rather than replacing them. Ratings and external scans see what's exposed to the internet; they can't see whether a vendor actually encrypts backups or has a tested incident response plan. You need both — the point of a modern VRM program is layering evidence sources, not swapping one blind spot for another.

Where to start if your program is behind

  1. Build the real inventory first. Most organizations underestimate their vendor count significantly — pull every active SaaS subscription, API integration, and signed contract, using accounts payable and your identity provider's connected-apps list as sources security teams routinely miss.
  2. Tier by impact, not by spend. A $200/month tool with access to your customer database is a bigger risk than a $50,000/year vendor with no data access. Tier on data sensitivity and business criticality.
  3. Turn on continuous monitoring immediately. It requires no vendor cooperation and gives you baseline coverage across your entire vendor list while deeper questionnaires roll out to the critical tier first.
  4. Add AI-specific questions to onboarding. What model, whose data, where hosted, is your data used for training, is there a human in the loop for consequential decisions.
  5. Map concentration risk once a year. Ask which critical functions share a single cloud region, identity provider, or payment processor — and treat a "yes" as a finding, not a footnote.

Vendor risk management isn't a compliance checkbox anymore — it's operational risk management for a supply chain most companies never fully mapped. The organizations getting hurt in 2025 and 2026 aren't the ones with the fewest vendors; they're the ones who never built the visibility to know which vendor mattered most.

Sources: Verizon 2025 Data Breach Investigations Report; IBM Cost of a Data Breach Report 2025; SecurityScorecard 2025 Global Third-Party Breach Report; European Supervisory Authorities (ESAs) Register of Critical ICT Third-Party Providers, November 18, 2025; Regulation (EU) 2022/2554 (DORA); NIS2 Directive (EU) 2022/2555.

Frequently Asked Questions

What percentage of data breaches involve third parties in 2025?

Verizon's 2025 Data Breach Investigations Report (DBIR), which analyzed more than 22,000 security incidents, found that third-party involvement in breaches doubled year-over-year — from roughly 15% to 30%. SecurityScorecard's 2025 Global Third-Party Breach Report, based on a separate sample of 1,000 breaches, put third-party-linked breaches at 35.5% for 2024, up 6.5 points from 2023. The exact figure moves by methodology and year, but every major source agrees on the direction: third-party involvement in breaches is rising fast, not holding steady. Older "60% of breaches involve third parties" claims still circulating online trace back to smaller or older studies and should not be cited as a current figure.

Why is vendor risk management more urgent in 2025 than a few years ago?

Four forces are converging. First, the numbers are getting worse — third-party breach involvement roughly doubled in Verizon's 2025 DBIR versus the prior year. Second, the cost is unusually high: IBM's 2025 Cost of a Data Breach report puts the average supply-chain compromise at $4.91 million and 267 days to identify and contain — the longest of any breach type, because it exploits a trust relationship instead of a technical flaw. Third, regulation has teeth now: the EU's DORA has applied to financial entities since January 17, 2025, and NIS2 began issuing administrative penalties in 2026. Fourth, vendors increasingly embed AI features and third-party models, adding a whole new category of risk that most vendor questionnaires still don't ask about.

What is the difference between a security questionnaire and continuous monitoring?

A questionnaire (SIG, CAIQ, or a custom form) is a snapshot — it tells you what a vendor's security posture looked like, and how honestly they described it, on the day they filled it out. Continuous monitoring uses externally observable signals — exposed services, leaked credentials, certificate hygiene, DNS misconfiguration, dark-web chatter — to track posture between assessments. Neither replaces the other. Questionnaires surface internal controls (encryption policy, access reviews, incident response plans) that external scanning can't see; continuous monitoring catches drift and new exposure in the eleven months a year most organizations aren't asking their vendors anything at all.

What is fourth-party risk and why does it matter?

Fourth-party risk is the risk introduced by your vendors' own vendors — the cloud host, payment processor, or subcontractor your SaaS provider relies on, which you never contracted with and usually can't see. It matters because a breach two or three hops away can still reach your data; the 2020 SolarWinds and 2023 MOVEit incidents each cascaded through hundreds of organizations that had no direct relationship with the original compromised vendor. Most VRM programs stop at first-party vendor assessment. A more mature program asks critical vendors to disclose their own critical subprocessors at onboarding and renewal.

How does the DORA regulation affect vendor risk management outside the EU?

The EU's Digital Operational Resilience Act (DORA) has applied to financial entities operating in the EU since January 17, 2025, and it requires a formal ICT third-party register, pre-contractual risk assessment, and specific contract clauses covering audit rights and exit strategies. It only binds EU-regulated financial entities directly, but it affects everyone else two ways: any US or global vendor selling into EU financial services now has to meet DORA's contractual requirements, and regulators elsewhere (including US banking regulators and NIS2 in the broader EU economy) are converging on the same expectations — a documented vendor inventory, tiering by criticality, and evidence of ongoing oversight rather than a one-time sign-off.

What is vendor concentration risk?

Concentration risk is the exposure created when many of your critical functions — or an entire industry's — depend on the same small set of providers. In November 2025, EU regulators published the first official list of Critical ICT Third-Party Providers (CTPPs) under DORA: 19 companies, including AWS, Microsoft, Google Cloud, Oracle, SAP, and IBM, now subject to direct regulatory inspection because so much of the financial sector runs on them. You don't need to be EU-regulated to have this problem — if a single cloud region, identity provider, or payment processor going down would take out multiple business-critical systems at once, that's concentration risk, and it's worth mapping even if no regulator is asking you to.

How should companies assess the AI tools their vendors use?

Treat embedded AI as a distinct risk category in vendor due diligence, not an extension of general security review. Ask what model or model family the vendor uses, whose data trained it, where inference runs, whether your data is used to train or fine-tune the model, and whether there's a human in the loop for consequential decisions. IBM's 2025 Cost of a Data Breach report found breaches involving unsanctioned "shadow AI" cost roughly $670,000 more on average than the overall mean and were a contributing factor in about one in five breaches — largely because employees fed sensitive data into tools nobody vetted. The same blind spot exists one layer out, in the AI features vendors quietly ship into products you already approved.

How often should you reassess a vendor's security posture?

Tie frequency to tier, not to a calendar default. Critical vendors — those with access to sensitive data or systems whose outage would stop the business — warrant continuous external monitoring plus an annual deep-dive questionnaire and a review at any material change (new subprocessor, ownership change, breach disclosure). Mid-tier vendors can run on annual or biennial questionnaires with lighter continuous monitoring. Low-risk vendors (no sensitive data access) mostly need a one-time onboarding check and a trigger-based review if their access scope changes. A flat "reassess everyone annually" policy wastes effort on low-risk vendors while under-watching the handful that can actually hurt you.

What's the fastest way to start a vendor risk management program from scratch?

Inventory first, tier second, assess third. Most organizations underestimate their vendor count badly, so start by pulling every active SaaS subscription, API integration, and signed contract you can find — accounts payable and your SSO/identity provider's app list are both good sources. Tier what you find by data sensitivity and system criticality, not vendor size. Then run continuous, automated monitoring across the full list immediately (it requires no vendor cooperation) while you roll out deeper questionnaires to the critical tier first. Trying to deeply assess every vendor on day one is why so many VRM programs stall before they cover their real exposure.

vendor riskthird-party riskcontinuous monitoringDORA compliance