The expanding attack surface
Every vendor you contract with sits inside a much larger, mostly invisible web: their own subcontractors, the cloud infrastructure they run on, and — increasingly — the third-party AI models and tools they've quietly built into their product. Most vendor risk programs only see the first layer.
The outward pulses in the diagram aren't decorative — they represent what continuous monitoring is meant to do: reach past the vendors you formally track and pick up signal from the layers most programs never look at.
What's actually driving the urgency
Four things changed at once, and together they explain why "we send a questionnaire once a year" stopped being defensible.
Third-party involvement in breaches is rising sharply. Verizon's 2025 DBIR — built from more than 22,000 real incidents — found third-party involvement in breaches roughly doubled year-over-year, from about 15% to 30%. SecurityScorecard's 2025 Global Third-Party Breach Report, using a separate methodology across 1,000 breaches, put the 2024 figure at 35.5% (up 6.5 points from 2023) and found 41.4% of ransomware attacks now start through a third party. Different studies, different exact numbers — same clear trend line, moving in the wrong direction.
When it goes wrong, it goes wrong expensively and slowly. IBM's 2025 Cost of a Data Breach report puts the average supply-chain compromise at $4.91 million, with an average of 267 days to identify and contain — longer than any other breach category the report tracks. That dwell time is the real story: these breaches exploit a trust relationship, not a technical flaw, so they don't trip the alarms a normal intrusion would.
Regulators stopped treating this as a best practice and started treating it as law. The EU's Digital Operational Resilience Act (DORA) has applied to financial entities since January 17, 2025, mandating a formal ICT third-party register, pre-contractual risk assessment, and specific audit-rights and exit-strategy clauses in vendor contracts — with fines up to 2% of global annual turnover. NIS2 imposes parallel supply-chain security obligations across 18 sectors and began issuing administrative penalties in 2026. If you sell into the EU or bank with someone who does, these requirements already reach you indirectly even if you're not directly regulated.
Concentration risk has a name and a list now. In November 2025, EU regulators published the first official list of Critical ICT Third-Party Providers (CTPPs) under DORA — 19 companies, including AWS, Microsoft, Google Cloud, Oracle, SAP, and IBM, now subject to direct regulatory inspection because so much of the financial sector depends on them. Whether or not you're EU-regulated, the underlying question is worth asking of your own stack: how many of your critical functions quietly depend on the same handful of providers?
The old approach doesn't cover this anymore
A once-a-year questionnaire made sense when the main goal was documenting that due diligence happened. It doesn't hold up against a threat landscape moving this fast.
| Practice | Legacy approach (pre-2023) | 2025-2026 approach |
|---|---|---|
| Assessment cadence | Annual questionnaire, filed and mostly forgotten | Continuous control monitoring layered on top of periodic deep-dives |
| Vendor visibility | First-party vendor list only | Mapped into subcontractors and 4th parties for critical vendors |
| Evidence source | Self-attested answers, taken at face value | Self-attestation cross-checked against independent security ratings and breach monitoring |
| AI exposure | Not assessed at all | Explicit questions on embedded AI, model provenance, and data use |
| Regulatory backing | Contractual best practice | Binding law — DORA (EU finance, since Jan 2025), NIS2 (penalties from 2026) |
| Concentration risk | Rarely tracked | Actively mapped and, for finance, named by regulators (19 CTPPs, Nov 2025) |
| What to actually do | — | Tier vendors by business impact, put continuous monitoring on your top tier now, add AI-specific questions at onboarding, and map subcontractor/cloud concentration before a regulator — or an outage — makes you do it under pressure. |
Notice that continuous monitoring augments questionnaires rather than replacing them. Ratings and external scans see what's exposed to the internet; they can't see whether a vendor actually encrypts backups or has a tested incident response plan. You need both — the point of a modern VRM program is layering evidence sources, not swapping one blind spot for another.
Where to start if your program is behind
- Build the real inventory first. Most organizations underestimate their vendor count significantly — pull every active SaaS subscription, API integration, and signed contract, using accounts payable and your identity provider's connected-apps list as sources security teams routinely miss.
- Tier by impact, not by spend. A $200/month tool with access to your customer database is a bigger risk than a $50,000/year vendor with no data access. Tier on data sensitivity and business criticality.
- Turn on continuous monitoring immediately. It requires no vendor cooperation and gives you baseline coverage across your entire vendor list while deeper questionnaires roll out to the critical tier first.
- Add AI-specific questions to onboarding. What model, whose data, where hosted, is your data used for training, is there a human in the loop for consequential decisions.
- Map concentration risk once a year. Ask which critical functions share a single cloud region, identity provider, or payment processor — and treat a "yes" as a finding, not a footnote.
Vendor risk management isn't a compliance checkbox anymore — it's operational risk management for a supply chain most companies never fully mapped. The organizations getting hurt in 2025 and 2026 aren't the ones with the fewest vendors; they're the ones who never built the visibility to know which vendor mattered most.
Sources: Verizon 2025 Data Breach Investigations Report; IBM Cost of a Data Breach Report 2025; SecurityScorecard 2025 Global Third-Party Breach Report; European Supervisory Authorities (ESAs) Register of Critical ICT Third-Party Providers, November 18, 2025; Regulation (EU) 2022/2554 (DORA); NIS2 Directive (EU) 2022/2555.