Companies rarely operate wholly within their own digital walls anymore. Critical business functions now depend on cloud platforms, software components, contractors, service providers and sprawling networks of suppliers, with each trusted relationship creating another possible route into an organization. And the risk is growing: Verizon’s 2026 Data Breach Investigations Report found that breaches involving third parties had increased 60% from the previous year’s dataset, accounting for 48% of all breaches analyzed.
For attackers, compromising a well-connected partner can be faster and more effective than challenging each target’s defenses directly. A 2025 GitHub Action supply chain compromise demonstrated how a tool embedded in development workflows could expose credentials and other sensitive information across downstream users. Yet many organizations still evaluate cyber risk from outside partners primarily through questionnaires and scheduled reviews—methods that document security practices but often fail to reveal how risks, access or dependencies have changed since the assessment was completed.
Reducing third-party cyber risk now requires organizations to look beyond whether a vendor passed an assessment and consider how trusted relationships affect their security and resilience over time. Below, members of the Senior Executive Cybersecurity Think Tank—with expertise in enterprise cybersecurity strategy, data breach prevention and risk management—explain what effective third-party risk reduction looks like today and where (and why) companies must move beyond checklist-driven oversight.
“Where companies overtrust checklists is the handoff after onboarding. A SOC 2 report, questionnaire or annual review can show intent, but it rarely shows today’s exposure.”
Stay Vigilant After Onboarding
Maman Ibrahim, Founder of Ginkgo Resilience LTD, says proper oversight begins with understanding the risk level associated with each vendor.
“Effective third-party cyber risk reduction starts with knowing which partners can hurt you most by access, data, service criticality and recovery dependency,” Ibrahim says. “Then, you manage them continuously through live risk signals, tested incident contacts, contract rights that matter, evidence of control effectiveness, and joint exercises for critical providers.”
He says that, for many organizations, vigilance wanes after the initial review has been completed.
“Where companies overtrust checklists is the handoff after onboarding,” Ibrahim says. “A SOC 2 report, questionnaire or annual review can show intent, but it rarely shows today’s exposure.”
He adds that as a vendor’s access, services and security posture evolve, it’s essential for security leaders to dig deeper.
“The harder questions are practical,” Ibrahim says. “What changed since the last review? Who can access our data? How fast will you tell us? Can you recover without us? Trust is evidence kept fresh.”
Inspect What Third-Party Code Does
Nirwan Dogra, Senior Software Engineer at Microsoft, says traditional methods of identifying malicious software may not be enough when attackers can continually alter how a harmful payload appears.
“Something often overlooked in third-party risk is that we still treat consumed artifacts as static objects, while attackers use them as delivery mechanisms,” Dogra says. “A signed package with a clean hash can still carry a malicious install hook. AI lets attackers generate thousands of functionally identical but syntactically unique payloads; no hash database or regex pattern will catch them.”
He explains that a more effective way to detect them is intent-aware inspection.
“We must understand what code actually does at the point of ingestion, whether it’s reading credentials, resolving unexpected domains, quietly shipping out environment variables, or anything else,” Dogra says. “We need to shift from, ‘Is this known-bad?’ to, ‘What is this trying to do?’”
Further, he stresses the importance of ongoing verification—even after a vendor relationship is approved.
“Most companies verify trust at onboarding and never revisit it,” Dogra says. “The software your vendor shipped last quarter isn’t the same today. Intent verification needs to happen before consuming any artifact, every single time; otherwise, there is no definitive way.”
Verify Every Artifact in Real Time
Jamshir Qureshi, Vice President of DevSecOps Engineering for MUFG Bank Ltd., says third-party security programs need to account for the possibility that even trusted partners may be compromised.
“Effective third-party risk reduction today means continuous, real-time verification of every artifact you consume, not just a signed paper,” Qureshi says. “You need zero trust for your supply chain: Assume partners get breached, limit their blast radius, and monitor live telemetry.”
He argues a once-a-year check-in with vendors is a dangerous strategy.
“Where do companies still fail? The annual questionnaire and last year’s pen test,” Qureshi says. “They trust a point-in-time SOC 2 report, then ignore what happens the next 364 days.”
He points to a tool he developed as one example of how organizations can verify software packages as they’re consumed.
“I built hcot-cli (pip install hcot-cli, check PyPI), which creates a hybrid chain of trust: cryptographic hashes, tamper-evident blockchain logs, and live OSV vulnerability scanning,” Qureshi says. “Instead of asking a vendor, ‘Do you sign code?’ you verify the actual package in real time. That’s third-party risk reduction that actually works.”
“Effective programs treat code provenance as a control through continuously maintained software bills of materials, signed and verified builds, scoped CI/CD credentials, and automated alerts when an upstream package or vendor changes ownership or behavior.”
Treat Code Provenance as a Control
Rajat Sharma, CEO of CWS, notes that supply chain attacks are now the most efficient way in for bad actors. “One compromised dependency, build pipeline or update channel reaches every customer downstream,” he says.
Reducing that exposure requires organizations to track the origins and integrity of software throughout the development and delivery process.
“Effective programs treat code provenance as a control through continuously maintained software bills of materials, signed and verified builds, scoped CI/CD credentials, and automated alerts when an upstream package or vendor changes ownership or behavior,” Sharma says.
He argues that service providers and trusted partners should be viewed through the same rigorous lens.
“Most programs still overrely on annual SOC 2s and questionnaires that grade documents, not behavior,” Sharma says. “Replace them with shared telemetry, least-privilege access and joint tabletops with the partners who will actually be on the call when something goes wrong.”
Monitor Vendor Exposure Continuously
Kumar Ritesh, Founder, Chairman and CEO of CYFIRMA, says attackers increasingly exploit the access organizations have already granted to outside parties.
“Trust is the attack vector,” Ritesh says. “Adversaries don’t break in; they log in through your suppliers, partners and service providers.”
He notes that while checklists measure compliance at a moment in time, attackers operate in real time. Therefore, effective third-party risk reduction requires continuous external visibility into vendors’ attack surfaces, not annual questionnaires.
“The right approach combines consolidated threat insight and visibility,” Ritesh says. “We need to know which vendors are actively being targeted or are already compromised through automated attack surface monitoring that flags changes the moment they occur. Breaches traced to third parties are typically visible in external threat data weeks before detection. The intelligence existed. The monitoring didn’t.”
The bottom line for Ritesh?
“Treat every trusted relationship as a potential threat vector and validate that trust continuously, not periodically.”
Understand the Full Chain of Dependencies
Pavel Mishchenko is a Manager of Security and IT Infrastructure Systems for large-scale critical infrastructure projects. He says vendor questionnaires—even highly detailed ones—can give organizations a false sense of security.
“Many companies still believe that managing third-party risks simply means sending a supplier a hundred questions in an Excel spreadsheet, getting all the right boxes ticked, and then solemnly declaring the risk closed,” Mishchenko says. “The problem is that, unfortunately, cybercriminals do not read such questionnaires.”
The challenge becomes even greater when organizations don’t know which subcontractors, platforms or providers their direct vendors depend on.
“Today, attacks increasingly come not via your direct suppliers but via fourth and fifth parties, the existence of which many organizations only learn about from an incident report,” Mishchenko says. “Therefore, the main question is no longer whether a vendor meets the requirements on paper but what access they have been granted and what damage their compromise could cause.”
He stresses that a robust third-party risk program must look past formal assurances and account for changes throughout the vendor ecosystem.
“Checklists create an illusion of certainty,” Mishchenko says. “Real resilience comes from understanding the chain of dependencies, engaging in continuous risk assessment, and rejecting the idea that trust, once granted, should be permanent.”
Connect Vendor Risk to Business Operations
Bhavya Bhandari, Cybersecurity Risk Management Leader, Financial Services at Ernst & Young US LLP, says effective third-party cyber risk reduction requires transitioning from annual assessments to ongoing visibility into vendor exposure, critical dependencies, privileged access and supply chain risk.
“Many organizations still rely on point-in-time reviews that provide a snapshot of security program maturity but fail to detect emerging vulnerabilities, compromised service providers or changes in risk posture,” he says.
Bhandari says risk reviews should help leaders understand the operational consequences if a third party is compromised.
“The focus needs to shift from checklists to ongoing monitoring, threat-informed reviews and understanding how third parties could impact critical business operations if compromised,” he says.
“Your most dangerous third party isn’t your biggest vendor. It’s the one with the deepest access and the weakest controls.”
Tier Vendors by Blast Radius
Gaurav Kulkarni, Senior Security Manager at Microsoft, says most third-party risk programs aren’t broken because of bad intentions; they’re broken because they’re built on a flawed assumption.
“A completed questionnaire does not reflect actual security posture,” he says. “A vendor who scores well on a point-in-time review can be compromised the next day.”
For Kulkarni, effective third-party risk reduction today must be grounded in three essential practices.
“We must tier vendors by blast radius, not by spend; replace point-in-time reviews with continuous monitoring; and secure contractual rights to real-time telemetry before a vendor goes live, not after an incident,” he says.
He explains that a company’s greatest exposure may not lie where leaders think it does.
“Your most dangerous third party isn’t your biggest vendor,” Kulkarni says. “It’s the one with the deepest access and the weakest controls.”
Kulkarni says the checklist model persists because it’s auditable—but he also cautions that “auditable” and “secure” are not the same thing.
“The organizations getting this right have stopped asking vendors what their security looks like and started verifying it themselves,” he concludes.
Building Stronger Third-Party Risk Defenses
- Prioritize vendors by the damage their compromise could cause. Evaluate partners based on access, data exposure, service criticality and recovery dependencies rather than treating every vendor as an equal risk.
- Inspect third-party code for behavior, not just known indicators. Intent-aware analysis can reveal suspicious activity that hashes, signatures and pattern matching may miss.
- Verify every software artifact at the point of use. Real-time checks help organizations identify changes or threats that weren’t present during onboarding or the last scheduled review.
- Treat code provenance as an active security control. Maintain software bills of materials, verify builds, restrict CI/CD credentials, and watch for unexpected changes in upstream packages or vendors.
- Continuously monitor vendors’ external exposure. Automated attack surface monitoring and threat intelligence can surface signs of targeting or compromise before a scheduled assessment would.
- Map the full chain of third-party dependencies. Organizations need visibility into fourth- and fifth-party relationships that could affect critical systems even when there is no direct contractual connection.
- Connect vendor risk to business operations. Reviews should identify how a third-party compromise could disrupt essential services, expose privileged access or weaken operational resilience.
- Tier vendors by blast radius, not by spending level. A smaller provider with deep access and weak controls may pose a greater threat than a large, well-known supplier.
Trust Must Be Earned, Tested and Reassessed
Effective third-party cyber risk management can no longer be built on questionnaires, annual reviews or compliance documents alone. Organizations need to understand which partners create the greatest exposure, limit the access those partners receive and continuously verify the software, services and relationships on which critical operations depend.
As supply chains become more interconnected, visibility and speed will matter as much as formal assurance. Companies that build real-time monitoring, threat-informed reviews and operational testing into their third-party programs will be better positioned to detect changing risks early, contain the impact of a partner’s compromise and keep trusted relationships from becoming unchecked attack paths.
MOST POPULAR
Beyond Automation: Measuring the Real Value of AI at Work
Top 5 AI Professional Associations: Membership Benefits & Reviews
Inspiring Ideas. Actionable Insights.
Senior Executive's Email Newsletters Deliver Fresh Solutions to Today's Leadership Challenges.
Subscribe Free
5 Attributes Executive Recruiters Seek When Hiring Chief Learning Officers
Top 500 CTOs to Watch in America
Boeing’s CLO Shares Selection Process for Leadership NeXt Program
