Rajat Sharma
CWS
Rajat Sharma
Published content

expert panel
Companies rarely operate wholly within their own digital walls anymore. Critical business functions now depend on cloud platforms, software components, contractors, service providers and sprawling networks of suppliers, with each trusted relationship creating another possible route into an organization. And the risk is growing: Verizon’s 2026 Data Breach Investigations Report found that breaches involving third parties had increased 60% from the previous year’s dataset, accounting for 48% of all breaches analyzed.For attackers, compromising a well-connected partner can be faster and more effective than challenging each target’s defenses directly. A 2025 GitHub Action supply chain compromise demonstrated how a tool embedded in development workflows could expose credentials and other sensitive information across downstream users. Yet many organizations still evaluate cyber risk from outside partners primarily through questionnaires and scheduled reviews—methods that document security practices but often fail to reveal how risks, access or dependencies have changed since the assessment was completed.Reducing third-party cyber risk now requires organizations to look beyond whether a vendor passed an assessment and consider how trusted relationships affect their security and resilience over time. Below, members of the Senior Executive Cybersecurity Think Tank—with expertise in enterprise cybersecurity strategy, data breach prevention and risk management—explain what effective third-party risk reduction looks like today and where (and why) companies must move beyond checklist-driven oversight.

expert panel
Vulnerability management used to depend on a familiar rhythm: A new flaw was disclosed, public databases added analysis and security teams worked through the queue by severity. That model is now straining under its own weight. Vulnerability disclosures keep climbing, but the National Vulnerability Database has faced a significant operational breakdown: Beginning in early 2024, NIST sharply slowed enrichment of new CVE entries, and in April 2026, NIST formally announced it would no longer enrich all CVE entries, moving to a triage model that leaves the majority of submissions without scores, metadata or supporting analysis.Security leaders need to rethink defensive strategies, from monitoring to remediation. Even with the help of automation, teams with limited resources can’t approach every vulnerability with equal urgency, and waiting for more complete information can leave a business exposed while attackers keep moving. Security teams must learn to weigh new vulnerabilities in terms of the organization’s real environment, operational priorities and potential business impact. In a world of incomplete signals, security leaders need a sharper sense of which risks matter now, which can wait and which require a different kind of control altogether. Members of the Senior Executive Cybersecurity Think Tank are leaders in enterprise cybersecurity strategies, data breach prevention, risk management and modern security architecture. Below, they share how organizations can rethink vulnerability risk assessment as public data becomes less complete and focus attention where it can have the greatest protective impact.