Third-party vendors have become an essential part of doing business, but they also introduce significant cyber risk. And, according to Spencer Timmel, Head of Cyber Insurance at Safety National, vendor risk is fast becoming a primary concern for many organizations today, with potentially far-reaching repercussions.
“Attackers are increasingly viewing vendors as a more efficient route into their ultimate targets,” he told IB. “Rather than attacking a well-defended organization directly, a threat actor may compromise a software provider, cloud platform, managed service provider, payroll company, claims administrator, or other partner that has trusted access to multiple customers. This creates a multiplier effect: one compromised vendor can expose hundreds or even thousands of organizations.”
Verizon’s 2026 Data Breach Investigations Report found third-party involvement in 48% of breaches in its dataset, reportedly representing a 60% increase from the prior year. What’s more, the report also identified vulnerability exploitation as a leading breach entry point, underscoring the risk created by widely deployed software and internet-facing systems.
According to Timmel, there are several trends contributing to the overarching problem, including;
“Vendor risk has therefore become both a cybersecurity issue and a business-resilience issue,” added Timmel. “A vendor incident can interrupt critical operations, compromise confidential information, create regulatory obligations and damage customer trust. NIST guidance treats cybersecurity supply-chain risk management as an enterprise-wide discipline covering the lifecycle of products and services, rather than simply a procurement checklist completed before signing a contract.”
When working with third-party vendors, privacy obligations and contractual data-protection requirements should be a key consideration. According to Timmel, one of the greatest challenges is maintaining visibility and control over personal information after it leaves the organization’s direct environment.
“Companies may know that a primary vendor receives data, but they do not always know where that data is stored, which employees can access it, whether it is used for secondary purposes, or which subcontractors receive it,” he warned.
Common challenges involving privacy include issues around data mapping and transparency, with organizations often lacking a complete inventory of the personal information shared with vendors.
“There are also issues around overlapping and sometimes conflicting legal and contractual requirements,” added Timmel. “A single vendor relationship may be subject to state privacy laws, sector-specific rules, contractual requirements and international data-protection laws. Requirements concerning consent, consumer rights, breach reporting, data localization and cross-border transfers may vary substantially.”
Timmel also listed subprocessor oversight, data minimization and retention, incident notification and use of AI as key challenges. To help reduce potential cyber or privacy-related risks, organizations should take preventative steps to improve due diligence rather than addressing issues only after an incident occurs.
“Vendor oversight should be risk-based,” advised Timmel. “A company should not apply the same review to an office-supply provider and a cloud vendor that stores sensitive customer information or supports a critical operational process.”
Before onboarding, Timmel suggests organizations should first classify the vendor according to;
And, for vendors presenting meaningful risk, essential due diligence should include:
“Incident provisions are especially important,” added Timmel. “Contracts should establish a clear and appropriately short period for reporting suspected security events - not merely confirmed legal breaches - and require the vendor, where appropriate, to preserve evidence, provide regular updates and cooperate with forensic, legal, regulatory and notification activities.”
Looking ahead to the next few months, organizations should continue to evolve alongside the risk landscape. Because cybercrime does not stand still, cyber risk management and cyber insurance practices should continue to adapt.
“Organizations should prepare now by developing a reliable vendor inventory, identifying critical and high-risk relationships, documenting fourth-party dependencies and assigning clear ownership,” added Timmel. “They should also standardize contractual requirements, establish measurable risk-acceptance procedures and build processes for continuously reassessing vendors.”
“The objective should not be to eliminate all third-party risk, which is unrealistic. It should be to understand where the organization is dependent, reduce avoidable exposure, prepare for vendor failure and make informed decisions about the risk that remains.”
Safety National’s cyber risk insurance is designed to protect large companies against global network security and privacy risks. The program reimburses damages and financial loss arising from accidental or malicious incidents involving computer networks, software, and data. Coverage options address a broad range of exposures, including liability, business interruption, reputational harm, regulatory penalties, and more. This program also promotes preparedness and effective incident response through an established network of cybersecurity and privacy breach vendors. Safety National’s organizational structure enables underwriting and claims decisions to be made quickly and thoughtfully. Safety National is a member of the Tokio Marine Group and is rated A++ (Superior), XV by A.M. Best.
This article was created in partnership with Safety National