Cybercriminals have found another way in - your vendors
As cybercriminals increasingly target vendors at scale, third-party risk is becoming difficult for businesses, and insurers, to ignore
Cybercriminals have found another way in - your vendors
PROFESSIONAL RISKS
By Emily Douglas
29 Sep 2026

Third-party vendors have become an essential part of doing business, but they also introduce significant cyber risk. And, according to Spencer Timmel, Head of Cyber Insurance at Safety National, vendor risk is fast becoming a primary concern for many organizations today, with potentially far-reaching repercussions.

“Attackers are increasingly viewing vendors as a more efficient route into their ultimate targets,” he told IB. “Rather than attacking a well-defended organization directly, a threat actor may compromise a software provider, cloud platform, managed service provider, payroll company, claims administrator, or other partner that has trusted access to multiple customers. This creates a multiplier effect: one compromised vendor can expose hundreds or even thousands of organizations.”

Vendor risk; a cybersecurity issue and a business-resilience issue

Verizon’s 2026 Data Breach Investigations Report found third-party involvement in 48% of breaches in its dataset, reportedly representing a 60% increase from the prior year. What’s more, the report also identified vulnerability exploitation as a leading breach entry point, underscoring the risk created by widely deployed software and internet-facing systems.

According to Timmel, there are several trends contributing to the overarching problem, including;

  • Greater dependence on cloud services, software-as-a-service and outsourced technology operations.
  • Increasing use of vendors with privileged network access or access to sensitive information.
  • Concentration risk, where many organizations depend on the same technology providers.
  • Limited visibility into fourth parties and other subcontractors.
  • Delayed remediation of vulnerabilities in vendor-managed systems.
  • Credential theft involving vendor accounts, remote-access tools and service accounts.
  • Ransomware attacks that disrupt a vendor’s customers even when customer data is not directly stolen.

“Vendor risk has therefore become both a cybersecurity issue and a business-resilience issue,” added Timmel. “A vendor incident can interrupt critical operations, compromise confidential information, create regulatory obligations and damage customer trust. NIST guidance treats cybersecurity supply-chain risk management as an enterprise-wide discipline covering the lifecycle of products and services, rather than simply a procurement checklist completed before signing a contract.”

‘Vendor oversight should be risk-based’

When working with third-party vendors, privacy obligations and contractual data-protection requirements should be a key consideration. According to Timmel, one of the greatest challenges is maintaining visibility and control over personal information after it leaves the organization’s direct environment.

“Companies may know that a primary vendor receives data, but they do not always know where that data is stored, which employees can access it, whether it is used for secondary purposes, or which subcontractors receive it,” he warned.

Common challenges involving privacy include issues around data mapping and transparency, with organizations often lacking a complete inventory of the personal information shared with vendors.

“There are also issues around overlapping and sometimes conflicting legal and contractual requirements,” added Timmel. “A single vendor relationship may be subject to state privacy laws, sector-specific rules, contractual requirements and international data-protection laws. Requirements concerning consent, consumer rights, breach reporting, data localization and cross-border transfers may vary substantially.”

Timmel also listed subprocessor oversight, data minimization and retention, incident notification and use of AI as key challenges. To help reduce potential cyber or privacy-related risks, organizations should take preventative steps to improve due diligence rather than addressing issues only after an incident occurs.

“Vendor oversight should be risk-based,” advised Timmel. “A company should not apply the same review to an office-supply provider and a cloud vendor that stores sensitive customer information or supports a critical operational process.”

The importance of ongoing due diligence

Before onboarding, Timmel suggests organizations should first classify the vendor according to;

  • The sensitivity and volume of information involved.
  • The vendor’s level of network or system access.
  • The operational importance of the service.
  • The potential effect of an outage.
  • The geographic locations in which information will be processed.
  • The vendor’s use of subcontractors.
  • Whether the relationship is subject to specific regulatory requirements.

And, for vendors presenting meaningful risk, essential due diligence should include:

  • Security and privacy documentation. Review independent audit reports and certifications where appropriate, such as SOC reports or relevant ISO certifications. These should supplement - not replace - a risk-based assessment.
  • Control validation. Evaluate controls such as multifactor authentication, encryption, vulnerability management, endpoint detection, logging, secure software development, access reviews, network segmentation and backup protection.
  • Data-governance review. Document exactly what information the vendor will receive, why it is required, where it will be stored, how long it will be retained and whether it will be shared with subprocessors.
  • Business-continuity analysis. Assess recovery capabilities, backup architecture, recovery objectives, crisis communications and the organization’s alternatives if the vendor becomes unavailable.

“Incident provisions are especially important,” added Timmel. “Contracts should establish a clear and appropriately short period for reporting suspected security events - not merely confirmed legal breaches - and require the vendor, where appropriate, to preserve evidence, provide regular updates and cooperate with forensic, legal, regulatory and notification activities.”

Not eliminating risk, but understanding where it lives 

Looking ahead to the next few months, organizations should continue to evolve alongside the risk landscape. Because cybercrime does not stand still, cyber risk management and cyber insurance practices should continue to adapt.

“Organizations should prepare now by developing a reliable vendor inventory, identifying critical and high-risk relationships, documenting fourth-party dependencies and assigning clear ownership,” added Timmel. “They should also standardize contractual requirements, establish measurable risk-acceptance procedures and build processes for continuously reassessing vendors.”

“The objective should not be to eliminate all third-party risk, which is unrealistic. It should be to understand where the organization is dependent, reduce avoidable exposure, prepare for vendor failure and make informed decisions about the risk that remains.”

About Safety National

Safety National’s cyber risk insurance is designed to protect large companies against global network security and privacy risks. The program reimburses damages and financial loss arising from accidental or malicious incidents involving computer networks, software, and data. Coverage options address a broad range of exposures, including liability, business interruption, reputational harm, regulatory penalties, and more. This program also promotes preparedness and effective incident response through an established network of cybersecurity and privacy breach vendors. Safety National’s organizational structure enables underwriting and claims decisions to be made quickly and thoughtfully. Safety National is a member of the Tokio Marine Group and is rated A++ (Superior), XV by A.M. Best.

This article was created in partnership with Safety National

Free newsletter

We'll keep you up-to-date with the latest breaking news, cutting edge opinion, and expert analysis affecting both your business and the industry as whole.

Free newsletter

Our daily newsletter is FREE and keeps you up - to - date with the world of Insurance. Please complete the form below and click on subscribe for daily newsletters from IB US.