A vendor can pass every questionnaire you send it and still be the reason you end up in a breach report.
That's the gap most third-party risk programs live in today. According to the 2026 Verizon Data Breach Investigations Report, 48% of breaches now involve a third party, up from 30% the year before and 15% the year before that. But most organizations still manage that risk with periodic assessments and separate threat feeds. Those methods can tell you whether a supplier passed a review last quarter. They can't tell you whether that same supplier is being targeted by a ransomware group this week.
The problem: Two views that don't talk to each other
Security teams generally have decent visibility into supplier posture and decent visibility into threat activity. What they don't have is a way to connect the two. A vendor can look compliant on paper while its security posture quietly degrades, or while it's actively discussed in underground channels, exposed in a breach, or targeted by a threat actor.
Organizations typically rely on a few separate approaches to manage third-party cyber risk:
- TPRM and GRC platforms assess vendors through questionnaires, reviews, and compliance workflows, but often provide a point-in-time view of risk.
- Security ratings and monitoring tools track a supplier’s security posture over time, but may not show whether that supplier is currently being targeted or compromised.
- Threat intelligence platforms and feeds surface ransomware, breach, threat actor, and cyber news activity, but that intelligence often sits separately from third-party risk workflows.
Manual research and cross-team investigation, understandably, is often used to bridge the gap, with CTI teams reviewing alerts, validating whether a supplier is actually affected, and then passing that information to TPRM, procurement, legal, or other stakeholders.
As a result, organizations may have strong visibility into supplier posture and strong visibility into threat activity, but those two views are often separate. Teams are left to manually determine which suppliers are under active threat, how serious the risk is, and where to act first.