Your Vendor List Is Not a Risk Assessment

Third-party involvement in breaches doubled in a single year. Most vendor-risk programs still produce an inventory and a questionnaire score, neither of which is a measure of loss.

The Verizon Data Breach Investigations Report has tracked third-party involvement in breaches for years. In its 2025 edition that figure doubled, from 15 percent to 30 percent of breaches year over year, the largest single-year move in the report’s 18-year history. Verizon defines the category broadly: a vulnerability in vendor software, direct vendor access being abused, or a shared platform being compromised all count.

Two other 2025 datasets point the same way. IBM ranks supply chain compromise as the second most common initial attack vector at 15 percent of breaches, the second most expensive at an average of $4.91M, and the slowest to contain at 267 days against a 241-day average. Unit 42 found that SaaS data was relevant in 23 percent of its incident-response cases, up from 6 percent three years earlier, and that more than 60 percent of cloud-native vulnerabilities sit in transitive dependencies, the libraries an organization pulls in without choosing them directly.

What the questionnaire misses

The standard response to this is a third-party risk program built around two artefacts: an inventory of vendors and a security questionnaire that yields a score per vendor. Both are useful for triage. Neither answers the question that matters for a risk decision: how much loss does this dependency actually carry? A vendor can score well on a questionnaire and still be the single point of failure whose two-week outage halts your operations.

The math the single-organization model misses

In quantitative risk terms, a supply chain scenario behaves differently from a direct-attack scenario in three ways. Contact Frequency is higher than a self-focused analysis suggests, because the relevant attack surface includes the vendor’s, not only your own. Resistance Strength is asymmetric: you do not control the vendor’s controls, trusted connections often bypass your perimeter, and smaller vendors frequently run a weaker posture. And Loss Magnitude multiplies: when an upstream provider is compromised, the secondary loss in that provider’s own risk scenario becomes the primary loss in each downstream customer’s scenario. A single upstream event produces many downstream loss events at once. A model that looks only at your own organization counts this once, if at all.

What to quantify instead

The useful exercise is not another questionnaire. It is a short list of scenarios: for each material vendor, what specifically fails if they are unavailable or compromised, what productivity loss that produces per day, and how long a realistic outage runs. The 267-day containment figure for supply chain incidents is a defensible starting point for the response-cost duration. Verizon’s 30 percent is a reasonable calibration anchor for how often a breach in your sector involves a third party at all. From there the analysis is ordinary quantitative risk modelling, and the output is a loss distribution per dependency rather than a colour-coded score.

An inventory tells you who your vendors are. A questionnaire tells you whether they filled in a form well. Neither tells you what they could cost you, and after a year in which third-party breach involvement doubled, that is the number worth having.