Sara Velásquez in Dec 4, 2025Growth LeadThird-party risk management (TPRM) has become a critical function in today’s business environment. It is no longer an IT-only concern—it is now a central business issue, especially across the supply chain. According to the Verizon Data Breach Investigations Report 2024, more than 30% of data breaches are attributable to third parties, highlighting the need for rigorous, ongoing vendor assessments.
The average cost of a breach, according to the IBM Cost of a Data Breach Report 2024, exceeds USD $4.35 million—excluding loss of trust, legal exposure, and reputational impact.
Today, most incidents no longer originate from a compromised firewall—they come from a vendor with weak controls, an unknown subcontractor in the chain, or a SaaS application that was never evaluated. Signing an NDA and a security appendix is no longer enough to ensure protection. TPRM is now a requirement for true business resilience.
To date, third-party risk has surged due to four key factors:
Cyber attackers increasingly target vendors as “backdoors” into larger organizations. ENISA reported that 53% of supply chain attacks in 2024 exploited software or service providers.
Core SaaS platforms, MSP/MSSPs, consulting firms, payment platforms, logistics providers, remote support, OT integrators, etc. Many companies now depend more on their ecosystem than on their internal systems.
Regulatory and market pressure has increased significantly.
Examples include:
NIST Cybersecurity Framework (CSF) 2.0, which emphasizes governance and supply chain security
NIST SP 800-161, now a key reference for cybersecurity supply chain risk management
ISO/IEC 27036, which provides guidelines on how to manage supplier relationships
Regulations such as NIS2 and DORA, while European, set expectations that influence multinational operations worldwide. This affects not only IT but also Procurement and Supply Management, which must adapt to these new requirements.
Procurement teams no longer just “purchase services”—they are directly involved in managing risk. Today, security heavily depends on:
how vendors are classified,
what is required in RFPs,
how risks are documented,
which controls are mandated before signing.
Key factors to evaluate per vendor:
access to sensitive data
impact on core operations
connectivity to internal networks or OT/ICS environments
dependency level or single points of failure
This helps differentiate an OT support provider, a financial SaaS platform, and a catering service.
For critical vendors:
vulnerability management
encryption at rest and in transit
strong MFA and IAM
backups + continuity
monitoring and logging
documented security programs
For non-critical vendors: lighter but proportional controls.
Depending on vendor type and risk level, we recommend including:
incident notification requirements
encryption and data protection obligations
clearly defined shared responsibilities
compliance with applicable frameworks (NIST, ISO, regulatory)
Continuous oversight is essential. Critical vendors should comply with stricter controls such as:
security SLA reviews
monitoring of public breach disclosures
selective audits
Our experience supporting organizations across industries has revealed recurring gaps in most third-party risk programs. Identifying them early is key to reducing operational, legal, and cybersecurity risks:
Evaluating all vendors the same way: Risk levels vary widely; a uniform approach drives unnecessary costs and insufficient controls where they matter most.
Not involving Security, Legal, and Risk teams: Without multidisciplinary input, key contractual, technical, and regulatory requirements may be overlooked.
Not documenting risk decisions: The lack of traceability hinders incident analysis, exception justification, and audit readiness.
Ignoring subcontractors: Many incidents originate from indirect third parties—often the most overlooked part of the chain.
At Seccuri, we help organizations of all sizes strengthen their cybersecurity maturity and third-party risk management using frameworks such as NIST CSF 2.0. Our team—experienced globally in risk, OT, governance, and compliance—partners with you to design a practical and comprehensive 18-month work plan focused on closing real gaps and prioritizing critical capabilities.
We also double-click on talent: with AI-powered evaluations, we assess your team’s skills and capabilities, identify gaps, career paths, and the roles required to sustain a robust cybersecurity program over time.
The question is no longer if you will be attacked, but when. Preparation makes all the difference.
If you want to understand your current level and the concrete steps you should take next, schedule an introductory call with us here:
👉 https://calendly.com/seccuri-contact/30min?back=1&month=2025-06
Sources:
IBM. (2024). Cost of a Data Breach Report 2024. IBM Security & Ponemon Institute. https://www.ibm.com/reports/data-breach
Verizon. (2024). Data Breach Investigations Report 2024. Verizon Enterprise. https://www.verizon.com/business/resources/reports/dbir/
ENISA. (2023). Threat Landscape for Supply Chain Attacks. European Union Agency for Cybersecurity. https://www.enisa.europa.eu/publications/threat-landscape-for-supply-chain-attacks
Gartner. (2023). Third-Party Risk Management Trends and Findings. Gartner Research.
National Institute of Standards and Technology. (2024). NIST Cybersecurity Framework (CSF) 2.0. U.S. Department of Commerce. https://www.nist.gov/cyberframework
National Institute of Standards and Technology. (2022). NIST Special Publication 800-161 Rev. 1: Cybersecurity Supply Chain Risk Management Practices for Systems and Organizations. https://doi.org/10.6028/NIST.SP.800-161r1
National Institute of Standards and Technology. (2021). NIST Special Publication 800-171 Rev. 2: Protecting Controlled Unclassified Information in Nonfederal Systems and Organizations. https://doi.org/10.6028/NIST.SP.800-171r2
International Organization for Standardization. (2022). ISO/IEC 27001:2022 — Information Security, Cybersecurity and Privacy Protection — Information Security Management Systems. ISO.
International Organization for Standardization. (2020). ISO/IEC 27036-1:2020 — Information Security for Supplier Relationships. ISO.
European Union. (2023). NIS2 Directive: Directive (EU) 2022/2555 on Measures for a High Common Level of Cybersecurity Across the Union. Official Journal of the European Union.
European Union. (2022). DORA — Regulation (EU) 2022/2554 on Digital Operational Resilience for the Financial Sector. Official Journal of the European Union.
SecurityScorecard. (2024). Global Third-Party Cyber Risk Report. SecurityScorecard.
Ponemon Institute. (2023). The State of Third-Party Risk Management. Ponemon Institute.