BlueRadius Research

    Third-Party Cyber Risk Report 2026

    Third-party involvement in breaches has doubled to 30% in a single year. This report synthesizes the strongest public evidence on vendor and supply-chain cyber risk, with sources you can trace and figures you can cite.

    Published September 2026. By BlueRadius Research.

    A security leader reviewing a third-party and supply-chain risk dashboard

    Executive summary

    The perimeter most organizations defend is no longer their own. In the year covered by the 2025 Verizon DBIR, the share of breaches that involved a third party doubled from 15% to 30%. A vendor, a supplier, a managed service provider, or a piece of software in the build pipeline now sits in the path of roughly one breach in three.

    The cost follows the trend. IBM puts the average vendor or supply-chain breach at $4.91M, the second most expensive category after malicious insider threats, and among the longest-lifecycle breach types to resolve. In Europe, ENISA counts supply-chain risk among its major threat categories, at 10.6% of tracked activity. And the blast radius is non-linear: a single flaw in one file-transfer product, MOVEit, cascaded to more than 2,700 organizations.

    This report pulls those threads into one place. It reports only figures traceable to primary sources, labels every one, and separates third-party statistics from BlueRadius interpretation. The finding underneath the numbers is simple: third-party risk is now a first-party problem, and most vendor assessment programs were built for a smaller one.

    Key findings

    Third-party cyber risk in numbers

    Eight figures, each traceable to a named primary source, written to be cited.

    30%

    of data breaches now involve a third party, double the 15% recorded a year earlier.

    Verizon 2025 Data Breach Investigations Report

    81%

    of breaches that involved a third party also involved system intrusion, the most technical attack pattern.

    Verizon 2025 Data Breach Investigations Report

    $4.91M

    average cost of a vendor or supply-chain breach, the second-costliest category after malicious insider threats.

    IBM Cost of a Data Breach 2025

    54%

    of 2024 ransomware victims' domains had already appeared in infostealer credential dumps, tying identity leakage to breach risk.

    Verizon 2025 Data Breach Investigations Report

    10.6%

    of ENISA's 2025 threat-category distribution is supply-chain risk, a distinct and rising category in the European landscape.

    ENISA Threat Landscape 2025

    22%

    of breaches began with stolen credentials, the single most common initial-access vector.

    Verizon 2025 Data Breach Investigations Report

    2,700+

    organizations were exposed through a single file-transfer vendor flaw in the MOVEit campaign.

    Cybersecurity Dive: Progress MOVEit fallout

    94 days

    median time to remediate a secret leaked in a public code repository, a standing supply-chain exposure.

    Verizon 2025 Data Breach Investigations Report

    Third-party involvement in breaches has doubled

    Share of confirmed breaches involving a third party, year over year, from the Verizon DBIR.

    Source: Verizon 2025 Data Breach Investigations Report.

    Definitions

    What counts as third-party cyber risk

    The term is used loosely, and the looseness matters. Where you draw the boundary changes every number that follows.

    Vendor and supplier compromise

    A breach at a company you do business with that exposes your data or disrupts your operations. Change Healthcare, CDK Global, and Blue Yonder are recent examples where one provider's outage rippled across an entire industry.

    Software supply-chain compromise

    Malicious or vulnerable code entering through a dependency, update, or build pipeline. SolarWinds and MOVEit are the archetypes: trusted software became the delivery mechanism.

    Identity and access via third parties

    Contractors, managed service providers, and integrations that hold standing credentials or privileged access into your environment. The trust relationship is the attack surface.

    SaaS and digital service exposure

    Data and workflows that live inside cloud platforms you do not operate. A compromise of the provider, or of its configuration, is a compromise of you.

    The landscape

    The third-party threat landscape in 2026

    Three of the most authoritative annual datasets agree on the direction, even where they disagree on the size.

    Verizon DBIR 2025

    30%

    of breaches involved a third party, across 12,195 confirmed breaches in 139 countries. 81% of those also involved system intrusion.

    Source: Verizon 2025 Data Breach Investigations Report.

    IBM Cost of a Data Breach 2025

    $4.91M

    average vendor or supply-chain breach, the second-costliest category after malicious insider threats, and among the longest-lifecycle breach types to resolve.

    Source: IBM Cost of a Data Breach 2025.

    ENISA Threat Landscape 2025

    10.6%

    of ENISA's threat-category distribution is supply-chain risk, amid 42,595 new vulnerabilities disclosed across 4,875 analyzed incidents.

    Source: ENISA Threat Landscape 2025.

    BlueRadius analysis

    What the datasets reveal together

    Our contribution is not new incident data. It is a cross-dataset reading of the public evidence, with the method stated plainly.

    1. The number depends entirely on the definition, which means most organizations undercount

    Across the three primary datasets, the third-party signal ranges from about 10.6% to 30%, but each source measures something different. ENISA reports supply-chain risk as 10.6% of its threat-category distribution. IBM attributes 15% of breaches to supply-chain compromise. Verizon counts any third-party involvement, at 30%. The wider the lens, the larger the number, so the practical takeaway is that third-party exposure is almost certainly undercounted wherever it is scoped narrowly.

    One risk, three numbers: share of breaches by how third-party risk is scoped

    The same phenomenon measured under three definitions. Figures are not directly comparable because the datasets differ in scope, timeframe, and geography; the spread is the point.

    Source: Verizon 2025 Data Breach Investigations Report. Ranges compiled by BlueRadius from Verizon DBIR 2025 (30%), IBM 2025 (15%), and ENISA 2025 (10.6%)

    2. Third-party risk is non-linear, because one vendor sits in front of thousands

    A direct breach compromises one organization. A vendor breach compromises everyone downstream of that vendor at once. The 2023 MOVEit campaign is the clearest illustration on record: a single vulnerability in one file-transfer product reached more than 2,700 organizations and tens of millions of individuals, with intermediary file-transfer vendors passing that exposure on to their own downstream customers. The risk a vendor carries is not its own size, but the size of everything behind it.

    3. Identity is the connective tissue

    Stolen credentials are the single most common way a breach begins, at 22% of all breaches, and third-party relationships are, at their core, grants of credentials and access: an integration token, a service account, a contractor's login, a privileged connection into your environment. When the most common entry point and the defining feature of vendor relationships are the same thing, identity and privileged access belong at the center of any third-party risk program, not at its edge.

    Methodology

    • Sources. This analysis draws on published figures from the Verizon DBIR 2025, IBM Cost of a Data Breach 2025, ENISA Threat Landscape 2025, and public reporting and advisories on disclosed incidents.
    • What BlueRadius did. BlueRadius did not collect incident data or survey organizations. Our contribution is a cross-dataset comparison and interpretation of these public reports. Every raw figure is attributed to its originating source and is reproducible from that source.
    • Limitations. The datasets use different definitions of "third party," cover different timeframes (Verizon Nov 2023 to Oct 2024, ENISA Jul 2024 to Jun 2025, IBM 2025), and different geographies. Figures are therefore not directly comparable, and we present the range rather than a single blended number.

    Attack paths

    How third-party breaches begin

    The entry points are not exotic. They are the ordinary mechanics of trust between organizations.

    Top initial-access vectors across all breaches

    Stolen credentials and exploited vulnerabilities are the two dominant entry points overall, per the Verizon DBIR. For comparison, ENISA finds phishing in roughly 60% of European initial-access cases under its narrower dataset.

    Source: Verizon 2025 Data Breach Investigations Report. Phishing comparison from ENISA Threat Landscape 2025

    Credentials and identity

    22% of breaches begin with stolen credentials, and 54% of 2024 ransomware victims' domains had already appeared in infostealer credential dumps. A third party's compromised login is a valid login into your systems.

    Unpatched vulnerabilities

    20% of breaches begin with an exploited vulnerability. With 42,595 new vulnerabilities disclosed in a year and critical ones weaponized within days, a vendor's patch backlog becomes your exposure.

    Software supply chain

    Malicious dependencies, poisoned updates, and, newly, slopsquatting, where attackers register package names hallucinated by AI coding tools. The median time to fix a secret leaked in a public repository is 94 days.

    SaaS and remote access

    Standing integrations and remote-access paths into your environment expand the number of doors an attacker can try without ever touching your own perimeter.

    Blast radius

    The vendor blast-radius problem

    MOVEit remains the defining case study in why a single vendor compromise scales the way it does.

    1

    vulnerable product

    CVE-2023-34362 in Progress MOVEit Transfer

    2,700+

    organizations exposed

    including banks, universities, health and government bodies

    85M+

    individuals affected

    an evolving tally across independent victim trackers, still growing

    Source: Cybersecurity Dive: Progress MOVEit fallout. Organization and individual figures are evolving estimates aggregated by KonBriefing and Emsisoft; CISA advisory AA23-158A describes the campaign but states no victim count

    Slow detection carries a measurable cost penalty

    Average breach cost by lifecycle length. IBM describes supply-chain compromise as among the longest-lifecycle breach types, and breaches that run past 200 days cost materially more.

    Source: IBM Cost of a Data Breach 2025.

    Exposure

    Industries most exposed

    The evidence points to sectors that combine sensitive data, heavy vendor reliance, and shared platforms. We describe the pattern rather than rank it, because the public datasets do not support a precise ordering.

    Healthcare

    The Change Healthcare compromise disrupted claims and pharmacy operations nationwide, and MOVEit victims were concentrated in health and insurance.

    Financial services

    Dense vendor chains, shared clearing and processing platforms, and regulated data make one provider's breach a sector-wide event.

    Public sector and education

    Named repeatedly in the MOVEit victim pool, with large downstream exposure through shared administrative software.

    Manufacturing and automotive

    The CDK Global outage halted operations across thousands of dealerships, a supply-chain dependency turned single point of failure.

    Retail and logistics

    The Blue Yonder incident showed how a supply-chain planning provider's outage cascades into physical operations.

    Technology and SaaS

    Software providers are both targets and transmission vectors: a compromise there propagates to every customer downstream.

    Source: Verizon 2025 Data Breach Investigations Report. Incident examples per Verizon DBIR 2025 and public reporting

    Case studies

    Notable third-party and supply-chain incidents

    Four factual reference points, each disclosed publicly and covered by primary advisories.

    2023

    MOVEit / Cl0p

    A SQL injection flaw (CVE-2023-34362) in the MOVEit file-transfer product let the Cl0p group reach 2,700+ organizations and tens of millions of individuals, largely through vendors that used MOVEit on their customers' behalf.

    CISA advisory AA23-158A (Cl0p / MOVEit)
    2020

    SolarWinds Orion

    Trojanized Orion software updates were distributed to thousands of customers, prompting CISA Emergency Directive 21-01. The archetype of a build-pipeline compromise.

    CISA advisory AA20-352A (SolarWinds)
    2024

    Change Healthcare

    A compromise of a major healthcare clearinghouse disrupted claims and pharmacy operations across the US, cited in the DBIR as a service-provider breach with industry-wide downtime.

    Verizon 2025 Data Breach Investigations Report
    2024

    CDK Global and Blue Yonder

    Outages at an automotive-dealer platform and a supply-chain planning provider halted operations for thousands of downstream businesses, illustrating operational, not just data, blast radius.

    Verizon 2025 Data Breach Investigations Report

    The gap

    Why traditional vendor assessments miss the risk

    Most vendor risk programs still run on a point-in-time questionnaire completed at onboarding. The evidence above describes a moving target: credentials leak continuously, vulnerabilities are weaponized within days, and a vendor's posture on the day you sign says little about its posture on the day it is breached.

    Questionnaires also measure the vendor, not the blast radius. They rarely capture the downstream chain, the standing access a vendor holds, or the fourth parties your vendor depends on. MOVEit was not exposure to one company; it was exposure to everyone who used a company that used MOVEit.

    And they measure attestation, not evidence. A signed control claim is not proof that the control is operating today. The visibility gap is the distance between what a vendor asserts once and what is actually true continuously, which is where most third-party breaches live.

    Response

    What security leaders should do

    Priorities that follow directly from the evidence, not a generic checklist.

    Inventory every third party with standing access or data, including the fourth parties your critical vendors depend on.
    Treat vendor identities as your own: enforce MFA, scope and time-box access, and monitor service accounts and integration tokens continuously.
    Replace point-in-time questionnaires with continuous evidence, tied to the vendor's actual security signals rather than a one-time attestation.
    Tier vendors by blast radius, not by contract size. A small vendor with broad downstream reach outranks a large one with none.
    Assume vendor compromise in incident response: pre-build the playbook for a provider outage or breach before you need it.
    Track software supply-chain hygiene: dependency provenance, patch latency, and exposed secrets in code.

    Third-party risk checklist

    • Maintained inventory of vendors, integrations, and fourth parties
    • Data-flow and access map for each critical vendor
    • MFA and least-privilege enforced on all third-party access
    • Continuous monitoring of vendor security signals, not annual questionnaires
    • Vendor tiering by downstream blast radius
    • Software supply-chain controls: SBOM, dependency and secret scanning
    • Contractual breach-notification and audit rights
    • Third-party scenarios rehearsed in incident-response exercises

    Cite this research

    This report is free to cite and link. No permission is required for reasonable citation. Please attribute to BlueRadius Research and link to the report.

    BlueRadius. "Third-Party Cyber Risk Report 2026." BlueRadius Research, 2026. https://blueradius.io/research/third-party-cyber-risk-report-2026

    Methodology

    Research integrity and methodology

    How this report was built, and its limits, stated plainly so any figure can be checked against its source.

    Datasets and date ranges

    The report draws on three primary annual studies plus public incident reporting and government advisories: the Verizon 2025 DBIR (22,052 security incidents and 12,195 confirmed breaches across 139 countries, covering 1 November 2023 to 31 October 2024); the ENISA Threat Landscape 2025 (4,875 analyzed incidents, July 2024 to June 2025); and the IBM Cost of a Data Breach 2025. Incident-level facts, such as MOVEit and SolarWinds, are attributed to CISA advisories and established reporting.

    How records were selected and categorized

    Each source applies its own inclusion criteria and taxonomy. BlueRadius did not re-classify any underlying incident. We grouped each study's already-published figures by theme (involvement, cost, containment time, initial-access vector, blast radius) and reported them as the originating source defined them.

    How BlueRadius observations were derived

    The observations in the BlueRadius Analysis section are cross-dataset comparison and interpretation, not primary incident collection. The "share of breaches by scope" range simply places the three sources' own headline figures side by side (30% Verizon any-third-party, 15% IBM supply-chain compromise, 10.6% ENISA supply-chain category) to show how definition drives the number. No blended or derived percentage is presented as if it were measured.

    Known limitations and biases

    The sources use different definitions of "third party," cover different timeframes, and reflect different geographies, so their figures are not directly comparable and should not be summed. Datasets built on disclosed incidents undercount events that were never reported. Missing data is not treated as zero. Where the evidence did not support a specific chart or ranking, we omitted it rather than estimate.

    Findings in this report represent analysis of the cited public data, not a proprietary BlueRadius survey. BlueRadius did not survey organizations.

    BlueRadius analyzed publicly available cybersecurity incident, breach, regulatory, and threat data from the sources identified in this report. Data analysis and report development were supported by automated and AI-assisted tools, with findings reviewed by BlueRadius for accuracy and cybersecurity context.

    About BlueRadius

    Understand your third-party exposure

    BlueRadius is a practitioner-led cybersecurity practice. We help mid-market and regulated organizations run security programs that hold up under scrutiny, including the third-party and supply-chain risk this report describes. Our engagements run on Radius360, so the vendor register and evidence stay current between reviews rather than living in a spreadsheet.