An organization's perimeter no longer coincides with the assets it administers itself. Today, a significant share of operations depends on technology suppliers, integrated SaaS platforms, cloud providers, and partner APIs. Each of these connections widens the internet-facing surface and transfers, beyond the company's direct control, a fraction of the risk that audit and risk committees are responsible for overseeing.
The 2025 data made this dynamic difficult to ignore. Verizon's annual report documented that the third-party share of confirmed breaches doubled relative to the prior period, rising from 15% to 30% of the analyzed cases. The reading is direct: approximately one in three breaches now involves a link in the supplier chain, and not exclusively the internal systems of the affected organization.
This text examines why third-party exposure has grown, why traditional supplier assessment instruments have ceased to keep pace with it, and what continuous supervision of the third-party attack surface offers those accountable for risk at the board level.
What the 2025 Figures Establish
The analytical base is broad and convergent. Verizon's report examined more than 22,000 incidents and 12,195 confirmed breaches, the largest dataset ever assembled by the publication, and recorded the jump in the third-party share from 15% to 30%. This is a doubling within a single annual cycle.
SecurityScorecard, in its global third-party breach report, points in the same direction with an independent methodology: 35.5% of the breaches analyzed in 2024 originated in third-party access, a rise of 6.5 percentage points over the previous year. The publication itself notes that the figure tends to be conservative, given the underreporting and misclassification of incidents whose external origin is not always reconstructed.
Cost tracks frequency. IBM's Cost of a Data Breach Report found that a supply chain compromise costs, on average, US$4.91 million and takes 267 days to be identified and contained — the longest lifecycle among all tracked vectors. Duration matters as much as value: the longer a compromise originating in a supplier remains undetected, the wider the window for lateral movement and exfiltration.
There is also the propagation effect. SecurityScorecard's analysis recorded that, for each compromised supplier, an average of 5.28 downstream organizations were publicly affected, the highest level ever observed. A single point of failure in a shared provider frequently converts into a simultaneous incident for dozens of customers.
Ransomware connects directly to this vector. The same analysis indicates that 41.4% of ransomware attacks have come to originate through third parties. Access to the supplier has become the path of least resistance for the attacker seeking scale.
Why the Third-Party Surface Has Grown
The expansion is not accidental. It reflects the technological architecture that organizations adopted over the past decade.
Modern operations are composed of integrated services. Authentication delegated to identity providers, cloud processing, collaboration tools, payment gateways, data platforms, and file transfer software form a mesh of dependencies. Each integration requires credentials, API tokens, or network channels that remain active and exposed. Verizon's report identifies that compromised credentials remain the most common initial access vector, present in 22% of breaches, and a substantial portion of these credentials belong to inter-organizational integration contexts.
The most exploited vectors concentrate in specific categories of suppliers. The 2025 analyses point to IT services, cloud platforms, and software solutions as the most recurrent targets, with vulnerabilities in file transfer software figuring among the most used entry points. Sectors such as retail, technology, and energy recorded the highest rates of third-party breach.
The structural point is that a supplier's exposure has become, in practice, the contracting organization's exposure. An outdated file transfer server, an internet-accessible administrative interface, or an expired certificate in a partner's environment creates risk that materializes in the customer's business, even though no asset of its own was touched.
Why the Point-in-Time Questionnaire Failed
The predominant instrument for managing supplier risk remains the assessment questionnaire applied at the moment of contracting and, where there is discipline, renewed annually. This model carries three limitations that recent data exposes with clarity.
The first is temporal. The questionnaire captures a declaration of posture on a specific date. A supplier's attack surface, however, changes continuously: new services go into production, assets are published, vulnerabilities are disclosed, and certificates expire. An assessment valid in January describes a reality that no longer corresponds to the environment in June. Between one review cycle and the next, the organization operates on the basis of an expired snapshot.
The second is the nature of the evidence. The questionnaire collects self-declarations. It records what the supplier states about its controls, not what is effectively exposed to the internet at its perimeter. There is a consistent distance between documented policy and the actual configuration of assets, and it is in that distance that the incident originates.
The third is coverage. The formal assessment program reaches the suppliers contractually recognized as critical. The mesh of actual integrations is broader: it includes sub-suppliers, SaaS services adopted by business functions without passing through central assessment, and partner connections that have accumulated over time. The concentration of dependency on shared providers, which European regulation already addresses explicitly, rarely appears in an individual questionnaire.
The sector itself recognizes the mismatch. The central recommendation of the 2025 reports is the transition from periodic supplier review to real-time observation, so as to contain exposure before it propagates through the chain.
Regulatory Convergence
Third-party supervision has ceased to be a best-practice recommendation and has become a regulatory requirement. In the European Union, the Digital Operational Resilience Act (DORA), applicable to financial entities since January 2025, imposes the most prescriptive set of obligations on ICT third-party risk ever formulated in the sector. It requires a maintained register of all providers, with criticality classification, pre-contractual risk assessment, and concentration risk analysis. The NIS2 Directive, in force in the bloc since October 2024, extends supply chain security obligations to essential and important entities across eighteen sectors.
The joint reading of these instruments points to a single requirement: continuous visibility over the security posture of suppliers and over the exposure they generate. The sanctions are material, with penalties that reach percentages of annual global revenue. For Brazilian organizations with operations or customers in Europe, the requirement is immediate; for the others, the standard being established in international regulation tends to become a reference for audit and contracting.
From the Static Inventory to a Continuous View of Exposure
The conclusion that imposes itself on risk committees is operational, not conceptual. The supplier risk management program needs to incorporate a dimension the questionnaire does not provide: the continuous, external observation of the attack surface of each relevant third party.
This observation starts from an objective and verifiable question. Which assets of each supplier are exposed to the internet, in what state they are, and how that exposure evolves over time. Unlike the self-declaration, this is a measurement of the observable reality of the perimeter, obtained from the same perspective an attacker would have. It complements the questionnaire without replacing contractual diligence, and it transforms the assessment from an annual event into a permanent monitoring activity.
The gain for supervision is timeliness. The degradation of a critical supplier's posture, the publication of a new vulnerable asset, or the exposure of a sensitive service become detectable when they occur, and not in the following review cycle. Considering that a supply chain compromise takes, on average, 267 days to be contained, anticipating the identification of the exposure directly alters the extent of the damage.
The CSURFACE Position
CSURFACE continuously maps and monitors the external attack surface of organizations and of their digital chain of suppliers and partners. The platform identifies the internet-facing assets associated with each relevant third party, tracks the evolution of that exposure over time, and provides risk and audit committees with a verifiable view of the external posture of their chain, grounded in observation rather than self-declaration.
For those accountable for risk at the board level, the result is the replacement of the annual snapshot with a continuous, defensible reading of the risk that the supplier chain introduces into operations. In a scenario where one in three breaches originates in a third party, this continuity has ceased to be a differentiator and has become a condition of adequate supervision.
Sources
- Verizon 2025 Data Breach Investigations Report — official announcement
- Verizon 2025 Data Breach Investigations Report (PDF)
- SecurityScorecard 2025 Global Third-Party Breach Report (PDF)
- SecurityScorecard — 2025 report announcement
- IBM Cost of a Data Breach Report 2025 — supply chain data
- Centraleyes — DORA's Third-Party Risk Standards in 2025
- Brandefense — NIS2 and DORA Compliance for Third-Party Risk Management