Introduction
Since the start of the decade, adversaries from well-funded nation states to common cybercriminals increasingly reach their attack targets via new vectors: vendors, software, and service providers that every modern organization depends on. Recent data from industry reports reinforces this change. Understanding that shift is the first step toward managing it through third-party risk management (TPRM) and ensuring continuous supply-chain ecosystem trust can be achieved.
A decade that began with a wake-up call
When the decade opened, a handful of incidents redefined how leaders think about trust in technology. The compromise of SolarWinds’ Orion application showed that a single trusted software update could quietly open doors inside thousands of organizations at once. The widespread exploitation of Microsoft Exchange servers showed how one flaw in commonly used software could be weaponized on a global scale. The attack on Kaseya VSA proved that compromising one provider of a remote management tool could ripple outward to the many businesses that relied on it.
These events shared a common theme and many lessons to be learned. The fastest way into a well-defended organization is often through a partner that the organization already trusts. Attackers discovered that the way into a well-defended organization was not through the front door, but through a side door; a supplier, software component, or service provider the organization already trusted. That insight has only deepened since. Microsoft specifically calls out more supply chain compromises as an emerging threat from attackers in their 2025 Microsoft Digital Defense Report.
Third-party involvement in breaches and impact on costs are growing exponentially
There’s no doubt enterprise organizations depend highly on global providers and deeply-integrated supply chains to run their businesses and retain much-needed cost, quality and time-to-market competitive advantages. What was once a series of headline incidents has become a measurable, sustained trend. The 2026 Verizon Data Breach Investigations Report found that breaches involving a third party reached 48 percent of all breaches, a 60 percent increase over the prior year. In roughly half of confirmed breaches, someone other than the victim organization played a part in the chain of events.
The significant financial consequences are just as clear. IBM’s Cost of a Data Breach Report 2026 research places the global average cost of a breach at a record $4.99 million, up 12 percent over the prior year. The average cost when the breach involved a supply chain partner increased by over $227 thousand. Not adequately managing third-party risk will likely have measurable financial impacts at the time of bad-day events when there is a data breach.
Attackers are innovating and staying ahead of defenders
The most important development is not simply that third-party attacks are more frequent. They have become more sophisticated in step with the way organizations build and buy technology. As development teams and business users adopt new tools at speed, like GenAI, attackers have followed them into that terrain. Adversaries are moving from smash and grab attacks and looking more like patient investors in future access. Let’s review recent, compelling examples.
Modern applications rely on shared packages that can be installed automatically across many systems and environments. Attacks like the Shai-Hulud ones highlight the weaknesses of identities and account access in the attack vector, and how a self-spreading worm can move through the trusted software package ecosystem to compromise systems and harvest credentials, secrets, and keys at scale. A single poisoned component can create downstream exposure for thousands of organizations.
In the XZ Utils case, an attacker spent years building trust within an open-source community before trying to insert a hidden backdoor into a widely used open-source library. This was a long-term effort to compromise foundational technologies millions of systems rely upon.
The old perimeter walls no longer mark the boundary
For years, organizations defended a clear edge and defensible perimeter. Firewalls, intrusion prevention, and endpoint protection were the organization’s main line of defense. That boundary has shifted. The new perimeter is increasingly defined by identities and the access they hold, not by the network. Trust itself is sought and attached.
Attackers can bypass traditional controls by stealing and abusing access tokens, cloud credentials, application keys, certificates, and other trusted credentials. Because the access can appear legitimate, conventional defenses may see routine activity rather than an intrusion, making detection difficult and giving attackers the time they need to carry out their goals.
Hiding in plain sight
Attackers are also abusing the same legitimate tools that IT teams and MSPs rely on every day. Microsoft in their MDDR found 79% of ransomware cases involved at least one remote monitoring and management tool. Huntress reported in their 2026 Cyber Threat Report that abuse of RMM tools rose a whopping 277 percent year over year and appeared in nearly one-quarter of investigated incidents. Stolen credentials were another major entry point, with suspicious logins representing 37 percent of the identity threats Huntress tracked.
AI is reshaping the types of attack and the organization’s attack surface
AI is changing supply chain risk in two ways. First, attackers are using it to work faster and at greater scale. Google Cloud’s Mandiant research describes a 2025 shift from experimentation to operational use, including adaptive tools that can rewrite code and agents that can navigate systems with limited human oversight.
Second, every supplier’s AI systems and use of AI is now part of an organization’s attack surface, whether it’s visible or not. Providers are rapidly embedding AI into software, digital products, and software, while organizations are connecting those tools to sensitive data and workflows. IBM found a 56 percent increase in AI-generated attacks. More than one in four organizations that experienced a malicious attack reported that it was AI-driven, adding an average of $1 million per breach. IBM also found that 92 percent of organizations reporting an AI-related breach lacked proper AI access controls.
The takeaways
Security and TPRM teams are facing a completely different world compared to the start of the decade. Digital supply chain complexity is no longer just about the ‘third-party.’ It’s forcing teams to look with wider optics across fourth and even nth parties! This complexity is happening against a landscape where supply chain attacks are now systemic; the perimeter has moved toward identity, access and trust, and AI increases both attacker capability and vendor exposure. This is happening at such an increasing speed such that cyber risk and TPRM can no longer be treated as a periodic compliance task across their vendor ecosystem.
Next in the series
Look for part two of the series where I’ll focus on the challenges of managing third-party cyber risk and why the current approaches are not delivering the resilience and ecosystem trust outcomes security and IT leaders must achieve.