Verizon’s DBIR Shows Third-Party Breaches Scaling Upstream

Verizon’s DBIR shows third-party risk has become a high-speed breach vector, pushing security teams toward continuous vendor, software, and identity control.

Updated

What is this trend?

Third-party breaches are accelerating upstream as attackers chain flaws in widely used vendors, software, firmware, and embedded components before enterprises can contain them.

  • Third-party breaches rose 60% YoY and now account for nearly half of all breaches.
  • Attackers are chaining flaws in common vendors like Ivanti, Palo Alto, and Cisco.
  • Embedded components in telecom and IoT supply chains are widening exposure.
  • Regulators are pushing continuous third-party oversight and audit-grade controls.
  • Value is shifting to platforms that unify exposure, identity, and supply-chain governance.

What’s the latest?

Verizon’s 2026 DBIR shows the third-party problem has moved up another gear: breaches involving third parties rose 60% year over year and now make up 48% of all breaches.

How it developed

  1. Runtime Governance Tightens, Hack-for-Hire Networks Face Export Scrutiny, and Third-Party Risk Turns Remedial
    • Third-Party Risk Becomes a Remediation Workflow
  2. Agent Access Tightens, Offense Accelerates, Sovereignty Hardens, and PQC Becomes Procurement Deadline
    • Managed Security and Third-Party Risk Automation

Go deeper

Curated long-form picks on this trend — podcasts, videos, and analysis, by vantage.

Stay ahead in Cyber Security

Get the weekly brief in your inbox — the developments, what they mean by vantage, and what to do next.