Verizon’s DBIR Shows Third-Party Breaches Scaling Upstream
Verizon’s DBIR shows third-party risk has become a high-speed breach vector, pushing security teams toward continuous vendor, software, and identity control.
What is this trend?
Third-party breaches are accelerating upstream as attackers chain flaws in widely used vendors, software, firmware, and embedded components before enterprises can contain them.
- Third-party breaches rose 60% YoY and now account for nearly half of all breaches.
- Attackers are chaining flaws in common vendors like Ivanti, Palo Alto, and Cisco.
- Embedded components in telecom and IoT supply chains are widening exposure.
- Regulators are pushing continuous third-party oversight and audit-grade controls.
- Value is shifting to platforms that unify exposure, identity, and supply-chain governance.
What’s the latest?
Verizon’s 2026 DBIR shows the third-party problem has moved up another gear: breaches involving third parties rose 60% year over year and now make up 48% of all breaches.
How it developed
- Runtime Governance Tightens, Hack-for-Hire Networks Face Export Scrutiny, and Third-Party Risk Turns Remedial
- Third-Party Risk Becomes a Remediation Workflow
- Agent Access Tightens, Offense Accelerates, Sovereignty Hardens, and PQC Becomes Procurement Deadline
- Managed Security and Third-Party Risk Automation
Go deeper
Curated long-form picks on this trend — podcasts, videos, and analysis, by vantage.
If you operate in this industry
Vicarius finds 79% hit by known vulnerability incidents
News analysis interview with Roi Cohen on 79% known-vuln incidents and remediation “ticket trap” workflow gaps.
IT Brief UK · News
Read →AI-Driven Third-Party Breaches Surge
Analysis interview with Joel Molinoff and Jeff Gamet on AI-driven third-party breaches and faster remediation workflows.
Dark Reading · News
Read →
Rethinking Vulnerability SLAs and Supply-Chain Security Urgently Needed
Opinion on remediation SLAs and emergency workflows after rapid exploits, plus CI/CD supply-chain attack fallout.
CISO Talk by James Azar · Substack
Read →If you sell into this industry

Infrastructure Trust Risks Prompt Urgent Patch and Automation Measures
How-to Substack post on infrastructure trust risks, mapping upstream third-party breaches and zero-day exploitation.
CISO Talk by James Azar · Substack
Read →SentinelOne and Tenable Find Cyber Attackers Routinely Target Edge-Device Vendor Ecosystems Rather Than Individual Vulnerabilities
Research data from SentinelOne & Tenable on edge-device vendor ecosystems, driving third-party remediation workflows.
IT Voice Media Pvt. Ltd. · News
Read →
DORA turns vendor risk policy into a legal must-have
Explainer news piece on how DORA mandates vendor risk as a remediation workflow with tiering, registers, and contract terms.
FinTech Global · News
Read →If you invest in this industry
Third-party data breaches rose 60% in a year. Most vendor reviews still happen once.
News explainer on Verizon’s DBIR: third-party breaches up 60%, and why static vendor reviews miss risks.
Lee News Central · News
Read →Sophos Research Finds MSPs Are Acting as CISOs for Nearly Half of Customers
Research & data report on MSPs acting as CISOs, mapping third-party risk remediation workflows and tool consolidation.
Cybersecurity Insiders · News
Read →