Third-Party Risk Management: Why Critical Cyber Exposure Now Sits Outside the Enterprise

Organizations have strengthened internal cybersecurity defenses for years, but the most significant cyber risks now often originate outside the enterprise. As businesses increasingly depend on vendors, processors, and SaaS providers, third-party risk has become a leading source of operational, regulatory, and reputational exposure.

The risk has moved beyond your walls

For years, enterprise cybersecurity strategy was built on a relatively straightforward premise: defend the perimeter, secure the endpoints, control access. That model has not simply evolved, it has been fundamentally displaced. Organizations today rely on a host of software-as-a-service providers and third-party vendors to accomplish all kinds of business operations. But the efficiency and scalability those solutions provide can also greatly expand the attack surface.

For CISOs and risk leaders, that shift changes the center of gravity in cyber risk management. The most consequential threat to the organization may now originate in the systems, credentials, and data stores of the vendors, processors, and SaaS platforms the business depends on. Seen through that lens, third-party cyber risk management is no longer a supporting control. It is a core resilience function.

Why threat actors prioritize concentrated third-party risk

This shift matters because threat actors have adjusted their strategy accordingly. Groups like Shiny Hunters (formerly Scattered Spider) are actively targeting concentrated risk where they can compromise a single system, vendor, or organization and create downstream impact for millions of people or hundreds of organizations at once. The model is efficient, scalable, and highly effective.

Beazley Security has observed the acceleration in third-party breaches both on the client level—for instance, a single client impactedby four different third-party vendor breaches in 2025—and more broadly, with increasing high-profile attacks on the developer ecosystem and supply chain, discussed in our Q1 Quarterly Threat Report. In other words, what once were isolated vendor incidents now look much more like a recurring operating condition.

For executive stakeholders, the implication is straightforward. Vendor security posture can no longer be treated as a secondary issue delegated to procurement or annual compliance review. It must be understood as a primary source of enterprise cyber exposure.

The Conduent breach and the business impact of vendor dependency

To understand what this looks like in practice, the Conduent case offers a clear example of concentrated vendor data processing risk. Conduent is a major contractor providing IT services to U.S. state governments and federal agencies, helping process Medicaid, food assistance, unemployment, and child support requests, while also handling payroll and HR functions for large corporations. The company processes data for more than 100 million people.

Against that backdrop, the scale of the incident becomes easier to understand. A ransomware group called SafePay infiltrated Conduent's network around October 2024 and remained in the environment for three months, unusual for ransomware actors, because they were exfiltrating more than 8 terabytes of data, including Social Security numbers, medical records, and financial information for millions of individuals.

Since February 2026, initial estimates that some 25 million people had their data exfiltrated have more than doubled to 62 million affected individuals as investigations have continued. Multiple U.S. federal and state agencies and large organizations were requiredto notify their customers that personal data had been stolen. Four state attorneys general opened investigations into the organization, focusing primarily on how long it took to identify the breach and notify affected organizations.

Taken together, the lesson is not only about a single breach. It is about the compound business impact of unmanaged third-party risk: regulatory scrutiny, litigation exposure, reputational damage, and delayed notification timelines that intensify each of those consequences.

Why continuous third-party risk monitoring has become a governance imperative

If the risk has become continuous, the control model must become continuous as well. Yet many organizations still rely on vendor risk programs built around questionnaires sent only to the most critical vendors, and only once a year. That approach no longer matches the speed or complexity of the threat environment.

More specifically, yearly questionnaires do not get to the root of risk, especially when AI-powered attacks evolve rapidly and vendor environments change constantly. A static review offers only a snapshot. What security leaders need instead is continuous vendor monitoring that treats third-party risk as a live operational signal rather than a compliance checkbox.

This is where governance and resilience intersect. A board or executive committee does not need perfect certainty about every vendor at every moment, but it does need confidence that the organization can identify, assess, and respond to emerging vendor exposure before it becomes a crisis.

Practical recommendations for better visibility

Many organizations still lack a clear picture of all third-party vendors in use. A stronger operating model starts with visibility. Use discovery methods that help identify SaaS applications across the organization, and supplement them with finance teams and company credit card records to surface shadow IT and unauthorized vendor relationships.

From there, several practical actions can materially reduce exposure:

  • Negotiate notification timelines contractually. For smaller vendors, it is often possible to establish contract clauses that legally require notification within 24 to 48 hours of identifying a compromise.
  • Minimize data retention at the vendor level. Some of the records stolen in the Conduent breach were years old and no longer needed. Data that is not retained cannot be exposed later.
  • Monitor vendors the way you monitor internal assets. Treat vendor security posture as a live signal, not a periodic snapshot.
  • Assume compromise as a planning posture. If a third-party vendor is breached, the key question is how far the impact can spread and how quickly the organization can contain it.

Ultimately, the organizations best positioned for this environment will not be those with the fewest vendor relationships. They will be the ones that can show those relationships are visible, assessed, monitored, and contractually governed with the assumption that breach is not exceptional, but manageable through resilience and disciplined oversight.

The risk has moved beyond your walls

For years, enterprise cybersecurity strategy was built on a relatively straightforward premise: defend the perimeter, secure the endpoints, control access. That model has not simply evolved, it has been fundamentally displaced. Organizations today rely on a host of software-as-a-service providers and third-party vendors to accomplish all kinds of business operations. But the efficiency and scalability those solutions provide can also greatly expand the attack surface.

For CISOs and risk leaders, that shift changes the center of gravity in cyber risk management. The most consequential threat to the organization may now originate in the systems, credentials, and data stores of the vendors, processors, and SaaS platforms the business depends on. Seen through that lens, third-party cyber risk management is no longer a supporting control. It is a core resilience function.

Why threat actors prioritize concentrated third-party risk

This shift matters because threat actors have adjusted their strategy accordingly. Groups like Shiny Hunters (formerly Scattered Spider) are actively targeting concentrated risk where they can compromise a single system, vendor, or organization and create downstream impact for millions of people or hundreds of organizations at once. The model is efficient, scalable, and highly effective.

Beazley Security has observed the acceleration in third-party breaches both on the client level—for instance, a single client impactedby four different third-party vendor breaches in 2025—and more broadly, with increasing high-profile attacks on the developer ecosystem and supply chain, discussed in our Q1 Quarterly Threat Report. In other words, what once were isolated vendor incidents now look much more like a recurring operating condition.

For executive stakeholders, the implication is straightforward. Vendor security posture can no longer be treated as a secondary issue delegated to procurement or annual compliance review. It must be understood as a primary source of enterprise cyber exposure.

The Conduent breach and the business impact of vendor dependency

To understand what this looks like in practice, the Conduent case offers a clear example of concentrated vendor data processing risk. Conduent is a major contractor providing IT services to U.S. state governments and federal agencies, helping process Medicaid, food assistance, unemployment, and child support requests, while also handling payroll and HR functions for large corporations. The company processes data for more than 100 million people.

Against that backdrop, the scale of the incident becomes easier to understand. A ransomware group called SafePay infiltrated Conduent's network around October 2024 and remained in the environment for three months, unusual for ransomware actors, because they were exfiltrating more than 8 terabytes of data, including Social Security numbers, medical records, and financial information for millions of individuals.

Since February 2026, initial estimates that some 25 million people had their data exfiltrated have more than doubled to 62 million affected individuals as investigations have continued. Multiple U.S. federal and state agencies and large organizations were requiredto notify their customers that personal data had been stolen. Four state attorneys general opened investigations into the organization, focusing primarily on how long it took to identify the breach and notify affected organizations.

Taken together, the lesson is not only about a single breach. It is about the compound business impact of unmanaged third-party risk: regulatory scrutiny, litigation exposure, reputational damage, and delayed notification timelines that intensify each of those consequences.

Why continuous third-party risk monitoring has become a governance imperative

If the risk has become continuous, the control model must become continuous as well. Yet many organizations still rely on vendor risk programs built around questionnaires sent only to the most critical vendors, and only once a year. That approach no longer matches the speed or complexity of the threat environment.

More specifically, yearly questionnaires do not get to the root of risk, especially when AI-powered attacks evolve rapidly and vendor environments change constantly. A static review offers only a snapshot. What security leaders need instead is continuous vendor monitoring that treats third-party risk as a live operational signal rather than a compliance checkbox.

This is where governance and resilience intersect. A board or executive committee does not need perfect certainty about every vendor at every moment, but it does need confidence that the organization can identify, assess, and respond to emerging vendor exposure before it becomes a crisis.

Practical recommendations for better visibility

Many organizations still lack a clear picture of all third-party vendors in use. A stronger operating model starts with visibility. Use discovery methods that help identify SaaS applications across the organization, and supplement them with finance teams and company credit card records to surface shadow IT and unauthorized vendor relationships.

From there, several practical actions can materially reduce exposure:

  • Negotiate notification timelines contractually. For smaller vendors, it is often possible to establish contract clauses that legally require notification within 24 to 48 hours of identifying a compromise.
  • Minimize data retention at the vendor level. Some of the records stolen in the Conduent breach were years old and no longer needed. Data that is not retained cannot be exposed later.
  • Monitor vendors the way you monitor internal assets. Treat vendor security posture as a live signal, not a periodic snapshot.
  • Assume compromise as a planning posture. If a third-party vendor is breached, the key question is how far the impact can spread and how quickly the organization can contain it.

Ultimately, the organizations best positioned for this environment will not be those with the fewest vendor relationships. They will be the ones that can show those relationships are visible, assessed, monitored, and contractually governed with the assumption that breach is not exceptional, but manageable through resilience and disciplined oversight.

No items found.

Learn more

Purple webinar banner titled 'Top Threats for 2025' with blurred city street and pedestrians in sunlight on the right.

For more on the critical cybersecurity controls you should be using and how they can protect your organization, replay the webinar on demand at:

Top Threats for 2025 (Webinar Replay)

watch webinar

More Insights

Afficher tout >

Beazley Security can help protect you

We offer services and solutions to help you prepare and stay resilient in the changing threat landscape. Prepare to learn more about how we can help you

Visit Solutions