- Data Privacy
- 30th Aug 2026
- 1 min read
Third-Party Data Breaches Take 258 Days to Contain
- Written by
In Short..
- Supply-chain compromise takes longest to catch: 258 days to identify and contain, 11 days above the global average of 247 days, tied for the slowest attack path in IBM's 2026 study.
- It is the second most common initial attack vector: Behind phishing, supply-chain compromise now ranks ahead of valid-account abuse, drive-by compromise and social engineering, which are tied for third.
- Annual assessments capture a single point in time: A supplier can pass a review in January and be compromised in March, with no visibility until the next scheduled cycle or someone outside the organisation reports it.
- Malicious and criminal attacks are rising: Up to 55% of all breaches in the 2026 study, from 51% the year before, meaning most third-party exposure is now deliberate.
Breaches that start with a compromised supplier take an average of 258 days to identify and contain, according to the IBM Cost of a Data Breach Report 2026, conducted by Ponemon Institute. That is 11 days longer than the global average of 247 days, and it ties supply-chain compromise with replication through removable media as the slowest attack path IBM measured. If your third-party risk programme still runs on an annual questionnaire, that gap is the number your board should see.
Expert View
Matt Davies Chief Product Officer, SureCloud |
What our experts say about closing the third-party detection gap
"The pattern we see with every third-party breach post-mortem is the same: the vendor passed their last review months earlier. That review was accurate on the day it was signed off. Continuous monitoring is what keeps it accurate every day after." |
The Data: Supply-Chain Compromise Is Slow to Catch and Getting More Common
Supply-chain compromise, where attackers use a trusted supplier's software, credentials or systems to reach the target organisation, took 258 days to identify and contain in the IBM Cost of a Data Breach Report 2026. Only breaches involving data replicated onto removable media took as long. Every other attack vector IBM measured, including phishing, social engineering and valid-account abuse, was faster to catch.
The average cost of a breach where supply-chain compromise was the initial attack vector was $4.96 million. That figure sits close to the study's global average, which means the real cost of a slow-to-detect supply-chain breach shows up less in the headline number and more in the 258 days of undetected exposure that precede it.
|
Attack Vector |
Days to Identify + Contain |
Average Cost (IBM 2026) |
|
Supply-chain compromise |
258 days |
$4.96 million |
|
Phishing (voice or SMS) |
251 days |
$5.29 million |
|
Social engineering |
254 days |
$5.23 million |
|
Abusing valid accounts |
243 days |
$5.07 million |
|
Global average (all vectors) |
247 days |
$4.99 million |
Why the detection gap matters commercially
The detection gap has commercial weight beyond the headline cost figure. Every additional day a supply-chain compromise goes undetected breaks down into four compounding costs:
- Extended data exfiltration: Every day a breach remains undetected, attackers continue to access, copy or exfiltrate data through the compromised supplier's connection. The exposure compounds.
- Higher remediation cost: IBM's 2026 data shows breach lifecycles beyond 200 days cost materially more than those contained faster. A supply-chain compromise sitting at 258 days is already past that threshold before containment even begins.
- Regulatory exposure: UK GDPR and equivalent frameworks require breach notification within 72 hours of becoming aware of a breach. That clock only starts once an organisation becomes aware a supplier has been compromised. The liability window grows with every day of non-detection.
- Reputational damage: A breach disclosed months after the fact, by an external party such as a regulator, a researcher, or the press, carries a disproportionate reputational cost.
These four costs compound the longer a compromise stays undetected, which is exactly why continuous third-party monitoring is built around detection speed.
Supplier Compromise Is Now the Second Most Common Attack Path
For the fourth year running, phishing was the top initial attack vector into breached organisations, used in 17% of attacks. Supply-chain compromise ranked second on its own, ahead of a group tied for third: abusing valid accounts, drive-by compromise, and social engineering.
After phishing, the single most common way attackers reach an organisation is through a supplier or technology provider, one step removed from the organisation's own infrastructure.
IBM's 2026 data also shows malicious and criminal attacks rose to 55% of all breaches studied, up from 51% the year before. A majority of breaches are now deliberate, targeted and criminal, and supply-chain relationships are one of the primary routes attackers use to reach them.
What this means for third-party risk management
The attack-vector data reframes the third-party risk question around two things: whether a supplier's security posture can resist a targeted, deliberate attack, and whether the organisation would know quickly if it couldn't.
A supplier that passes an annual vendor assessment in January can be compromised in March. With the only visibility into that supplier's posture being a questionnaire completed eight months earlier, a detection timeline stretching toward 258 days becomes the likely outcome.
Why Annual Vendor Assessments Cannot Close the Detection Gap
Annual vendor assessments serve a legitimate purpose. They establish a documented baseline of a supplier's security controls, policies, and compliance posture at a point in time. The problem is that phrase: at a point in time.
The point-in-time problem
A questionnaire-based vendor assessment captures a snapshot. The supplier answers questions about their security programme as it exists on the day they complete the form. That assessment is then filed, reviewed, and used as the basis for risk decisions for the next twelve months.
In those twelve months, the supplier may undergo a significant infrastructure change, onboard a new sub-processor with weaker controls, suffer an undisclosed security incident, experience staff turnover in key security roles, or fail to renew a certification that was central to their assessment score.
None of these events would be visible to the assessing organisation. The risk posture on file states low risk. The actual risk posture may have shifted materially, and the next scheduled review may be months away.
Annual assessments were designed for a calmer, slower-moving threat environment. They assume a supplier's risk posture is relatively stable between assessments. That assumption is what's actually breaking: a supplier's risk can now shift enough within a single assessment cycle that the next scheduled review is already out of date before it happens.
Spreadsheets and Email Make the Problem Worse
Even organisations that recognise the limitations of annual assessments often find their operational workflow compounds the problem. When third-party risk management runs on spreadsheets and email, the structural delays are significant, and they're baked into the process itself.
Chasing suppliers for completed questionnaires, certificates and policy documents by email introduces weeks of delay into every assessment cycle. Reminders, escalations and progress tracking are all manual, which means they rarely happen consistently between scheduled review cycles.
With hundreds of suppliers in scope, a spreadsheet-based programme cannot dynamically surface which suppliers represent the highest current exposure. Risk teams end up spending time on whichever suppliers respond quickest, regardless of where exposure actually sits. Assessment data, remediation actions and audit evidence also tend to live scattered across different files, inboxes and folders, so when a regulator or board asks for evidence of supplier oversight, assembling it becomes a significant manual exercise on its own.
In the context of a 258-day detection window for supply-chain compromise, that operational drag becomes a direct contributor to the gap.
What Continuous Third-Party Monitoring Looks Like in Practice
Continuous monitoring means building a risk-weighted programme that matches scrutiny to supplier exposure and adjusts monitoring frequency accordingly, and that surfaces changes in real time regardless of where a supplier sits in the assessment cycle.
Step 1: Tier your suppliers by exposure
Supplier risk varies widely. Tiering should reflect data sensitivity, system access, business criticality, and regulatory exposure. Tier-one suppliers, those that score high across multiple dimensions, warrant the most intensive monitoring cadence. Tier-three suppliers may need only annual assessment with automated alert triggers.
Step 2: Build a live monitoring feed
A continuous third-party risk management programme feeds multiple data sources into a live monitoring view against each supplier record: security ratings and external threat intelligence, breach disclosures and regulatory filings, control changes and certification updates, and assessment progress and remediation status. When any of these signals change, the system surfaces it against the relevant supplier record without waiting for the next scheduled review.
Step 3: Auto-escalate, audit, and act
The monitoring feed is only as useful as the workflow it triggers. A mature continuous monitoring programme auto-escalates material changes in supplier risk posture to the responsible risk owner, maintains an auditable trail of every signal received and every remediation action taken, stores all signals in the same GRC record as the formal assessment, and enables a rapid response the moment a supplier is identified in a breach disclosure, well ahead of the next assessment cycle.
Periodic assessments stay part of the programme; continuous monitoring is what fills the detection window between a third-party breach and its discovery with active signal.
SureCloud's guide to third-party cybersecurity risk in 2026 walks through the tiered monitoring cadence and response SLAs behind this kind of programme in more detail.
Regulatory Pressure Is Moving in the Same Direction
The shift from periodic to continuous oversight is a response to the threat data, and regulators are arriving at a similar conclusion, encoding it into law.
DORA: continuous monitoring for critical ICT third parties
The Digital Operational Resilience Act (DORA) entered into application on 17 January 2025 and is now in force for financial entities across the EU and for firms operating in EU markets. Among its requirements is oversight of critical ICT third-party providers, including a Register of Information that financial entities must keep current. DORA treats third-party oversight as a continuous discipline that runs alongside the business, year-round.
For financial services organisations in scope, that's already a live obligation.
NIS2: an EU obligation with an indirect UK route
The NIS2 Directive extends supply-chain security obligations to a significantly broader set of sectors than its predecessor, including energy, transport, health, digital infrastructure and other essential and important entities. NIS2 is EU legislation. Its transposition deadline for EU member states was 17 October 2024, and it's already in force across the bloc, though the European Commission has referred several member states to the Court of Justice over incomplete transposition.
NIS2 reaches UK organisations only indirectly, through EU customers, data flows or supply-chain relationships with EU-regulated entities. The UK is running its own parallel track: the Cyber Security and Resilience Bill, which cleared the Commons and entered the House of Lords in mid-2026. Once in force, it'll extend supply-chain oversight duties to UK-regulated sectors on a similar logic to NIS2, with continuous oversight as the baseline expectation.
The convergence of commercial and regulatory logic
But the commercial case and the regulatory direction of travel, in both the EU and the UK, now point the same way. Organisations that invest in continuous third-party monitoring reduce the detection gap that IBM's report measures, and build the documented oversight capability that regulators are increasingly expecting, whichever regime eventually applies to them.
The organisations that will struggle most treat regulatory compliance as the ceiling of their third-party risk programme. The data suggests it should be the floor.
How SureCloud Closes the Third-Party Detection Gap
SureCloud calls this discipline Secure, Proven and Repeatable: AI You Can Trust. SureCloud's Third-Party Risk Management platform is built around the operational reality most TPRM programmes share: hundreds of suppliers to track, limited time to do it, and a workflow still built around periodic assessment.
Replacing spreadsheets with structured workflow
SureCloud replaces email-and-spreadsheet assessment processes with standardised, automated workflows. Supplier questionnaires are issued, tracked and chased automatically. Evidence is collected and stored against the supplier record, and assessment cycles run to schedule without manual intervention. The result is a 50% reduction in third-party risk assessment time, so risk teams spend that time on analysis and response.
AI-surfaced exposure for focused monitoring
Not every supplier can receive the same level of attention, and that's exactly the problem a vendor risk manager juggling hundreds of accounts runs into daily.
Gracie AI Agents with Personas and Skills, a virtual GRC team rather than a bolt-on chatbot, surfaces the highest-exposure suppliers for focused monitoring, drawing on assessment data, control status and external signals to prioritise where human attention is most needed. This is the practical application of risk-weighted tiering: the programme concentrates scrutiny where exposure is highest and scales back where it's lower.
A single GRC system of record
Every monitoring signal, assessment response, remediation action and audit trail lives in the same GRC record. When a regulator or auditor asks for evidence of supplier oversight, the answer is a complete, timestamped record of every interaction with every supplier, including the signals that triggered reviews outside the normal assessment cycle. This matters for DORA and, prospectively, the Cyber Security and Resilience Bill, both of which expect organisations to demonstrate continuous oversight of their suppliers, documented as it happens.
SureCloud's third-party risk management capability is recognised in Gartner's 2025 Market Guide for Third-Party Risk Management Technology Solutions.
The Business Case in One Number
IBM's Cost of a Data Breach Report 2026 gives risk and compliance leaders a board-ready number: 258 days to identify and contain a supply-chain compromise, 11 days longer than the global average, at an average cost of $4.96 million. That's the number that belongs in the business case for continuous supplier risk monitoring.
The organisations that reduce their third-party breach exposure are those that pair periodic assessment with continuous, risk-weighted monitoring: live signals, automated escalation, a single system of record, and AI-driven prioritisation of the suppliers that matter most.
The 258-day detection gap comes down to programme design.
See how SureCloud closes the third-party detection gap.
Continuous monitoring, automated workflows, and a single system of record for every supplier relationship. |
Found this useful?
Choose SureCloud as a preferred source in Google and you will see more of our GRC guidance in Top Stories, AI Overviews and AI Mode. It takes one click and you can undo it at any time.
Close the Third-Party Detection Gap
FAQ’s
What is a third-party data breach?
A third-party data breach occurs when an organisation's data, systems or customers are compromised through a supplier, vendor, partner or other external party. The breach originates in the third party's environment but creates liability, regulatory exposure and reputational risk for the organisation that relies on them.
Why do supply-chain breaches take longer to contain?
Because the compromise originates outside the affected organisation's own infrastructure, detection depends on visibility into a supplier's environment, visibility most organisations only get at scheduled assessment points. According to the IBM Cost of a Data Breach Report 2026, supply-chain compromise takes 258 days to identify and contain on average, 11 days longer than the study's global average and tied with removable-media breaches as the slowest attack path measured.
What causes the third-party detection gap?
Several factors compound the delay. Annual assessment cycles mean supplier risk posture is only reviewed periodically, leaving changes undetected between reviews. Manual workflows slow evidence collection and risk escalation.
There's often no automated mechanism to surface external signals, such as breach disclosures or security rating changes, against the relevant supplier record. The result is a structural visibility gap that persists until a scheduled review or an external event closes it.
What is the difference between a vendor assessment and continuous monitoring?
A vendor assessment is a point-in-time evaluation of a supplier's security controls, policies and compliance posture, most often conducted annually via questionnaire. Continuous monitoring is an ongoing process that tracks changes in supplier risk posture between assessments, feeding real-time signals such as security ratings, breach disclosures and control changes into a live view of each supplier's risk status. The two are complementary: assessments establish the baseline, monitoring detects what changes after it is set.
Why are annual vendor assessments no longer enough on their own?
Annual assessments capture a supplier's posture on a single day of the year. Anything that changes after that, a new sub-processor, a lapsed certification, an undisclosed incident, stays invisible until the next scheduled cycle. With supply-chain compromise now the second most common initial attack vector in IBM's 2026 data, and the majority of breaches attributed to malicious and criminal actors, the threat environment changes faster than annual review cycles can track. Assessments remain necessary but need to sit inside a broader, continuous third-party risk programme.
How does third-party risk management help reduce breach risk?
A structured third-party risk management programme reduces breach risk by improving visibility and reducing response time. It tiers suppliers by exposure, applies the appropriate level of monitoring to each tier, and surfaces risk posture changes in real time, well ahead of the next scheduled assessment. When a supplier is identified in a breach disclosure or their security posture changes materially, the programme escalates it immediately, ahead of the next annual review. SureCloud's TPRM platform supports this with automated workflows, AI-driven prioritisation and a single system of record for all supplier risk data.
Platform +
Frameworks +
Products +
Industries +
Resources +
Company +
London Office
1 Sherwood Street, London, W1F 7BL, United Kingdom
US Headquarters
6010 W. Spring Creek Pkwy., Plano, TX 75024, United States of America
© SureCloud 2026. All rights reserved.