This is the number every third-party risk program cites, and it is the strongest available argument that vendor review is worth doing at all.
It is also the number most often misread. Third-party involvement is coded broadly. It covers the case where a compromised supplier was the entry point and the case where a supplier simply held data that ended up exposed. Those need different controls, and a program that treats them as one problem tends to build a questionnaire that addresses neither.
The year-over-year movement is the part worth taking to a board. Supply chain breaches rose 60%, a rate of change that no static annual questionnaire cycle can track. If the review happens once at onboarding and then annually by template, the program is measuring a vendor's posture at a moment that has already passed.
Common questions
- How often is a third party involved in a data breach?
- Verizon's 2026 Data Breach Investigations Report found third-party involvement in 48% of breaches analysed, with third-party supply chain breaches rising 60% year over year. The coding is broad and covers both cases where a supplier was the entry point and cases where a supplier held affected data.
- Does third-party breach data justify security questionnaires?
- Partially. The DBIR establishes that suppliers are involved in roughly half of breaches, which is a strong argument for reviewing them. What the data cannot show is whether questionnaires help, because nothing in the report measures which affected organizations ran vendor reviews or what those reviews found.
- How often should a vendor security review be repeated?
- More often than annually for suppliers with real access. Verizon recorded a 60% year-over-year rise in third-party supply chain breaches, a rate of change no annual template cycle tracks. Continuous signals such as breach notifications, subprocessor changes, and certificate expiry beat a once-a-year questionnaire refresh.