This is the number every third-party risk program cites, and it is the strongest available argument that vendor review is worth doing at all.

It is also the number most often misread. Third-party involvement is coded broadly. It covers the case where a compromised supplier was the entry point and the case where a supplier simply held data that ended up exposed. Those need different controls, and a program that treats them as one problem tends to build a questionnaire that addresses neither.

The year-over-year movement is the part worth taking to a board. Supply chain breaches rose 60%, a rate of change that no static annual questionnaire cycle can track. If the review happens once at onboarding and then annually by template, the program is measuring a vendor's posture at a moment that has already passed.