Observed telemetry. Counted from systems rather than asked of people. The limit is whose systems were visible to the party counting.
This is the number every third-party risk program cites, and it is the strongest available argument that vendor review is worth doing at all.
It is also the number most often misread. Third-party involvement is coded broadly. It covers the case where a compromised supplier was the entry point and the case where a supplier simply held data that ended up exposed. Those need different controls, and a program that treats them as one problem tends to build a questionnaire that addresses neither.
The year-over-year movement is the part worth taking to a board. Supply chain breaches rose 60%, a rate of change that no static annual questionnaire cycle can track. If the review happens once at onboarding and then annually by template, the program is measuring a vendor's posture at a moment that has already passed.
What this does not mean
This does not mean 48% of breaches were caused by a vendor. The coding includes incidents where a third party was merely a data holder rather than the attack path, so the figure overstates the case for entry-point controls specifically. It also does not support the common vendor claim that a security questionnaire would have prevented these. Nothing in the DBIR measures whether the affected organizations ran third-party reviews, so the data is silent on whether that control works.
Take this to your board
Forty-eight percent of breaches involved a third party, per Verizon's 2026 Data Breach Investigations Report, which counts confirmed incidents rather than asking people what they believe.
Say the peer figure and your own in the same breath. A number without a comparison invites the board to supply one from memory.
Sources
Every external figure on this page, with its origin, sample, and the date it was last checked by hand.
Third parties were involved in 48% of breaches analysed, and third-party supply chain breaches rose 60% year over year.
The DBIR draws on contributed incident data from many organizations, which skews toward incidents that were detected, investigated, and reported. Third-party involvement is coded broadly and covers both cases where a partner was the entry point and cases where a partner merely held affected data, so the figure should not be read as 48% of breaches being caused by a vendor.
Common questions
How often is a third party involved in a data breach?
Verizon's 2026 Data Breach Investigations Report found third-party involvement in 48% of breaches analysed, with third-party supply chain breaches rising 60% year over year. The coding is broad and covers both cases where a supplier was the entry point and cases where a supplier held affected data.
Does third-party breach data justify security questionnaires?
Partially. The DBIR establishes that suppliers are involved in roughly half of breaches, which is a strong argument for reviewing them. What the data cannot show is whether questionnaires help, because nothing in the report measures which affected organizations ran vendor reviews or what those reviews found.
How often should a vendor security review be repeated?
More often than annually for suppliers with real access. Verizon recorded a 60% year-over-year rise in third-party supply chain breaches, a rate of change no annual template cycle tracks. Continuous signals such as breach notifications, subprocessor changes, and certificate expiry beat a once-a-year questionnaire refresh.