Uncategorized

Vendor Risk Without the Guesswork: Moving from Scores to Strategy

Vendor Risk Without the Guesswork: Moving from Scores to Strategy

Vendor Risk Without the Guesswork: Moving from Scores to Strategy

SecurityScorecard has released the 2025 edition of their Global Third Party Breach Report. Drawing on the analysis of data from over 1,000 breaches, the report provides security leaders with insights into relevant factors such as industry-specific risks, evolving attack methods, and the tactics of threat actors. The information presented in the report is taken directly from SecurityScorecard’s proprietary risk and threat dataset.

The report reveals a rise in cyberattacks on the supply-chain and shows that just over a third of breaches are traced to third-party origins. The message that emerges from the report is that relying solely on risk ratings for supply chain partners isn’t enough in the current threat landscape. The threats now faced require an approach that uses real-time visibility, continuous monitoring, and strategic actions across procurement, operations, and security teams up and down the supply chain.

The criminals who are attacking 24/7 look to exploit vendor loopholes, subsidiary companies, software suppliers, or any other supply chain weakness. Defenders need to move past periodic vendor threat and risk assessments and adopt a continuous and dynamic risk monitoring model. The report’s conclusions urge business leaders (not just security professionals) to integrate risk intelligence and assessment into business decisions, so that it helps drive cyber resilience across the entire supply chain.

Download The Report For Free

Download the full 2025 Global Third-Party Breach Report for free (registration required) to understand which industries, vendors, and tactics are shaping today's risk landscape. The report provides detailed insights into attack patterns, threat actor behaviours, and strategic recommendations that can transform your vendor risk programme from a compliance exercise into a competitive advantage.

For MSPs in Ireland looking to protect their clients from evolving third-party and supply chain risks, contact Renaissance for expert advice on implementing SecurityScorecard solutions. Our team can help you build comprehensive risk management solutions that go beyond scores to deliver real security outcomes for your clients’ supply chain partners. Read on for some highlights from the report.

Security Ratings are Just the Start

Security ratings have served as an indicator of supplier security posture for many years. However, as the SecurityScorecard report shows, a more nuanced approach that goes beyond headline scores is needed in the current interconnected business supply chain landscape.

Relying on security ratings alone can give a false sense of confidence when considering supply chain security. A high score at a point in time is only the beginning of the vendor analysis process. The threat landscape is so dynamic that traditional vendor risk assessments that happen annually, or even quarterly, do not have the granularity to detect newly emerging threats. By the time you detect a supply chain vulnerability during the next assessment, attackers may already have exploited it to breach your security.

This does not mean that security ratings should not play a part in supply chain assessments. But they should be thought of as part of a broader, continuous process to evaluate vendor risk, and not the be-all and end-all of the process. They should play a part in how CISOs monitor and respond to changes in a vendor’s threat exposure. They should be part of the decision-making process about how your IT systems interface and interact with the vendor systems. And how you instruct suppliers to update or change their cybersecurity practices before you allow them to interact with your IT systems.

Turning Ratings into Strategy

The report shows that the most resilient organisations with respect to supply chain security move beyond passive risk scores to a proactive third-party risk management (TPRM) approach by integrating cyber risk insights directly into:

Procurement and Vendor Selection - Don’t just get a risk score and then move on. Set minimum score thresholds for suppliers and integrate those into procurement frameworks. Require vendors to demonstrate their security programmes and remediation timelines for any failing grades.

Due Diligence in M&A - Mergers and acquisitions have significant security blind spots. The report found that foreign subsidiaries are twice as likely to be a breach source. Including cybersecurity assessments, especially around third-party risk, in due diligence can help avoid inheriting liabilities after a merger.

Ongoing Service Assurance - The report reveals that ransomware groups are exploiting vulnerabilities in file transfer tools and cloud platforms to scale attacks across multiple organisations. Continuous monitoring of critical vendors is now essential. This is especially true in sectors like Retail & Hospitality, where over 52% of breaches come from third parties.

Cybersecurity by Design: Across the Ecosystem

A valuable insight in the report data is the variation in risk patterns. It shows that 41% of ransomware attacks now start via third-party breaches. Over half of all breaches stem from non-technical services like call centres, logistics providers, and via industry-specific third parties like healthcare support providers.

This means that a vendor risk assessment process can’t be IT-centric. It needs to cover legal, compliance, procurement, and operational domains.

Opportunities for MSPs

The information and recommendations in the SecurityScorecard report, along with the SecurityScorecard platform, provide an opportunity for MSPs to work with their clients to reduce supply chain risk. Download the report, have a look at the SecurityScorecard platform, and the options for MSPs.