Third-Party Data Breaches Increased 49% — Why TPRM Is Now the Top Security Priority
The TPRM Reality
Third-party risk has become the primary attack surface . Third-party data breaches increased 49% year-over-year between 2023 and 2024, and 74% of security professionals cite insufficient vendor security as their biggest concern .
The September 2025 Jaguar Land Rover attack is a stark example: production halted for five weeks, triggering supply chain disruptions, with economic losses amounting to nearly £1.9 billion . The M&S 2025 cyber attack led to losses across multiple critical areas, with M&S's market value falling by over £700 million .
The TPRM Challenge
Manual Processes
34% of organizations admit they still rely on manual spreadsheets to identify and manage third-party risks .
Budget Volatility
When organizations face budget reductions, active team involvement in TPRM drops to 52%, compared to 84% in environments with expanding budgets .
Vendor AI Risk
Vendor AI governance introduces new challenges. A vendor tool that initially enters as a productivity assistant may later gain access to emails, meeting notes, internal documents, and customer records—significantly changing its operational risk profile after procurement .
How AI Is Transforming TPRM
Agentic AI is replacing periodic, questionnaire-driven assessments with continuous monitoring models :
|
Traditional TPRM |
AI-Powered TPRM |
|
Periodic assessments |
Continuous monitoring |
|
Manual questionnaires |
Automated data retrieval |
|
Static risk scores |
Dynamic risk scoring |
|
Point-in-time snapshots |
Real-time visibility |
|
Reactive (after breach) |
Proactive (before breach) |
Providers such as Wipro and HCLTech are augmenting their GRC and TPRM capabilities through AI-driven document processing and ecosystem integrations .
The Continuous TPRM Model
In 2026, modern organizations are centralizing third-party workflows within a dedicated platform to ensure :
- Clear ownership of vendor relationships
- Automated reassessment cadences
- Continuous evidence tracking
- Integration with external risk signals
- Real-time risk scoring
Key TPRM Questions
When evaluating vendor AI risk, organizations should ask :
- Does the vendor use customer data to train models?
- Which subprocessors provide AI capabilities?
- Is there human review for high-impact outputs?
- Are prompts, outputs, and decisions logged?
- Has the vendor done an AI impact/risk assessment?
The Regulatory Driver
Government agencies have begun actively offboarding contractors who fail to meet strict Cybersecurity Maturity Model Certification (CMMC) mandates or cannot guarantee that controlled unclassified information (CUI) is housed in a FedRAMP Moderate authorized environment .
Conclusion
Third-party risk management is no longer confined to initial vendor onboarding—it has become an ongoing operational requirement. Organizations that centralize TPRM workflows, implement continuous monitoring, and assess vendor AI risk will reduce their primary attack surface.
Action Items for Your Organization
- Inventory all third-party vendors with access to your systems or data
- Implement automated TPRM workflows
- Assess vendor AI risk
- Establish continuous monitoring for critical vendors
- Define reassessment cadences
- Integrate TPRM with your risk register