Back to the threat counter
Threat brief

Third party breaches. The hidden risk.

Your security is only as strong as your weakest supplier. One compromised vendor can cascade across thousands of organisations, including yours.

The headline number

45%

of breaches involve third parties

Supply chain attack growth
+78%
Average vendors per enterprise
5,000+
Vendors touching sensitive data
89%

45%

Breaches involving third parties

+78%

Increase in supply chain attacks

2023 on 2022

5,000+

Average vendors per enterprise

89%

Vendors with sensitive data access

Attack surface

Your vendors are your vulnerability

Four categories of supplier account for the bulk of cascading incidents.

Cloud Providers

Shared infrastructure

When AWS, Azure, or Google Cloud has an incident, thousands of businesses are affected simultaneously. Your security is only as strong as your provider's.

Example: Microsoft Exchange Online breach exposed US government emails (2023)

Software Vendors

Trusted access

SaaS tools and enterprise software have deep access to your systems. A compromised vendor update can spread malware across all customers.

Example: SolarWinds attack affected 18,000+ organisations including Fortune 500

Service Providers

Data handling

Outsourced IT, payroll, and business services handle sensitive data. Their breach becomes your breach.

Example: Capita breach exposed data from hundreds of UK councils and NHS trusts

APIs & Integrations

Connection points

Every integration is a potential entry point. Attackers increasingly target the connections between systems rather than systems themselves.

Example: CircleCI breach compromised customer secrets and environment variables

The cascade effect

One breach, thousands of victims

Supply chain attacks are devastating because they multiply impact rather than adding to it.

MOVEit / Progress Software

2023
2,600+ organisations

BBC, British Airways, Boots, Shell, and US government agencies were all affected by one file transfer tool vulnerability

SolarWinds

2020
18,000+ organisations

US Treasury, Commerce, Homeland Security, Microsoft, and Intel were compromised through malware embedded in trusted software updates

Kaseya VSA

2021
1,500+ businesses

REvil ransomware spread through IT management software to MSP customers worldwide

Okta

2022
366 customers

Identity provider breach gave attackers potential access to authentication for hundreds of enterprises

You cannot control your vendors. Control your data instead.

Third party risk is unavoidable in connected systems. The dependable way to keep your most critical data out of a vendor breach is to hold it physically offline.

Mark Fermor
David Bailey
Kenny Phipps
Online Now
Concierge

Protect your data from third-party failures

Find out how offline isolation keeps your most critical assets safe, even when your suppliers are compromised.

Takes about 2 minutes. No account needed.

Free2 minsNo sign-up