A Panorays survey of 200 U.S. CISOs reported rising third-party security incidents alongside major visibility gaps across extended vendor ecosystems. In the findings cited by Help Net Security and SC Media, 60% of CISOs said third-party incidents increased over the past year, while only 15% said they have full visibility into third-party risk across deeper supply-chain tiers (third-, fourth-, and beyond). The reporting emphasizes that vendor dependencies now span core functions (cloud, software development, data processing, and AI services), expanding attack surface and enabling attackers to exploit less-monitored downstream relationships such as subcontractors and affiliates.
The survey also pointed to weak preparedness and governance as compounding factors: while 77% of CISOs view third-party risk as a major threat, only 21% reported having tested crisis response plans, and only 41% monitor risk beyond direct suppliers. Both articles highlight unmanaged/“shadow” AI tools as an emerging third-party risk driver, with only 22% of organizations having formal AI vetting processes and 60% of respondents identifying shadow AI as uniquely risky—creating new, poorly understood pathways for supply-chain compromise and regulatory exposure.

See attribution, scope, and your downstream exposure.
2 events from the most recent confirmed update back to the earliest known activity.
On January 14, Panorays reported that 60% of CISOs had seen an increase in third-party security incidents, while only 15% said they had full visibility into third-party risks and their supply chains. The report also highlighted weak preparedness, with only a small minority reporting tested third-party breach response plans.
Panorays conducted a survey of 200 U.S. CISOs examining third-party cyber risk, supply-chain visibility, incident trends, and the impact of AI tools and AI vendors on vendor-risk management.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See attribution, scope, and whether this vendor sits anywhere in your supply chain.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.