Key Takeaways:
- Third-party involvement in breaches climbed 60 percent year over year to 48 percent of total breaches, per Verizon’s 2026 DBIR, making vendor risk a primary attack vector.
- The standard vendor questionnaire cycle, self-attested and unverified, wasn’t built to keep pace with that shift. A differently worded version of the same 200 questions for each client doesn’t produce faster or better assurance.
- A validated HITRUST assessment lets a vendor answer the third-party risk question once, through a certified assessment and shared responsibility matrix, instead of restarting due diligence with each enterprise client.
- Enterprise risk teams should weigh a vendor’s validated HITRUST certification differently than a self-attested questionnaire response, since independently verified assurance is a different class of evidence than a completed form.
Third-party involvement in breaches climbed 60 percent year over year, reaching 48 percent of total breaches, according to Verizon’s 2026 Data Breach Investigations Report. That means vendor risk is getting close to a coin flip in the space of twelve months, and the questionnaire-based way most organizations manage it wasn’t built for that shift.
THIRD-PARTY INVOLVEMENT IN BREACHES JUMPED 60 PERCENT IN A YEAR
Verizon’s own dataset from the prior year put third-party involvement at roughly 30 percent. A year later, it’s up to 48 percent, and the report ties that growth to how much organizations now depend on external service providers and software vendors: each integration, outsourced function, and piece of vendor-managed infrastructure expands the paths an attacker can use without ever touching the organization’s own network directly.
The same report shows what unresolved vendor risk looks like in practice. Only 23 percent of third-party organizations fully resolved missing or misconfigured multi-factor authentication on cloud accounts, and for half of the findings involving weak passwords or permission misconfigurations, remediation stretched to roughly eight months. That’s the gap between knowing a vendor has a problem and confirming it’sfixed, and it’s a gap self-reported questionnaires rarely catch.
Worth noting: 360 Advanced’s own read of the 2026 HITRUST Trust Report landed on a similar figure, close to 48 percent, using a separate methodology. Two independent measures pointing in the same direction is a stronger signal than either one alone.
THE VENDOR QUESTIONNAIRE MODEL WASN’T BUILT FOR SCALE
The standard third-party risk process still runs on security questionnaires: a client sends one, a vendor answers it, and the answers are self-attested with no independent check behind them. Multiply that across a vendor’s client base, each asking a differently worded version of largely the same 200 questions, and often neither side gets faster or better assurance from the exercise. The vendor spends real hours answering redundant forms. The client’s risk team spends real hours reviewing answers that it has no independent way to verify.
That model was tolerable when third-party involvement in breaches sat closer to 15 or even 30 percent. At 48 percent, a self-attested form is a weak instrument for a risk this big.
A VALIDATED HITRUST ASSESSMENT ANSWERS THE THIRD-PARTY RISK QUESTION
A HITRUST assessment answers the third-party risk question with independently validated evidence instead of a self-reported form. A vendor undergoes one certified assessment against HITRUST’s control framework, and the resulting certification, backed by HITRUST’s own quality assurance review and shared responsibility matrix, is something a client’s risk team can rely on rather than taking the vendor’s word for it.
The practical difference is evident in how the assessment gets used. Through the MyCSF platform, a client who is evaluating a vendor’s HITRUST certification can review independently verified control performance, which is evidence that a self-completed form can’t offer. One validated assessment can stand in for the reviews a dozen individual clients would otherwise each have to run.
WHAT CHANGES ON BOTH SIDES OF THE RELATIONSHIP
For a vendor, a HITRUST certification moves third-party risk review from a recurring bottleneck to a differentiator: due diligence that used to stall a sales cycle for weeks becomes a document a prospect’s risk team can check quickly, because the validation work is already done.
For an enterprise risk team, the shift is in how much weight a vendor’s assessment carries. A validated HITRUST certification and a self-attested questionnaire response belong to different classes of evidence, and a vendor risk program that scores them identically is measuring assurance it doesn’t truly have. With third-party involvement now approaching half of total breaches, scoring should build in that distinction from the beginning.