OCTOBER 6, 2026 • 4 MIN READ

When Everyone Gets Hit: Third-Party Incidents Are the New Normal

State of TPRM - When Everyone Gets Hit: Third-Party Incidents Are the New Normal

New Drata research: 85% of security teams reported a third-party incident last year — vendor risk is now a standing condition, not a rare event.

For years, security teams treated the third-party breach as the exception — the event you prepared for but expected to dodge, the reason you collected SOC 2 reports and filed them away. That framing no longer matches reality.

Our recent survey of 309 IT and security leaders and practitioners across the U.S., U.K., and Canada, 85% reported at least one third-party-related security incident in the past 12 months. Only 15% got through the year without one. And a single event was the outlier: roughly two-thirds of organizations reported two or more.

When something happens to five out of six teams in a year, it stops being an outlier event and becomes a standing operating condition. The question worth asking is what a program looks like when it is built for "when," not "if."

It’s Not a Surprise

The distribution is what makes the finding so impactful. More than half of respondents reported two to five incidents in the year. The typical pattern is a steady drumbeat of smaller events: a vendor outage that halts your operations, a fourth party quietly exposed, a supplier that discloses a compromise weeks after the fact. Individually minor, collectively constant.

The word matters here. These are incidents — a broader category than confirmed breaches that captures the full range of ways a third party can introduce risk into your environment. That breadth is exactly the point. The surface area of vendor risk is wide, and most of it never makes the headlines. It just accumulates.

Concern Is Rising for a Reason

Security teams feel the shift. Over the past 24 months, concern about third-party risk increased for 75% of organizations, and the number of third parties they work with rose for 71%. More vendors, more worry, more incidents — the inputs are all moving in the same direction at once.

There is also a visible relationship between how stretched a program is and how often it gets hit. The teams reporting the most incidents are consistently the ones most likely to say they lack the capacity to assess third parties adequately, while the teams that made it through the year clean are far less likely to name that constraint. The pattern is directional, and it points somewhere intuitive: when a program can't keep up with its portfolio, the gaps are where incidents find their way in.

What a “Good” Program Looks Like

If incidents are routine, then a program organized around preventing every one of them is organized around the wrong goal. The goal is resilience: catching more of what matters, sooner, and keeping the picture current enough to act before a problem becomes an incident.

That reframing changes what "good" looks like. A point-in-time questionnaire answered once at onboarding tells you a vendor's posture on the day they filled it out, not on the day something goes wrong. A program built for "when" assumes posture drifts, assumes new vendors arrive faster than anyone can manually review them, and assumes AI and other fast-moving changes can reshape a supplier's risk profile between annual reviews. It leans on continuous and consistent criteria-based assessment so that coverage stays wide and evidence stays fresh.

The organizations that manage third-party risk well over the next few years won't be the ones that were never touched. In a world where 85% get hit, that group barely exists. They'll be the ones that assumed it would happen, built for it, and could show their work when it did. The full research report breaks down where programs are stretched today and why the old model can't keep pace.

See the findings and what to do about them in The State of Third-Party Risk Management 2026. Or book a demo to see how Drata helps you solve these challenges. 


Chart Your Course

Navigate to new worlds of trust with Drata.