Third Party Risk Statistics

72% of organizations had a vendor-linked cybersecurity incident in the past 12 months—see the third-party risk stats and key takeaways.
Magnus ÖbergAdrien Chevalier

Written by Magnus Öberg

Fact-checked by Adrien Chevalier

Statistics
22
Sources
22
Sections
6
Reading time
7 minutes
Third-party risk affects organizations across industries when suppliers and ecosystem partners introduce vulnerabilities—often surfacing as control weaknesses, delays, and gaps in incident response. This page compares what teams do with vendor security governance, from minimum cybersecurity requirements and risk ratings to continuous monitoring and re-validation. You’ll also see how regulation, enforcement, and supply-chain threats influence priorities, investment, and escalation decisions like vendor terminations.

Key Takeaways

  1. 129% of organizations stated they do not have a formal process to review third-party security attestations in 2024
  2. 2In 2024, 52% of surveyed organizations expected increasing regulation related to vendor and supply-chain risk.
  3. 3The SEC’s Division of Enforcement brought actions involving cybersecurity controls at third-party service providers in 2024, totaling 12 matters (as listed in its enforcement releases).
  4. 456% of organizations increased spending on third-party risk management due to supply chain threats in 2024
  5. 534% of organizations reported that they have a minimum cybersecurity requirement set for vendors (as of 2024)
  6. 674% of organizations reported they use risk ratings or scoring for third parties
  7. 7The median time to contain a breach was 73 days in 2024
  8. 831% of organizations said they have terminated vendors due to security risk in the past 12 months (as of 2024)
  9. 923% of organizations reported experiencing delays in onboarding due to third-party risk reviews in 2024
  10. 10In 2024, 46% of organizations said they use external security ratings from third parties to inform third-party risk decisions.
  11. 1160% of cybersecurity leaders say third-party risk is a top or high priority for their organization.
  12. 1268% of surveyed organizations assess third parties at least annually as part of their third-party risk program.
  13. 13The US third-party risk management market was estimated at $1.8 billion in 2023.
  14. 1457% of organizations track third-party risk metrics but do not use them to automate remediation workflows
  15. 1572% of organizations experienced a cybersecurity incident linked to a vendor or third party in the past 12 months.

Most organizations face vendor risk gaps and incidents, prompting higher spending, monitoring, and regulatory focus.

02User Adoption

4
  1. 156% of organizations increased spending on third-party risk management due to supply chain threats in 2024
  2. 234% of organizations reported that they have a minimum cybersecurity requirement set for vendors (as of 2024)
  3. 374% of organizations reported they use risk ratings or scoring for third parties
  4. 468% of organizations have implemented continuous monitoring for at least some third parties

03Cost Analysis

3
  1. 1The median time to contain a breach was 73 days in 2024
  2. 231% of organizations said they have terminated vendors due to security risk in the past 12 months (as of 2024)
  3. 323% of organizations reported experiencing delays in onboarding due to third-party risk reviews in 2024

04Controls And Coverage

3
  1. 1In 2024, 46% of organizations said they use external security ratings from third parties to inform third-party risk decisions.
  2. 260% of cybersecurity leaders say third-party risk is a top or high priority for their organization.
  3. 368% of surveyed organizations assess third parties at least annually as part of their third-party risk program.

05Industry Overview

3
  1. 1The US third-party risk management market was estimated at $1.8 billion in 2023.
  2. 257% of organizations track third-party risk metrics but do not use them to automate remediation workflows
  3. 372% of organizations experienced a cybersecurity incident linked to a vendor or third party in the past 12 months.

06Process Maturity

3
  1. 137% of organizations report they rely on manual processes for vendor security reviews.
  2. 244% of organizations say they lack a clearly defined process for periodic re-validation of vendor security posture.
  3. 338% of organizations do not have a dedicated incident response plan that covers third-party scenarios.

Cite this report

This report is designed to be cited. We maintain stable URLs and versioned verification dates. Copy the format appropriate for your publication below.

APA
Magnus Öberg. (2026, September 21). Third Party Risk Statistics. Statpit. https://statpit.com/third-party-risk-statistics
MLA
Magnus Öberg. "Third Party Risk Statistics." Statpit, 21 Sep 2026, https://statpit.com/third-party-risk-statistics.
Chicago
Magnus Öberg. 2026. "Third Party Risk Statistics." Statpit. https://statpit.com/third-party-risk-statistics.

Sources and references

22 datasets cited across this report. Attribution is report-level.

1 additional datasets are cited and not shown individually.