
MID-YEAR 2026 UPDATE
WE PREDICTED (Jan 2026)
50-60% of major incidents via suppliers or software dependencies 75-90% supplier spend continuously scored MTTD supplier compromise under 24 hours
WHAT’S HAPPENING NOW
Third-party breaches hit 48% – a record 454,600 new malicious OSS packages (+75%) Supply-chain breach costs $4.91M avg 44% of 2025 zero-days hit file-transfer tools
48% of breaches involved a third party – highest ever, up from 30%
454.6k new malicious open-source packages in 2025 (+75% YoY)
$4.91M average cost of a supply-chain compromise (267-day lifecycle)
44% of 2025 zero-day attacks targeted file-transfer tools
Running ahead of forecast. Third-party involvement nearly reached our 50-60% range a full year early, and software-dependency risk is compounding fast. Organizations that can continuously monitor and rapidly isolate suppliers now hold a measurable trust, resilience and commercial advantage – increasingly a deciding factor in regulated deals and cyber-insurance pricing.

Vendor inventory accuracy was:


In the past security assessment cadence : Annual or onboarding-only




50-60% of major incidents originate via suppliers or software dependencies

Continuous third-party risk scoring coverage will be: 75-90% of supplier spend

Mean time to detect supplier compromise

