Third-Party Risk Is a Data Problem: What 2025’s Breach Epidemic Tells Us

Kloudynet Security Team
Posted On
March 10, 2026
5 min
read
Data Security
Supply chain
DSPM

In early 2026, Volvo Group North America disclosed that data belonging to nearly 17,000 employees and customers, including Social Security numbers, health insurance details, and medical information, had been exposed through Conduent, a business services provider it used for HR administration. The intrusion had happened in late 2024 and went undetected for months. Volvo was not breached. Volvo's data was. The distinction matters because it captures the precise nature of the problem: an organisation can maintain defensible internal security controls and still suffer significant data exposure through the supply chain it depends on operationally.

This is not an isolated case. It is a pattern. And for enterprise security leaders, the pattern calls for a reorientation of data security strategy, from perimeter-centric to data-centric, and from internal-only to supply-chain inclusive.

‍

The Scale of the Problem

The Identity Theft Resource Center's 2025 Annual Data Breach Report documented a record 3,322 publicly disclosed breaches in the United States alone, with cyberattacks responsible for 80% of incidents. Qantas disclosed that data belonging to over five million customers was exposed through a third-party contact centre platform. Match Group experienced an incident traced to a marketing analytics provider. AT&T's settlement covered data extracted from a workspace hosted by a cloud data platform it used. In each case, the common thread is not a failure of the primary organisation's security controls. It is a failure to govern the data entrusted to third parties with equivalent rigour.

The Verizon 2025 DBIR noted that 60% of breaches continue to involve a human element, primarily phishing and stolen credentials. In the third-party context, this means the initial compromise often occurs within a vendor's environment through a conventional attack vector, and the downstream impact lands on the organisations whose data that vendor holds. The enterprise that invested in phishing-resistant authentication and privileged access management still has its customer data exposed, because those controls did not extend to the vendor processing it.

‍

Where Governance Falls Short

Most enterprise data security programmes are architecturally bounded. They protect data within the environment the organisation directly administers. Once data leaves that environment, to a payroll processor, a cloud analytics provider, or a customer support outsourcer, direct control over its protection effectively ends. What replaces it is contractual obligation: data processing agreements that state what the vendor is required to do but provide no continuous visibility into whether they are doing it. Most third-party data incidents occur in the gap between contractual requirement and operational reality.

There is a compounding structural issue. Most organisations do not maintain a complete inventory of where their sensitive data actually resides across the third-party ecosystem. The data flows approved at vendor onboarding may have expanded significantly since. What began as a limited HR data transfer may now include payroll, benefits, and performance records. That gap between what was documented at contract signature and what currently flows is frequently invisible until an incident makes it unavoidable.

‍

What Adequate Governance Requires

Addressing third-party data risk is fundamentally a visibility problem. Organisations that cannot answer where their sensitive data currently resides, and who has access to it, across both internal and external environments, cannot manage the risk it carries. Four capabilities are required in practice. First, a continuously updated inventory of sensitive data across internal systems, cloud environments, and third-party relationships, not a static map from last year's audit.

Second, vendor-level data security assessment that goes beyond certification verification and evaluates incident detection, data segregation, and notification capability. The Conduent and Volvo scenario, where an intrusion in October 2024 was disclosed to downstream organisations in February 2026, shows what inadequate notification practices produce.

Third, data minimisation discipline: limiting what sensitive data is shared with vendors to what is operationally necessary, which reduces exposure at source.

Fourth, integration of third-party risk into ongoing posture management rather than periodic procurement review. Vendor security is not static. A supplier that passed assessment 18 months ago may have changed significantly since.

‍

Conclusion

The breach incidents of 2025 have collectively made the case that internal security controls alone are insufficient when sensitive data flows through an extended third-party ecosystem without equivalent governance. The organisations that suffered the most damaging consequences were not the ones that failed to invest in their own security. They were the ones that had not extended the same rigour to the data they entrusted to others. Data security governance in 2026 has to be built around a demanding principle: the organisation is accountable for its data wherever it resides. That accountability requires visibility, and visibility requires a programme that extends beyond the internal perimeter into every vendor environment that holds, processes, or accesses sensitive information on the organisation's behalf.

Recommended for You

Managed Security
Market & People

What ASEAN's $12 Billion Cybersecurity Opportunity Means for Enterprise Leaders

ASEAN's $12.2 billion security market reflects real necessity. Each market brings distinct regulation and threats, and compliance now demands genuine operational capability.
Kloudynet
March 9, 2026
Know More
AI Security
Artificial Intelligence

The AI Security Paradox: Your Greatest Defender Is Also Your Biggest Risk

AI cuts both ways: it speeds breach detection by 108 days, and powers cheap, effective attacks. Enterprises must govern both sides at once.
Kloudynet
March 8, 2026
Know More
Identity Security
Identity & Detection

Identity Is the New Perimeter - And Most Enterprises Aren't Ready

79% of 2026 attacks involve no malware. Adversaries log in with stolen credentials, making identity governance the new center of enterprise security.
Kloudynet
March 7, 2026
Know More

Securing your Identity, Data,
Cloud, and AI landscape.

© 2026 Kloudynet Technologies. All rights reserved.