News

Third-Party Cybersecurity Risks Rise as Digital Dependencies Grow

Cybersecurity leaders warn that growing dependence on third-party technology providers is creating concentration risks, allowing one supplier vulnerability or disruption to trigger widespread operational and security failures.

Written By : Poulami Saha
Reviewed By : Ankitha Phulare

Cybersecurity leaders are raising concerns about the growing dependence on third-party technology providers, warning that vulnerabilities at a single supplier can spread across entire business ecosystems. As organizations rely more heavily on cloud platforms, software vendors, managed services and digital infrastructure providers, supplier security is becoming a critical part of enterprise resilience.

Concentration Risk is Growing

The World Economic Forum’s Global Cybersecurity Outlook 2026 explained, “Third-party dependency and concentration are major supply-chain concerns. Organizations often have limited control over suppliers’ security practices, while a small number of critical digital providers now support large parts of the global economy. A vulnerability or disruption at one provider can therefore create cascading consequences for customers worldwide.”

Third-party breaches can affect multiple organizations simultaneously. Black Kite’s 2026 Third-Party Breach Report identified 136 major third-party incidents in 2025 that affected 719 companies directly, while estimating that another 26,000 organizations may have been indirectly affected. The findings highlight how quickly supplier-related incidents can scale when organisations share common technology dependencies.

Recent incidents have reinforced the concern. Thomson Reuters disclosed this week that an unauthorized party accessed files through its C-Track case management platform, affecting court systems across several US states, the US Virgin Islands and Ontario. The company brought in external cybersecurity experts and notified affected customers.

Safety Nets

The rapid adoption of artificial intelligence is further expanding the attack surface. More organizations are connecting AI systems with cloud services, data platforms and external applications, creating additional dependencies that security teams must monitor.

At the same time, attackers are using AI to identify vulnerabilities and automate parts of cyberattacks. More than 100 technology companies recently called for stronger collective defences against AI-enabled attacks, warning that critical infrastructure faces increasing exposure.

Also Read: White House to Meet OpenAI, Meta, Google Over AI Cybersecurity Tests

AI Agents Could Outnumber Humans Soon, Cybersecurity Leader Warns

Saudi AI Push Gets Bigger as Humain Eyes $2.5 Billion Fund

Luba 4 AWD: Mammotion’s New Robot Mower Gets Advanced Navigation, Edge-Cutting Feature

Muse Spark 1.3: Meta Boosts Coding, Agentic AI Capabilities

Google Expands Android Features to Older Phones with September Update