Third-party vendor risk, the exposure created by outside companies and software tools with access to your systems, now plays a role in roughly half of all data breaches. That is not a typo and not a rare worst case. It means the IT contractor, payroll processor, or SaaS app you trust with a login is now one of the more likely paths into your business.
- Third-party involvement in breaches jumped to 48% this year, up from 30%, a 60% year-over-year increase.
- Most of those incidents trace back to missing multi-factor authentication, stale credentials, or access that was never revoked, not sophisticated hacking.
- Small organizations account for 96% of ransomware victims in the same report, and 69% avoided paying a ransom because they had working backups.
- You do not need a formal vendor risk program to close most of this gap. A short access review does most of the work.
- October is Cybersecurity Awareness Month, which makes this a reasonable month to actually run that review instead of filing it under someday.
Why did third-party risk jump so much in one year?
Businesses keep adding connected tools. A scheduling app, a marketing platform, a remote monitoring agent your IT provider installed two contracts ago. Each one gets a login, and most of those logins outlive the reason they were created. The 2026 Verizon Data Breach Investigations Report found that only 23% of third-party organizations had fully fixed missing or misconfigured MFA on their cloud accounts, and weak passwords or permission problems took a median of nearly eight months to resolve. The weak point usually is not a clever attacker. It is an account nobody turned off.
What does this actually mean for a 20 to 50 person Boston business?
It means your attack surface is bigger than your own network. A dental practice in Newton or a logistics firm in Quincy does not get breached through a zero-day exploit most of the time. It gets breached because a vendor’s employee reused a password, or a contractor’s laptop was compromised, and that vendor had standing access into the practice management system or the file server. You cannot audit every vendor’s internal security, but you can control what access you hand out and for how long.
Which vendors actually deserve a second look?
Not every vendor carries equal risk. Focus on the ones that can read or move your data, not the ones that just send you an invoice. That usually narrows to your managed IT provider, your accounting or payroll processor, your CRM or practice management platform, and any remote-access or monitoring tool installed on your machines. If a vendor can log into your network, see customer records, or push software updates to your computers, it belongs on the short list.
How do you check vendor access without turning it into a full-time job?
Pull a list of every active login tied to an outside company, and every app connected through single sign-on if you use Microsoft 365 or Google Workspace. For each one, confirm three things: is MFA actually required, is the access still needed, and who inside your business owns that relationship. A business we work with found an old web developer’s account still active eighteen months after the project ended. That is the kind of gap this exercise catches. It takes an afternoon, not a quarter.
What should change before this year ends?
Three practical steps cover most of the exposure. First, require MFA on every vendor account with access to your systems, no exceptions. Second, remove access the moment a contract or project ends, rather than waiting for a cleanup pass. Third, ask your highest-access vendors in writing whether they enforce MFA and least-privilege access on their own infrastructure. If a vendor cannot answer that question directly, that is useful information too. For how this connects to your broader recovery planning, see our look at whether you could move your data without a vendor’s help, and if a vendor-related incident does turn into a reportable breach, our rundown of the Massachusetts data breach notification law covers what happens next.
Frequently asked questions
What counts as a third-party vendor for breach risk purposes?
Any outside company with access to your systems, network, or data. That includes your IT provider, payroll processor, accounting firm, marketing agency, SaaS tools like your CRM or scheduling software, and any contractor who logs into your network remotely.
How many vendors does a typical small business actually need to worry about?
Fewer than owners usually guess, but more than the handful they think of first. Start by pulling every active login in your identity system and every app connected through single sign-on. Most 20 to 50 person businesses find 15 to 30 outside connections once they actually list them.
Do we need a formal vendor risk management program?
Not a heavy one. A basic list of who has access, what they can see, how they log in, and when that access was last reviewed covers most of the exposure for a small business. Formal programs matter more once you handle regulated data at scale.
What is the fastest way to reduce this risk without a big project?
Require multi-factor authentication on every vendor account that touches your systems, turn off access for vendors you no longer use, and ask your two or three highest-access vendors in writing whether they enforce MFA on their own side. That one step closes the gap behind most of the incidents in the data.
If you are not sure which vendors currently have standing access into your systems, that uncertainty is itself the risk this report is describing. Boston Managed IT offers a free 15-minute Microsoft 365 and security review where we pull your actual access list, flag any vendor accounts without MFA, and tell you plainly what to fix first. Call (617) 322-5155 or visit bostonmit.com/contact to set it up.
— Boston Managed IT