Third-Party Vendor Risk Is Driving Nearly Half of All Data Breaches

Two business professionals reviewing a vendor security checklist on a laptop in an office

Third-party vendor risk, the exposure created by outside companies and software tools with access to your systems, now plays a role in roughly half of all data breaches. That is not a typo and not a rare worst case. It means the IT contractor, payroll processor, or SaaS app you trust with a login is now one of the more likely paths into your business.

  • Third-party involvement in breaches jumped to 48% this year, up from 30%, a 60% year-over-year increase.
  • Most of those incidents trace back to missing multi-factor authentication, stale credentials, or access that was never revoked, not sophisticated hacking.
  • Small organizations account for 96% of ransomware victims in the same report, and 69% avoided paying a ransom because they had working backups.
  • You do not need a formal vendor risk program to close most of this gap. A short access review does most of the work.
  • October is Cybersecurity Awareness Month, which makes this a reasonable month to actually run that review instead of filing it under someday.

Why did third-party risk jump so much in one year?

Businesses keep adding connected tools. A scheduling app, a marketing platform, a remote monitoring agent your IT provider installed two contracts ago. Each one gets a login, and most of those logins outlive the reason they were created. The 2026 Verizon Data Breach Investigations Report found that only 23% of third-party organizations had fully fixed missing or misconfigured MFA on their cloud accounts, and weak passwords or permission problems took a median of nearly eight months to resolve. The weak point usually is not a clever attacker. It is an account nobody turned off.

What does this actually mean for a 20 to 50 person Boston business?

It means your attack surface is bigger than your own network. A dental practice in Newton or a logistics firm in Quincy does not get breached through a zero-day exploit most of the time. It gets breached because a vendor’s employee reused a password, or a contractor’s laptop was compromised, and that vendor had standing access into the practice management system or the file server. You cannot audit every vendor’s internal security, but you can control what access you hand out and for how long.

Which vendors actually deserve a second look?

Not every vendor carries equal risk. Focus on the ones that can read or move your data, not the ones that just send you an invoice. That usually narrows to your managed IT provider, your accounting or payroll processor, your CRM or practice management platform, and any remote-access or monitoring tool installed on your machines. If a vendor can log into your network, see customer records, or push software updates to your computers, it belongs on the short list.

How do you check vendor access without turning it into a full-time job?

Pull a list of every active login tied to an outside company, and every app connected through single sign-on if you use Microsoft 365 or Google Workspace. For each one, confirm three things: is MFA actually required, is the access still needed, and who inside your business owns that relationship. A business we work with found an old web developer’s account still active eighteen months after the project ended. That is the kind of gap this exercise catches. It takes an afternoon, not a quarter.

What should change before this year ends?

Three practical steps cover most of the exposure. First, require MFA on every vendor account with access to your systems, no exceptions. Second, remove access the moment a contract or project ends, rather than waiting for a cleanup pass. Third, ask your highest-access vendors in writing whether they enforce MFA and least-privilege access on their own infrastructure. If a vendor cannot answer that question directly, that is useful information too. For how this connects to your broader recovery planning, see our look at whether you could move your data without a vendor’s help, and if a vendor-related incident does turn into a reportable breach, our rundown of the Massachusetts data breach notification law covers what happens next.

Frequently asked questions

What counts as a third-party vendor for breach risk purposes?
Any outside company with access to your systems, network, or data. That includes your IT provider, payroll processor, accounting firm, marketing agency, SaaS tools like your CRM or scheduling software, and any contractor who logs into your network remotely.

How many vendors does a typical small business actually need to worry about?
Fewer than owners usually guess, but more than the handful they think of first. Start by pulling every active login in your identity system and every app connected through single sign-on. Most 20 to 50 person businesses find 15 to 30 outside connections once they actually list them.

Do we need a formal vendor risk management program?
Not a heavy one. A basic list of who has access, what they can see, how they log in, and when that access was last reviewed covers most of the exposure for a small business. Formal programs matter more once you handle regulated data at scale.

What is the fastest way to reduce this risk without a big project?
Require multi-factor authentication on every vendor account that touches your systems, turn off access for vendors you no longer use, and ask your two or three highest-access vendors in writing whether they enforce MFA on their own side. That one step closes the gap behind most of the incidents in the data.

If you are not sure which vendors currently have standing access into your systems, that uncertainty is itself the risk this report is describing. Boston Managed IT offers a free 15-minute Microsoft 365 and security review where we pull your actual access list, flag any vendor accounts without MFA, and tell you plainly what to fix first. Call (617) 322-5155 or visit bostonmit.com/contact to set it up.

— Boston Managed IT

Picture of Nicholas Salem

Nicholas Salem

As the CEO of BMIT, a leading managed IT services company, Nick Salem is responsible for providing strategic leadership and direction to the organization. With over 15 years of experience in the IT industry, Nick has a strong track record of driving business growth and improving operational efficiency through the use of technology. https://nicholassalem.com

Free assessment

Not sure where you stand?

Thirty minutes with a senior engineer on your security, backups, and Microsoft 365. Findings in writing.

Keep reading

A Boston managed IT partner's weekly, monthly, and quarterly work laid out on a timeline

What a Boston Managed IT Partner Should Actually Be Doing for a 20–50 Person Business

Here is the conversation I have most often with a business...

IT technician checking server hardware in a data center, representing Windows Server 2022 reaching end of mainstream support

Windows Server 2022 End of Mainstream Support: What It Means for Boston Businesses

Windows Server 2022 reaches end of mainstream support on October 13,...

Business owner reviewing a data breach notification checklist on a laptop in an office

Massachusetts Data Breach Notification Law: What Boston Businesses Must Do When It Happens

Massachusetts Chapter 93H, the state’s data breach notification law, requires any...

Free technical assessment

Thirty minutes with a senior engineer.

  • Security posture, backups, and Microsoft 365, reviewed live
  • The three fixes that matter most, ranked, with rough effort
  • Findings in writing, and an honest answer on whether you need us

Book your assessment

Next, you pick a time on our calendar. No sales deck.

Prefer the phone? (617) 322-5155