Primary topic

IBM Cost of a Data Breach Report 2026: What the Findings Mean for Third-Party Risk Management

IBM’s 2026 breach findings provide context for reviewing AI services and supplier dependencies. Explore the verified figures and TPSaaS’s implications for third-party risk decisions.

September 2026
7 min read

Third-party risk management (TPRM) is the process organizations use to identify, assess, monitor, and manage cybersecurity, operational, and compliance risks introduced by vendors, suppliers, and other external partners.

‍

For years, many organizations viewed third-party risk primarily as a governance requirement. Vendor questionnaires were sent, security documents were collected, and assessments were completed.

‍

The latest findings from IBM’s 2026 Cost of a Data Breach Report highlight why that approach is no longer enough.

‍

IBM’s official 2026 findings report a global average breach cost of $4.99 million. Its announcement says more than 20% of surveyed organizations experienced a breach targeting AI models or applications. These findings provide context for reviewing the external services and integrations on which an organization depends.

‍

These findings reinforce a growing reality: Organizations are not only responsible for securing their own environments.

‍

They must understand the security posture, access, and dependencies created by the suppliers connected to their business.

IBM 2026: Verified Study Context
$4.99M
Global average cost of a data breach across the study.
602
Organizations in the global breach study.
AI exposure
More than 20% reported a breach targeting AI models or applications.

What the IBM 2026 Report Reveals About Supply Chain Risk

IBM’s 2026 Cost of a Data Breach Report analyzed 602 organizations that experienced breaches between March 2025 and February 2026. The study found that the global average breach cost increased 12% to a record $4.99 million.

‍

While artificial intelligence and emerging attack methods received significant attention, the findings around supply chain compromise carry important lessons for third-party risk teams.

‍

For third-party risk teams, these findings are a reason to examine trusted external software, services, and integrations. This is TPSaaS’s interpretation of the wider findings, not a quantified estimate of supplier-caused losses.

‍

The global average describes the study population as a whole; it should not be presented as the average cost of a supply chain compromise.

‍

The key takeaway is not that every supplier creates a predictable financial loss.

‍

The important point is that compromised business partners introduce complexity.

‍

They can delay detection, complicate investigations, and increase the difficulty of containing an incident.

The Challenge Is Knowing Which Suppliers Matter Most

Modern organizations often rely on hundreds or thousands of vendors.

‍

However, not every supplier creates the same level of exposure.

‍

A marketing platform with no sensitive access presents a very different risk profile than a cloud provider connected to production systems, a vendor processing customer data, or a partner supporting critical operations.

‍

Effective third-party risk management requires organizations to understand:

- Which suppliers have access to sensitive information.

- Which vendors connect directly to internal systems.

- Which suppliers support critical business processes.

- Which third parties could create significant operational disruption if compromised.

‍

Without this visibility, organizations may spend valuable resources assessing low-risk suppliers while failing to maintain appropriate oversight of the relationships that matter most.

Third Parties Can Increase Risk, But They Can Also Improve Detection

A practical supplier-governance consideration is that external organizations can support incident response as well as introduce dependencies.

They can also contribute to faster identification and response.

‍

Internal security teams need clear ownership of incident detection, escalation, and response.

‍

Security service providers, business partners, and consultants can contribute visibility and specialist expertise; responsibilities and notification requirements should be explicit.

‍

The lesson is not that organizations should rely entirely on internal teams or external providers.

‍

Strong security programs combine internal ownership with external visibility, clear supplier communication requirements, and coordinated incident response processes.

‍

A compromised supplier that cannot quickly notify affected customers creates additional exposure.

Effective Response Requires Shared Visibility
Supplier Awareness
Understanding which external relationships create meaningful exposure.
→
Early Detection
Identifying incidents quickly through internal and external visibility.
→
Coordinated Response
Reducing impact through clear communication and defined responsibilities.

AI Is Expanding the Third-Party Attack Surface

Artificial intelligence is creating another layer of complexity for third-party risk management.

‍

Organizations are increasingly adopting AI capabilities through SaaS platforms, cloud providers, embedded vendor features, and specialized AI providers.

‍

This means AI risk often enters organizations through existing supplier relationships.

‍

IBM’s official announcement states that more than 20% of organizations reported a breach targeting AI models or applications.

‍

Supplier reviews should consider how AI capabilities are delivered and which external systems can access organizational information.

‍

The issue is often not the AI model itself.

‍

Instead, risk frequently comes from surrounding components such as cloud configurations, APIs, applications, plugins, and access controls.

‍

One area requiring more attention is non-human identities.

‍

These include service accounts, machine credentials, applications, and API connections that allow systems to communicate without direct human involvement.

‍

IBM’s report page highlights identity controls, tightly scoped permissions, human attribution, and auditability as priorities for agentic AI.

‍

As organizations rely more heavily on interconnected platforms, managing these identities becomes a critical part of supplier assurance.

AI Risk Is Moving Through Existing Relationships
Traditional Vendor Risk
Organizations evaluate a supplier based on known services, access, and documented security practices.
AI-Expanded Risk
Vendors introduce new capabilities, data flows, integrations, and machine identities that continuously change exposure.

Why Annual Vendor Assessments Are No Longer Enough

The IBM findings do not suggest that security questionnaires are unnecessary.

‍

Assessments remain an important part of understanding supplier controls and governance.

The challenge is relying on assessments as the only source of truth.

‍

A questionnaire completed six months ago cannot show whether a supplier has experienced a breach, introduced a new integration, changed ownership, exposed an API, or altered its security posture.

‍

Modern third-party risk management requires a lifecycle approach that connects supplier intake, risk tiering, assessments, remediation, continuous monitoring, and secure offboarding.

‍

Organizations need current information that helps them make decisions, not historical documentation that only proves a review happened.

Building a More Resilient Third-Party Risk Program

TPSaaS draws the following practical supplier-governance priorities from the wider breach and AI-risk findings.

‍

Organizations should begin by identifying which suppliers create the greatest potential impact.

‍

Risk-based tiering allows teams to focus deeper oversight on vendors that handle sensitive data, provide critical services, or maintain privileged connections.

‍

Monitoring should also reflect supplier risk.

‍

High-impact vendors require greater visibility than low-risk providers with limited access.

‍

Contractual requirements should establish clear expectations before an incident occurs. This includes notification timelines, escalation procedures, investigation support, and evidence requirements.

‍

Supplier incidents should also be tested through realistic exercises.

‍

Security, procurement, legal, compliance, and business stakeholders should understand their responsibilities before a third-party compromise happens.

‍

Finally, secure offboarding must be treated as a critical part of supplier governance.

‍

Removing integrations, revoking credentials, and confirming data return or deletion prevents former vendors from becoming forgotten access points.

Third-Party Risk Requires Lifecycle Visibility
Identify
Understand which suppliers create the greatest potential business impact.
→
Monitor
Track changes in security posture, access, and supplier dependencies.
→
Respond
Take action when supplier risk increases or incidents occur.

Moving From Vendor Assessments to Supplier Intelligence

TPSaaS’s interpretation of IBM’s 2026 findings is that supplier oversight should connect evidence to business context and accountable action.

‍

It is that organizations need better visibility into which suppliers matter, what access they have, and how quickly changes in supplier risk can be identified.

‍

At TPSaaS, we believe modern third-party security requires more than collecting questionnaires.

‍

Organizations need a structured approach that connects supplier onboarding, risk assessment, remediation management, continuous visibility, and secure offboarding.

‍

TPSaaS combines purpose-built workflows with practitioner-led assurance to help organizations maintain a clearer view of their supplier ecosystem and make better risk decisions.

‍

The executive question is no longer: “Have our suppliers completed their assessments?”

‍

The better question is: “Which suppliers could create a material business impact, and how quickly would we detect, escalate, and respond?”

The Modern TPRM Question
Which suppliers could create material business impact, and how quickly would we detect, escalate, and respond?

Frequently Asked Questions

What is third-party risk management (TPRM)?

Third-party risk management is the process of identifying, assessing, monitoring, and managing risks created by vendors, suppliers, and external partners that have access to an organization’s data, systems, or operations.

Why does third-party risk increase breach costs?

Third-party compromises often involve complex investigations because organizations must coordinate with external suppliers, understand shared responsibilities, and determine how the compromise affected connected systems or data.

Are vendor questionnaires still useful?

Yes. Vendor questionnaires remain an important part of supplier due diligence. However, they are most effective when combined with risk-based tiering, continuous monitoring, remediation tracking, and lifecycle management.

How does AI affect third-party risk management?

AI expands third-party risk because organizations increasingly consume AI capabilities through external platforms, SaaS applications, APIs, and technology providers. These connections create new data flows, access paths, and dependencies that require oversight.

What should organizations monitor after onboarding a supplier?

Organizations should monitor changes that could affect risk, including security posture changes, new integrations, access changes, incidents, certifications, vulnerabilities, and changes in business dependency.

‍

‍

Sources and references

About the author

Founder & CEO of TPSaaS, with more than 25 years in cybersecurity, third-party risk, and security assurance. Vic connects practitioner judgment, evidence, and human accountability to better supplier decisions.

Vic du Toit

Founder & CEO
Book a Demo