Powered by MOMENTUMMEDIA
For breaking news and daily updates, subscribe to our newsletter

Op-Ed: Why third-party breaches are becoming everyone’s problem

Every time a major cyber breach makes headlines, Australian security leaders face the same urgent question: does this affect us?

user icon Kash Sharma, Managing Director APAC, at BlueVoyant Mon, 14 Sep 2026
Op-Ed: Why third-party breaches are becoming everyone’s problem

For cyber risk teams, the answer is rarely straightforward and they may work through the following issues:

  • Was one of our vendors, suppliers or partners involved?

  • Did the incident affect a technology platform they rely on?

     
     
  • What if the compromised organisation sits further down the supply chain?

These questions are increasingly important as Australian organisations become increasingly dependent on interconnected ecosystems of technology providers, suppliers and partners. Over the past year, third-party cyber incidents have affected sectors including transport and aviation, education, hospitality and professional services, demonstrating the exposure that can emerge through external providers and shared technology platforms. The common thread is that an organisation does not need to be the initial target for its operations, systems or customer data to be exposed.

The visibility gap in third-party risk

Third-party risk management (TPRM) has traditionally relied on assessments during onboarding and at periodic intervals throughout a supplier relationship. These remain important, but cyber risk does not operate according to an annual cycle. A supplier’s security posture can change, new vulnerabilities can emerge and technology dependencies can evolve. A supplier can also suffer a breach through one of its own providers.

Australian organisations are already experiencing the consequences. BlueVoyant’s 2025 State of Supply Chain Defense research found that 99 per cent of Australian organisations surveyed experienced negative impacts from a third-party or supply-chain breach during the previous 12 months. Yet only 30 per cent reported having established or optimised TPRM programs, while 95 per cent expected their third-party ecosystems to continue growing.

As these ecosystems expand, security teams need to understand not only the risks identified during an assessment, but what changes between assessments. This is where cyber breach awareness should become part of continuous TPRM monitoring.

Making cyber breach awareness continuous

Cyber breach awareness is the ability to identify emerging breach events and determine whether the organisations involved have a relationship to your business or supply chain.

In practice, breach information is fragmented across news reports, regulatory disclosures, company statements, security research and other public sources. Early reporting may be incomplete, details can change, and organisations may be identified under different company, subsidiary or brand names.

The challenge is not simply finding out that a breach occurred. The harder question organisations should ask is: does this breach matter to us? Answering that requires connecting external information about an incident with knowledge of suppliers, technology dependencies and fourth-party relationships.

Cyber breach awareness should sit alongside other forms of continuous TPRM monitoring. Supplier assessments provide point-in-time information. External monitoring can identify changes in security posture, while vulnerability intelligence can highlight technical exposure. Breach awareness adds another signal: whether an organisation within the extended supply chain is associated with an active incident.

Using AI to close the information gap

Historically, maintaining this level of awareness required significant manual effort. Analysts needed to monitor multiple sources, identify relevant organisations and compare those findings against supplier inventories.

AI and automation are making that process more scalable. AI can analyse large volumes of commercial and open-source information, identify potential breach events, connect references to the same organisation and map affected organisations against a company’s third-party ecosystem.

For example, at BlueVoyant we use AI to monitor commercial and open-source data for publicly reported breaches and map organisations identified in those reports against monitored third-party portfolios. This can reduce the manual work needed to determine whether an emerging incident warrants further investigation.

The role of AI is not to make the risk decision. It is to reduce the information security teams need to manually collect and correlate before making that decision. Public reporting is not always complete or verified, so AI-supported breach awareness should be treated as an early signal rather than definitive intelligence. Human judgement remains essential to understand the supplier relationship, assess exposure and determine what action should follow.

From awareness to action

Knowing that a supplier has been associated with a breach is only valuable if an organisation can act on that information. Security teams should quickly establish whether it involves a critical supplier, what systems or data that supplier can access, whether downstream dependencies exist, and whether the incident could affect operations or customer information.

The breached organisation may not appear on the company’s supplier list at all. Organisations increasingly depend on cloud platforms, software providers and specialist services embedded within suppliers’ operations. These fourth-party relationships can create exposure even where there is no direct commercial relationship.

Without that visibility, organisations can find themselves reconstructing supply-chain relationships after an incident has already occurred. Continuous TPRM therefore needs to move beyond asking whether a supplier passed its last assessment. It should help organisations understand how exposure changes as suppliers, technologies, vulnerabilities and threats evolve.

No organisation can prevent every cyber incident across its extended supply chain. What organisations can control is how quickly they recognise when an incident elsewhere could create risk for them.

Technology, including AI, can help connect these signals at a scale that would be difficult through manual analysis alone. However, organisations still need clear processes for validating those signals, understanding their exposure and deciding when to act. The breach may belong to one organisation, but its impact could reach many more.

Cyber DailyWant to see more stories from trusted news sources?
Make Cyber Daily a preferred news source on Google.