Damon Fleury is the Chief Product Officer of SpyCloud, a leader in identity threat protection.gettyOver the past decade, the supply chain has quietly transformed. It no longer runs primarily on business relationships, but on authenticated access. APIs connect logistics providers to retailers, cloud platforms integrate directly with payroll processors and SaaS applications continuously exchange customer and operational data across organizational boundaries.As a result, the supply chain is no longer a closed system, but a complex web. While most organizations have invested heavily in internal cybersecurity—such as multifactor authentication (MFA), zero-trust initiatives and phishing training—attackers are increasingly bypassing these controls and targeting trusted third-party accounts instead. My company found that nearly one-third of breaches now involve third parties, with one infection unlocking access to an average of 25 applications.​​ The 2025 Verizon Data Breach Investigations Report reported similar findings.In such an environment, organizations overlook supply chain security at their own risk. The perimeter has expanded to include the people, applications and access paths of third parties, and cybersecurity must reflect this reality.​From Periodic Assessment To Continuous Identity Threat MonitoringIn many ways, traditional third-party risk management (TPRM) is outdated. Most programs still rely on annual assessments, questionnaires and static risk scores. This approach is built on the assumption that risk stems primarily from unpatched systems, misconfigurations or public-facing vulnerabilities. While those factors still matter, they no longer reflect how attackers actually gain access.​Today, attackers increasingly target identity as the primary attack surface. Rather than breaking in through infrastructure alone, they exploit the interconnected nature of identity data across vendors, systems and users. Stolen credentials, hijacked sessions, malware-infected endpoints and phishing campaigns provide direct, authenticated access.​This shift fundamentally changes how third-party risk must be understood. Risk is no longer just about a vendor’s security posture on paper, but whether compromised identity data tied to that vendor can be actively used to access your environment.​To keep up, organizations need a proactive, identity-centric approach that reflects how attackers operate today. Static assessments and point-in-time risk scores offer little value without visibility into real, exploitable exposure. Instead, organizations must continuously monitor identity-linked threat data—such as malware exfiltration, phishing kits, breach logs and combolists—to understand what attackers can use right now.​Ensuring Visibility Translates Into Action​Of course, visibility is only valuable if it leads to action. That’s why security teams need a unified, continuously updated view of third-party exposures: one that aggregates and contextualizes risk. That means tracking exposures over time, attributing them to specific vendors and domains, and understanding both the type and severity of risk in a way that supports real decision-making, not just reporting.​Ultimately, the goal isn’t only awareness, but action and operational clarity. While elevated malware exposure may point to other vulnerable habits such as weak device hygiene, repeated phishing incidents can signal heightened risk of session hijacking or lateral movement and patterns of credential reuse often indicate deeper identity management issues. With this level of insight, organizations can act decisively: restricting access, adjusting privileges, reassessing integrations or re-tiering vendors based on real, current risk.​​The Bottom Line​​Shifting from static assessments toward continuous, actionable insight can help organizations manage supply chain risk more effectively. At the same time, this new approach shifts security from an adversarial model to a collaborative one. This shift from “prove you’re secure” to “let’s reduce risk together in real time” is especially impactful for smaller vendors, where even a handful of high-quality signals can drive meaningful improvements when shared constructively.​The benefits can extend beyond security operations. When continuously updated risk signals are incorporated into the vendor lifecycle, they can inform procurement, onboarding, access decisions and ongoing vendor reviews rather than remaining confined to periodic TPRM exercises. They can also provide earlier indications that a vendor’s risk profile has changed, giving security and risk teams an opportunity to investigate before an issue becomes a larger exposure. Most importantly, the approach can create a more consistent operating model across teams such as the SOC, TPRM, procurement and compliance, helping turn third-party risk into an ongoing discipline rather than a periodic checkbox exercise.​Ultimately, the enterprise attack surface now extends far beyond what any organization directly controls. Securing internal systems is no longer enough; your organization is only as secure as the vendors you do business with. The key question is no longer whether vendors have been assessed, but whether you understand, in real time, how they could be used against you.​​Forbes Technology Council is an invitation-only community for world-class CIOs, CTOs and technology executives. Do I qualify?