Third-party risk: the board's biggest concern, and the case for bringing together cyber, AI and data.
26 August 2026
Emma Di iorio | CEO & Co-founder, Spriggun
Boards rank third-party and supply chain risk as the single biggest barrier to cyber resilience, ahead of direct attacks. Nearly half of all cyber breaches now trace back to a vendor, up sharply on 2025 figures. Most businesses respond with a questionnaire, a score, a signed attestation filed somewhere. Many security leaders running these programmes will privately admit that this does not give any certainty, but it is a comparatively cheap response to a massive task, often one without sufficient funding at board level. It also reflects the difficulty in getting big tech players to answer specific questions. The result is corporate decoration rather than assurance. Here we focus on third-party risk, as the sharpest current example of a wider pattern of disconnect across incident detection, insider risk, and internal AI rollout.
Why cyber, AI and data are not three separate risks
Most businesses still manage cyber, data, and AI risks in isolation: relying on separate risk registers; distinct executive owners; and disconnected review cycles. This can mean the CISO assesses cyber threat, the legal team reviews data (privacy and governance) compliance, and an AI committee evaluates model governance in isolation even from broader AI governance. A truly effective approach is nearly impossible to achieve from inside these silos. Indeed, the underlying risk is deeply connected, not merely adjacent. AI runs on data the business already holds, governed by privacy laws that predate the company’s AI strategy. Ultimately, both depend on cyber infrastructure to remain secure in the AI age. Consider a vendor breach involving customer data, which is simultaneously a cyber breach, a privacy breach - both triggering regulatory breach responses - and an AI governance breakdown, potentially triggering strict penalties under the EU AI Act.
A lack of planning is dangerous, but planning in silos is equally flawed. When a serious crisis hits, the business knows this is one problem the moment it becomes urgent. Nobody runs three separate response teams for cyber, privacy, and AI, there is only one incident response team. This team must report to the board on an hourly loop, navigating different start times and complex thresholds for multiple 24-to-72-hour regulatory notification windows. Three separate continuity plans do not add up to an effective strategy during a crisis, for the chaotic clean-up required to ensure business continuity, or when explaining what went wrong and remedial mitigation to regulators.
Why the standard assurance process cannot answer the question the board is asking
Vendor questionnaires and scoring platforms are built for volume: teams checking whether a box is ticked, not judging whether the reality is sufficient for what a specific vendor actually does. Increasing monitoring technology can make this worse, producing continuous false confidence - still generally focusing on high-cost, high-visibility vendors - rather than the genuinely high-risk ones. It also misses an entire category, of free or low cost tools an employee started using without procurement ever seeing.
It is crucial to treat Know Your Data (KYD) and Know Your AI (KYAI) as an ongoing discipline, paired with the fluency and defined governance limits this article series has already argued for. Managed services can scale confidence built on shaky foundations just as easily; human in the loop is not a tickbox, and a documentary shield does not hold up in the current regulatory environment. A comprehensive-looking risk register, which falls over as soon as a significant cyber breach hits, only poses increased regulatory questions. It also hinders business continuity and the clean-up, the approach to which are generally as important as the breach happening at all, from a regulatory standpoint. While regulators were previously somewhat open to questionnaires, or continuous control monitoring, these - often decorative - approaches no longer meet requirements. Regulators want factual answers, not merely what has been written in a policy nobody follows. Lastly, ISO, SOC 2 and their certifications, attestation, or similar, do not serve to meet minimum legal requirements, in spite of many treating them as alternative solutions.
Article 50 of the EU AI Act is a live demonstration of how companies are handling risk in this area. To meet new transparency mandates, organisations are rapidly onboarding content-marking software vendors. In many cases vendors are filtered through isolated security reviews or simple compliance checklists, rather than a unified, business-wide evaluation. This piecemeal strategy introduces a hidden hazard, expanding a company's cyberattack surface before proper defences are in place or even contemplated as necessary.
What works instead
Scrutinising every vendor with the same depth is not realistic. Prioritise instead by potential harm, to the business if the relationship fails, and to the people whose data depends on it. NCSC's own supply chain guidance sets requirements for different suppliers, based on risk, rather than forcing identical requirements on all third parties.
For third parties that pose significant risk, a cross-functional approach is needed. Sizing risk across cyber, AI and data for a single vendor needs the people who hold each piece of the picture in a room together, not the CISO alone and not privacy doing an assessment, or legal reviewing a contract in isolation.
Knowing a relationship is high-risk is not the same as being able to fix it. What it takes to resolve, including: repapering contracts; negotiating audit access; evidential proof security requirements are being met; and internal steps including architectural containment and focused threat intelligence (all with their own challenges to do effectively), is real enough to deserve its own piece rather than a compressed paragraph here.
Board responsibility and expanding legislation
Supply chain risk is no longer an afterthought. While the EU’s NIS2 directive mandates strict third-party risk management, the UK Cyber Security and Resilience Bill directly targets the root of digital vulnerability, by regulating MSPs and critical third-party suppliers. Both legislative regimes demand active, personal accountability from corporate boards, away from the old de facto approach of one specialist board member taking responsibility. For businesses that sit outside the formal scope of these laws, there is no reprieve, with security expectations increasingly pushed down supply contracts by regulated companies.
This represents a single, cohesive board duty rather than three separate disciplines overlapping. No single function: cyber, legal, or data - privacy or governance, can grasp the entire landscape, which requires multi-disciplinary expertise. Appointing a CISO as Chief Trust Officer has recently been proposed, but is unlikely to be successful, as the role lacks both the cross-functional purview and the operational independence necessary to audit its own technology footprint. As this series has argued elsewhere, boards that hand over this judgement to whoever understands the technology best build concentrated authority instead of shared fluency. This same structural blindness skews vendor prioritisation, with supply chains audited solely by financial spend frequently relegating low-cost, high-risk data vendors to low priority, even when contrary to actual risk exposure. If a product is free or especially cheap, you or your data are generally the product.
Where to start
- Identify the ten vendor relationships that would cause the most harm if they failed. Judge this by the potential damage to the business, rather than by financial spend or proximity to IT: considering both financial exposure and likelihood, and risk of harm, including to those whose data is in scope. Ten is a deliberate, manageable starting point: the average remediation cost across these top ten becomes the concrete business case for funding the wider programme.
- Establish a cross-functional team rather than relying on a single department. This group must report directly to the board, holding a unified mandate to assess each vendor relationship across cyber, privacy, and AI risks simultaneously. Crucially, they must possess the organisational authority, and funding, to act on what they find.
- Run realistic board and executive scenarios in a calm environment. Test a concurrent cyber breach, data breach and AI manipulation event to answer critical questions: who has authority to act, do we have true operational resilience, what would we need to disclose and to whom, do we require vendors to meet and to pass on our minimum requirements to sub-contractors / fourth parties (long required under privacy legislation). NIS2 and the UK cyber regime demand incident notifications within exceptionally tight windows: deadlines that are nearly impossible to meet if the board's first real engagement with the crisis happens during a live attack rather than before it.
The boardroom can no longer evaluate cyber, AI, and data as distinct line items. These risks intersect at a single point of failure, with a single vendor event now causing near-instant, enterprise-wide fallout. Yesterday’s tools answer three separate questions, but today's boards need one unified answer.
Anything less is corporate decoration: a register that looks complete, until somebody finds out what's actually in it at 2am on a Sunday.
Emma Di Iorio is Co-Founder and CEO of Spriggun, a UK-based RegTech and AI governance advisory firm. A qualified solicitor with senior in-house and advisory experience, she writes and speaks internationally on AI, data, privacy, and web compliance.