Three Years of Ransomware Susceptibility Index Data Say Your Questionnaire Is Guessing
Published
Aug 3, 2026
Authors
Introduction
This blog makes the third-party cyber risk management case for an argument I laid out in full on LinkedIn: a flawless vendor questionnaire should worry you more than a messy one. Read the original post here: A Perfectly Pristine Questionnaire Is a Red Flag.
Years ago I sent security questionnaires to vendors, and some came back answered perfectly. Every control in place, every policy mature, not a single gap on the form. One vendor returned a security policy that still read "insert your company name." A pristine questionnaire is like a SOC report with zero findings: the first question it raises isn't about the vendor's security posture, it's about who actually filled the thing out. Self-graded homework collected once a year is still self-graded homework, no matter how sharp the questions get.
What RSI Measures
Black Kite just published the 2026 Ransomware Report, built on 7,551 publicly disclosed ransomware victims over the reporting period. Part of that work is the annual calibration of the Ransomware Susceptibility Index® (RSI™), which scores a company from 0 to 1 without asking that company a single question.
RSI combines two categories of externally observable evidence.
- Exposure covers the technical indicators an attacker would find first: possible vulnerabilities, misconfigurations, stealer logs, open remote ports, and other signals sitting on the vendor's perimeter right now.
- Predisposition covers the intrinsic indicators that shape how a breach plays out: geolocation, industry, annual revenue, and the size of the company's digital footprint.
Add them together and you get a susceptibility score built entirely from evidence a compliance questionnaire was never designed to capture.
Here's what that model looks like when you give it three years to prove itself.
The Power of Three Years of Data
.png&w=3840&q=85)
Our research shows companies scoring above 0.8 on this year's model were 291 times more likely to experience a ransomware attack than companies scoring below 0.2. In raw incidence terms, 41% of the high band got hit while the low band sat at 0.14%.
If this were only one year of data, it would make a good marketing slide, and I wouldn't blame anyone for filing it there. A three-year trend is what changed how I read this report. The multiplier climbed from 27x in 2023, to 96x in 2024, to 291x this year, while the high-risk band barely moved, holding in the mid-40s the entire run.
Why the Gap Keeps Widening
All of that growth traces to the bottom of the table. Incidence among low-RSI companies fell from 1.7%, to 0.5%, to 0.14% across the same three years. The model held its read on the risky vendors while getting dramatically better at clearing the safe ones.
Clearing the safe ones is the half of the job nobody puts on the slide, even though it's where your assessment hours go to die. Picture both inputs sitting in front of you. The questionnaire captures what somebody in the vendor's compliance office believed, or hoped, on the afternoon they finally found time to fill it out. RSI captures what an attacker scanning that same vendor can see this morning, checked against three straight years of actual victims. Running a third-party program on the first of those alone is driving with nothing but a rearview mirror, glanced at once a year.
I'll be diplomatic and say questionnaires and evidence-based tools are complementary, and there's some truth to that. But let's be direct about the real version: when three years of victim data point one direction and a self-assessment points the other, continuing to bet your program on the self-assessment is a decision. It's not one you'd want to defend to a board after the breach.
What This Means for Your Questionnaire
None of this means the questionnaire disappears entirely. Its purpose was always to find out whether a specific control is in place, whether it's mature, whether it's working or failing. If RSI and the evidence behind it already answer that before you ever engage the vendor, you've closed out 95%, maybe 98%, of the questions. What's left is three or four genuine clarifications worth a real conversation, the kind of targeted follow-up that AI-powered questionnaire management is built to route straight to the right analyst.
Not "describe your patch management program," which invites a paragraph of policy language. Something closer to "we're seeing an open RDP port on this subnet, walk me through why." That's not a weaker assessment process. It's the first one your vendors won't resent, and the first one you can actually trust.
If your third-party risk management program still runs on annual self-attestation, the data for the better path is public as of today. Comfortable inaction doesn't save you money. It just delays the bill.
See how Black Kite's Ransomware Susceptibility Index® maps this exposure across your vendor ecosystem in real time. Book a demo.