Continuous Monitoring
Continuous monitoring is the ongoing, automated surveillance of a vendor's external security posture, as opposed to relying on point-in-time assessments. It surfaces new vulnerabilities, configuration changes, and emerging threats in near real time, replacing the inadequate "assess once a year" model that leaves organizations blind to changes between review cycles. Black Kite rescans vendor portfolios on a rolling basis and surfaces changes through FocusTags® and automated workflow alerts.
What Is Continuous Monitoring in Cybersecurity?
Continuous monitoring is the practice of maintaining always-on, real-time surveillance of a vendor's external security posture, tracking changes in their attack surface, vulnerability exposure, ransomware susceptibility, dark web signals, and compliance posture without waiting for scheduled reassessments or vendor-submitted updates.
What Is Continuous Monitoring in Third-Party Risk?
In third-party cyber risk management, continuous monitoring replaces the annual questionnaire cycle with a living, observable picture of each vendor's security state. It is the difference between knowing what a vendor's security posture looked like when you last asked and knowing what it looks like today.
The case for continuous monitoring starts with a simple problem: vendor security posture changes constantly, and most organizations check it infrequently.
Why Is Point-in-Time Assessment No Longer Sufficient?
Point-in-time assessments (questionnaires, annual reviews, SOC 2 reports) give you an accurate picture of a vendor's security posture on the day the assessment was completed. They tell you nothing about the 364 days that follow.
The 2026 Third-Party Breach Report found that the average time between a vendor compromise and its public disclosure was 117 days. That gap doesn't exist because organizations aren't paying attention. It exists because the mechanisms most programs rely on to detect vendor risk changes create intervals of blindness between checks. A vendor that passed last year's assessment may have deployed software with an unpatched critical vulnerability in month two. A third party that looked clean at onboarding may have had credentials exposed on the dark web in month four. Without continuous monitoring, neither change surfaces until the next scheduled review. Often it doesn't surface at all.
The threat environment doesn't run on annual cycles. Attackers don't wait for your vendor's assessment window to exploit a newly disclosed vulnerability. Continuous monitoring aligns your detection capability with the actual pace of risk change. AI for TPRM: Filter the Noise in 24/7 Risk Monitoring covers how AI changes what's operationally possible at this stage.
What Does Continuous Monitoring Actually Watch?
Continuous monitoring for third-party cyber risk covers several distinct signal types, each addressing a different dimension of vendor exposure.
Attack Surface Changes
A vendor's external-facing infrastructure (domains, IP ranges, cloud assets, application endpoints) changes frequently. New assets expand the attack surface. Misconfigured or forgotten assets create exploitable gaps the vendor may not be aware of. Continuous monitoring tracks these changes as they happen rather than capturing a snapshot once a year.
Vulnerability Exposure
When a critical vulnerability is disclosed (a new CVE, a known exploited vulnerability (KEV), or a zero-day) continuous monitoring determines which vendors are running affected software and how exploitable their instances are. Vulnerability Intelligence Briefs™ (VIB™) provide this ecosystem view: not just which software is vulnerable globally, but which of your specific vendors are running it and what their actual exposure looks like.
Ransomware Susceptibility
The Ransomware Susceptibility Index® (RSI™) monitors changes in each vendor's susceptibility to ransomware attack based on observable signals in their digital footprint. These are the same patterns that appear in vendors that have historically been victimized. RSI changes in real time as vendor behavior changes, providing a predictive signal rather than a retrospective one.
Dark Web and Leaked Credentials
Continuous monitoring tracks whether vendor employee credentials, system access tokens, or sensitive data appear in dark web forums or breach datasets. Leaked credentials from a vendor's environment are often the first visible indicator of a compromise, appearing weeks or months before an official breach disclosure.
Threat Actor Targeting
FocusTags® connect global threat intelligence to the specific vendors in your ecosystem. Active ransomware campaigns, exploited vulnerabilities, and threat actor targeting patterns all feed into the same view. When a threat actor begins targeting organizations using a particular software vendor's product, FocusTags® surface that exposure in your vendor inventory immediately.
How Does Continuous Monitoring Fit Into the TPCRM Lifecycle?
Continuous monitoring is the operational core of the TPCRM lifecycle. It's what happens between onboarding and offboarding. It's the sustained risk management that makes a vendor relationship manageable rather than a periodic guessing game.
The risk baseline established at onboarding becomes the reference point against which continuous monitoring measures change. A vendor who onboarded with a specific set of open findings is being watched for changes against that baseline. When their posture improves, that's captured. When it degrades, an alert is generated before the degradation becomes a third-party breach.
Continuous monitoring is what keeps vendor risk decisions current between formal review cycles. A vendor's onboarding assessment reflects their risk profile on day one. Without ongoing monitoring, that snapshot ages. With it, significant changes, such as a new critical vulnerability, a spike in ransomware susceptibility, or credentials appearing on the dark web, surface in real time, giving teams the intelligence to act before the next scheduled review.
The link to vendor response is equally direct. An effective continuous monitoring program doesn't just detect risk. It routes risk to the right response workflow. When a monitoring alert surfaces a critical finding in a Tier-1 vendor's environment, the downstream action should be automatic: an alert to the responsible team, engagement initiated with the vendor through The Bridge™, and a tracked remediation request with a defined resolution timeline.
What's the Difference Between Continuous Monitoring and Periodic Reassessment?
Periodic reassessment is a scheduled check. Continuous monitoring is persistent surveillance. The distinction matters because the risk each catches is fundamentally different.
Periodic reassessment catches risk that exists at assessment time. If a vendor's patching falls behind in month three and they catch up by month eleven, a year-end reassessment won't see the gap. If a vendor deploys new infrastructure with a misconfiguration in month seven, you won't know until the next review. By then it may already have been exploited.
Continuous monitoring catches risk as it appears. A new critical CVE affecting a vendor's software stack is visible within hours of disclosure. A credential appearing on a dark web forum is detected as it's posted. A change in a vendor's network configuration is logged when it happens.
For organizations subject to regulatory requirements under DORA, NIS2, or NIST SP 800-161, continuous monitoring isn't just best practice. It's increasingly an explicit obligation. These frameworks expect organizations to demonstrate ongoing awareness of vendor risk posture, not just evidence of periodic review. Your Vendor's Breach Already Happened makes the case for why waiting for vendor disclosure is a losing strategy. Think Like a Hacker for Successful TPRM extends that argument into what ongoing surveillance actually needs to watch for.
How Does Black Kite Deliver Continuous Monitoring?
Black Kite Monitor is the always-on monitoring capability within the platform, running passive, non-intrusive surveillance across the full vendor ecosystem without requiring vendor participation or agent installation.
The platform monitors each vendor's external digital footprint continuously, tracking the 20 technical control categories that make up Black Kite's standards-based cyber rating methodology, along with RSI™ changes, FocusTag® alerts, dark web signals, and financial impact exposure.
Because the monitoring is outside-in, it doesn't depend on the vendor reporting changes to you. A vendor that doesn't know their credentials were leaked, or hasn't yet patched a disclosed vulnerability, is still visible in the platform. Your awareness of their risk isn't limited by their own awareness of it.
For organizations managing supply chain cyber risk across extended ecosystems, Black Kite Extend adds Nth-party visibility by monitoring the fourth and fifth parties your vendors depend on. It surfaces cascading risk before it reaches your organization. The 2026 Third-Party Breach Report documented 136 third-party breach events affecting 5.28 downstream organizations each. The programs that reduced their exposure were not the ones with better questionnaires. They were the ones watching their vendors continuously.