Cyber Risk
of digital systems, data security, or technology infrastructure. In third-party cyber risk management, cyber risk encompasses not only an organization's own exposure but also the risk introduced by vendors, suppliers, and other external parties with access to its systems or data.
What Loss Scenarios Make Up Cyber Risk?
Quantification models break cyber risk into distinct loss scenarios, so financial, operational, reputational, and regulatory losses can be traced to the event that causes them. Black Kite's Open FAIR™ quantification uses three mutually exclusive scenarios:
Data breach
Sensitive data is accessed, stolen, or exposed without authorization.
Ransomware
Systems are encrypted or data is held for extortion.
Business interruption
Operations are disrupted by environmental or supply chain events, such as natural disasters, pandemics, geopolitical unrest, or supplier failures.
Each scenario carries its own drivers of how often a loss happens and how large it gets. Treating them separately keeps one number from hiding very different exposures.
How Does FAIR Break Cyber Risk Into Measurable Parts?
Factor Analysis of Information Risk (FAIR) measures cyber risk through two things, how often loss events happen and how large they are. FAIR builds those from a set of factors:
- Threat event frequency: How often a threat actor is expected to act against an asset.
- Vulnerability: The probability that a threat event becomes a loss event.
- Loss magnitude: The expected impact, including response, productivity, legal, reputational, and customer-related costs, along with regulatory penalties.
The output is a range of probable losses, and FAIR practitioners treat a defensible range as the goal.
How Does a Vendor's Cyber Risk Become Yours?
A vendor's cyber risk becomes yours when it holds your data, runs services you depend on, or connects to your systems, because you share the loss without controlling the safeguards. Black Kite's 2026 Third-Party Breach Report measured how far that sharing reaches. Each breached vendor led to an average of 5.28 publicly compromised downstream companies in 2025, the highest level Black Kite has recorded. Across 136 verified breach events, that added up to 719 publicly named victim companies. That spread is what turns one vendor incident into a third-party breach affecting many organizations at once.
The Most Shared Vendors Carry More Risk
The same report audited the 50 vendors most shared by the Forbes Global 2000. Those vendors averaged a cyber grade of 83.9, a B, and 52% had suffered at least one verified data breach. When one of them has an incident, the loss lands on every customer at once. That shared exposure is the pattern behind concentration risk.
How Do Organizations Respond to Cyber Risk?
NIST recognizes five responses to an identified risk, which are accepting, avoiding, mitigating, sharing, and transferring it. Each has a direct vendor equivalent:
- Accept: Keep the risk because it falls within tolerance, such as a low-criticality vendor with minor findings.
- Avoid: Remove the conditions that create the risk, such as declining a vendor or ending a relationship.
- Mitigate: Reduce likelihood or impact, such as requiring remediation or limiting the data a vendor receives.
- Share: Split the risk with another party through contractual arrangements.
- Transfer: Move the financial impact to another party, such as through cyber insurance.
Responses can also be combined over time. A team can accept a vendor risk briefly during onboarding, then mitigate it through remediation requirements once the contract is signed.
Risk Management Runs in Four Steps
NIST SP 800-39 organizes the work into four steps, which are framing risk, assessing it, responding to it, and monitoring it. Framing sets the organization's assumptions and tolerance. Monitoring closes the loop, since vendor risk shifts as vendors change their systems, their own third parties, and their security practices.
How Is Cyber Risk Measured?
Organizations measure cyber risk through ratings, quantification, and compliance assessment, and each one answers a different question. The three approaches are:
- Ratings: Technical security posture observed from outside, expressed as a cyber rating.
- Quantification: Probable financial loss, the focus of cyber risk quantification.
- Compliance assessment: Alignment with standards and frameworks, measured through a cyber risk assessment.
Black Kite's three-dimensional risk approach measures all three together, so no single view stands in for the whole picture.
How Do Inherent and Residual Cyber Risk Differ?
Inherent cyber risk is the exposure before any controls are applied, and residual cyber risk is what remains after them. A vendor that processes payment data carries high inherent risk no matter how well it's secured. Its controls determine the residual risk a customer actually accepts. Vendor programs use both, with inherent risk setting how closely a vendor is reviewed and residual risk setting whether the relationship is acceptable.
How Is Cyber Risk Different From Cybersecurity?
Cybersecurity is the set of practices and controls an organization uses to protect its technology, while cyber risk is the exposure to loss those practices are meant to reduce. Strong cybersecurity lowers cyber risk, and the exposure that remains is residual risk. Risk also depends on things security controls don't touch, such as how much data a vendor holds, how critical a service is, and how fast the business can recover. Two vendors with identical security practices can carry very different cyber risk for the same customer. The one holding more sensitive data or running a more critical service carries more.
Why Can't a Single Metric Capture Cyber Risk?
Each way of measuring cyber risk leaves something out, so relying on one creates blind spots. A technical rating shows security posture, but Black Kite has noted that a rating alone lacks context about business impact. A dollar figure adds that context, but it depends on the inputs behind it. A compliance result shows which controls a vendor reports having, and testing or observation shows how well they work. Reading the three together shows where they disagree, and those disagreements point to where a risk team should look next.
How Does Black Kite Measure Third-Party Cyber Risk?
Black Kite measures third-party cyber risk with standards-based ratings, Open FAIR™ financial quantification, and compliance mapping. Its standards-based ratings grade vendors across 19 categories using MITRE, NIST, and Open FAIR™ standards. Its view of the financial impact of cyber risk estimates probable loss across the ransomware, data breach, and business interruption scenarios. Those Open FAIR™ factors are populated from continuous monitoring data, assessment responses, and uploaded documentation.
See also: What Is Cyber Risk in TPRM?