Data Breach Risk
Data breach risk is the risk that a vendor incident results in unauthorized access to or exposure of sensitive data belonging to the first party or its customers. It is one of the three Factor Analysis of Information Risk (FAIR) model scenarios in Black Kite's Financial Impact Rating.
How Do Vendors Create Data Breach Risk?
Vendors create data breach risk whenever they hold, process, or can reach an organization's data, because a compromise on their side exposes it. The exposure comes through three paths:
- Stored data: Customer records or internal data held in a vendor's platform.
- Granted access: Integrations and accounts that reach into the organization's systems.
- The vendor's own third parties: Any sub-processor that handles the data on the vendor's behalf.
Access Paths Carry Risk Without Stored Data
A vendor that stores none of an organization's data can still expose it. An integration with read access to a customer database, or an administrative account on a customer system, gives an attacker the same reach once the vendor is compromised. Reviews that only ask what data a vendor holds miss this path entirely.
Black Kite's 2026 Third-Party Breach Report measured the scale. The publicly disclosed human impact of third-party breaches in 2025 reached 433 million people, roughly the population of the EU.
Why Do Organizations Learn About Vendor Breaches So Late?
Vendors detect breaches far faster than they disclose them, which leaves customers exposed without knowing it. The same report measured that gap. Vendors detected breaches in a median of 10 days, but public disclosure took an average of 117 days, with a median of 73 days.
The Disclosure Gap Widened in 2025
The average disclosure window grew from 76 days in 2024 to 117 days in 2025. Black Kite calls this period the Silent Window. It's why official notifications can't be the only way an organization learns its data is at risk. A vendor's fast detection does nothing for a customer that hasn't been told, so continuous monitoring of vendors shortens the customer's side of the gap.
What Notification Duties Apply When a Vendor Is Breached?
Under GDPR, a vendor acting as a processor must notify its customer without undue delay, and the customer then has 72 hours from awareness to notify its supervisory authority. That sequence puts the vendor's speed on the customer's compliance clock. Article 33 of GDPR requires the customer's notification to describe the nature of the breach, including the categories and approximate number of people and records concerned. If the notification arrives after 72 hours, it has to include the reasons for the delay.
The Customer's Clock Starts at Awareness
The 72-hour window runs from when the customer becomes aware of a breach. A vendor that takes weeks to disclose pushes the customer's awareness back by the same amount.
Contracts that define how fast a vendor must report a breach, and what the report must contain, give the customer the detail it needs to meet its own obligations.
How Is Data Breach Risk Quantified?
Quantifying data breach risk means estimating how often a vendor breach is likely to happen and how large the loss would be. Black Kite models it separately from its ransomware and business interruption scenarios, so a breach estimate isn't blended with other kinds of loss. The output feeds Black Kite's Financial Impact Rating, which puts vendor data breach risk in dollar terms.
Shared Record Volume Changes the Estimate
How much data a vendor holds directly affects the size of a potential loss. Black Kite's view of the financial impact of cyber risk lets teams model how sharing more or fewer records with a vendor changes probable financial impact. A vendor’s breach history is a separate signal. Black Kite's Data Breach Index a company’s recent exposure from 0.0 to 1.0, based on the severity and recency of data breaches, leaked credentials, stealer logs, hacktivist mentions, and IP reputation issues.
How Is Data Breach Risk Different From Data Exfiltration?
Data exfiltration is one way a breach happens, while data breach risk covers every path to exposure. Data exfiltration is the specific act of moving data to an attacker. Data can also be exposed without anyone taking it, such as through a misconfigured storage bucket or a database left open to the internet. Either path ends in a data breach, and data breach risk accounts for both.
Which Data Raises Vendor Breach Risk the Most?
The kind of data a vendor holds matters as much as how much of it there is. Some categories carry more consequence when they're exposed:
- Regulated personal data: Records that trigger breach notification obligations when exposed, including health records that vendors handle for healthcare organizations.
- Credentials and access tokens: Data that lets an attacker move from the vendor into customer systems.
- Financial data: Payment card and bank account details that enable direct fraud.
Mapping which vendors hold which categories shows where a single breach would cost the most. Black Kite's research adds a caution here. A vendor breach that leaks only intellectual property or internal strategy, with no consumer data, can leave the affected company unnamed, since nothing triggers a public disclosure requirement.
What Reduces Data Breach Risk From Vendors?
Three levers reduce vendor data breach risk, which are sharing less data, detecting problems sooner, and knowing where leaked data ends up. Practical steps include:
- Data minimization: Limit the data each vendor receives to what the service actually requires.
- Notification terms: Set breach notification timelines in contracts, since public disclosure can trail detection by months.
- Continuous monitoring: Watch vendors for breach signals as they appear, ahead of any formal notice.
- Leak detection: Watch for exposed data on the dark web and in stealer logs.
Internal Data Handling Needs Assessment Evidence
External monitoring can't see how a vendor handles data internally, such as its access controls or retention practices. Those still need evidence from an assessment. Pairing the two gives a fuller picture than either one alone.
How Does Black Kite Track Vendor Data Breach Risk?
Black Kite flags vendors affected by confirmed data breaches and estimates what a vendor breach could cost. FocusTags® include Data Breach tags, which highlight vendors affected by confirmed breaches so a team can assess exposure and begin follow-up immediately. Black Kite's monitoring maps those events to specific vendors in a portfolio. The data breach scenario in Black Kite's Open FAIR™ quantification then estimates the dollar impact.
See also: 2026 Third-Party Breach Report: Our Top Key Takeaways