The Leverage Myth in Vendor Risk
Third Party Podcast: What Actually Moves Vendors to Fix Their Risk

Introduction
In the latest episode of the Third Party podcast, Jeffrey Wheatman, Bob Maley, and Ferhat Dikbiyik put a favorite TPCRM assumption on trial: that your organization holds real leverage over the vendors it depends on. The verdict is not what most risk teams want to hear.
Ask a room full of CISOs how many could actually walk away from a vendor relationship over cyber risk, and the honest answer is almost none. That is the uncomfortable starting point for this episode, and it changes everything about how third-party risk programs should actually operate.
The Leverage Illusion
Most TPCRM programs still run like leverage is unlimited: send the questionnaire, escalate to legal, repeat until compliant. That model assumes a kind of power that mostly does not exist. A CISO's job was never to say no to a vendor relationship. It is to expose the risk and let the business decide, which means most of what the industry calls leverage is really just a persuasive risk report.
And when the vendor is a hyperscaler, good luck. Telling Amazon, Google, or Microsoft they are not patching fast enough gets you their process, on their timeline, regardless of how large your invoice is.
The Vulnerability Math Doesn't Work in Your Favor
Mid-market vendors, smaller software providers, and open-source maintainers now average 197 days to detect a vulnerability and 60 days to remediate it, according to Black Kite's 2026 Supply Chain Vulnerability Report. Attackers using the same class of AI-assisted discovery tools are effectively operating on negative seven days, exploiting flaws before the public disclosure clock even starts. That gap is not closing. It is widening, because AI-powered scanning is expensive, and only the best-resourced vendors can afford the tier that actually closes it.
It gets worse before it gets better. Roughly 48,000 vulnerabilities were published last year, yet only 58 of them were genuinely relevant and dangerous to enterprise supply chains. Managing all 48,000 is not a strategy. It is a delusion. The real job is prioritization: knowing which few dozen matter and building the relationship muscle to get vendors to act on exactly those.
A vendor claiming they are patched tells you almost nothing on its own. A thousand servers with one patched does not mean a thousand servers are safe, and most organizations cannot say how fast they are remediating relative to what they committed to in their own risk assessments. This is where cyber risk quantification earns its keep, and it is the same logic behind Black Kite's Ransomware Susceptibility Index® (RSI™): a compiled signal of ransomware risk, not a raw vulnerability count, built so the answer maps to business impact instead of a CVE tally. Instead of chasing a patch percentage, the better question is whether loss exposure is shrinking. If you do not know your loss exposure, every leverage conversation is a guess dressed up as a plan.
The First 90 Days, Mostly
The early stretch of a vendor relationship tends to set the tone for everything that follows, though it is not an ironclad rule. Show up with real, well-packaged intelligence tied to a specific exposure instead of a generic warning, and even a rocky start can turn around once a vendor sees the tip was accurate.
One escalation path makes the point concrete. Flagging a serious exposure at a fourth party, then working through account managers and executives until the finding reached the actual security team, framed purely as "here is your exposure" rather than a demand, reset an entire relationship going forward. Blame closes doors. Information a vendor can act on opens them.
When the Vendor Truly Can't Be Replaced
Every vendor is technically replaceable. Some are just brutally expensive or slow to swap out, and that distinction changes the whole leverage conversation. The right response is a risk-based one: compare the dollar value a vendor delivers against the dollar cost of the exposure, and let that math, not frustration, drive the decision.
One real example makes the logic concrete. A manufacturer relying on a single supplier for an irreplaceable component recognized the cyber risk, quantified it, and stockpiled millions of dollars of inventory as a mitigating control. When that supplier was later hit with ransomware, production never stopped. That is not leverage, and it is not luck. It is knowing exactly what the horse is worth before deciding how much fence it deserves.
Collaboration Beats Enforcement, Every Time
None of this means leverage is fake. It means the industry has been defining it wrong. Contract language that reads like a threat gets ignored the moment a vendor has any other option, while contract language built around collaboration, paired with continuous intelligence instead of an annual questionnaire, actually gets a response.
The goal was never to switch vendors. It is to shrink the risk while keeping the relationship intact, and that requires trading blame for value: showing a vendor exactly what was found, why it matters to their specific business, and how to fix it, instead of flagging that a CVSS score is red. Continuous, standards-based monitoring shared through Black Kite's vendor engagement makes that kind of intelligence-led outreach the default instead of the exception, and a standards-based risk methodology keeps the underlying math honest.
The real shift is starting the conversation before an incident forces it. Programs that build trust early spend less time arguing about leverage and more time actually getting vendors to fix what matters.
Don't Miss an Episode!
Subscribe to Third Party on YouTube, the podcast for people who don't need to ask ChatGPT what TPCRM means. New episodes every other week.
Next time on Third Party:
Next time we get into the AI vulnerability scanning revolution. Projects like Glasswing and Frontier cyber models like Mythos and Daybreak are claiming to change the whole game. We break down what actually changes for risk teams and what is still mostly marketing.
Subscribe below.