Tuesday, August 11, 2026
LIVEThe Unrelenting Cyber Battle: Hacking Threats and the Imperative of Robust Data Protection///Navigating the Cyber Labyrinth: Bolstering Defenses Against Evolving Hacking Threats///The Dual Front War: Battling Hacking and Bolstering Data Protection in the Digital Age///The Ever-Evolving Cyber Threat Landscape: Navigating Hacking and Fortifying Data Protection///The Unseen Battle: Fortifying Data in an Age of Relentless Hacking///The Unseen War: Hacking's Relentless Advance and the Imperative of Data Protection///The Evolving Threat Landscape: Hacking, Data Protection, and the Imperative for Proactive Security///Navigating the Digital Minefield: Bolstering Data Protection in an Era of Relentless Hacking///The Dual Fronts of Digital Defense: Combating Hacking and Fortifying Data Protection///Hacking's New Frontier: Fortifying Data Protection in the Age of Advanced Cyber Threats///The Dual Front: Navigating Hacking Threats and Fortifying Data Protection in the Digital Age///Navigating the Digital Gauntlet: The Evolving Nexus of Hacking and Data Protection///The Unrelenting Cyber Battle: Hacking Threats and the Imperative of Robust Data Protection///Navigating the Cyber Labyrinth: Bolstering Defenses Against Evolving Hacking Threats///The Dual Front War: Battling Hacking and Bolstering Data Protection in the Digital Age///The Ever-Evolving Cyber Threat Landscape: Navigating Hacking and Fortifying Data Protection///The Unseen Battle: Fortifying Data in an Age of Relentless Hacking///The Unseen War: Hacking's Relentless Advance and the Imperative of Data Protection///The Evolving Threat Landscape: Hacking, Data Protection, and the Imperative for Proactive Security///Navigating the Digital Minefield: Bolstering Data Protection in an Era of Relentless Hacking///The Dual Fronts of Digital Defense: Combating Hacking and Fortifying Data Protection///Hacking's New Frontier: Fortifying Data Protection in the Age of Advanced Cyber Threats///The Dual Front: Navigating Hacking Threats and Fortifying Data Protection in the Digital Age///Navigating the Digital Gauntlet: The Evolving Nexus of Hacking and Data Protection///
Subscribe
Cyber Security
Independent · Digital
Thehackingpost
CybersecurityAI-assisted

As Third-Party Vulnerabilities Rise, CISOs Accelerate Push for Security Modernization

Panorays has released the latest edition of its annual CISO Survey for Third-Party Cyber Risk Management, highlighting significant concerns for security professionals.

Panorays has released the latest edition of its annual CISO Survey for Third-Party Cyber Risk Management, highlighting significant concerns for security professionals.

The survey indicates a rise in software supply chain attacks, as cybercriminals exploit the complexity of third-party components. The adoption of AI contributes to this increased threat surface, although it also provides new tools for defense.

According to the survey, 60% of the 200 U.S.-based CISOs reported an increase in third-party security incidents this year. Of these, 9% noted a significant rise, while 51% observed a slight increase. Third-party software risks are a major concern, with 23% of respondents identifying it as the primary risk to their organizations.

CISOs are increasingly aware of their reliance on third-party software vendors. A study by JumpCloud showed that enterprises use between 100 and 300 software-as-a-service applications, not accounting for cloud infrastructure and open-source components.

The survey indicates a rise in software supply chain attacks, as cybercriminals exploit the complexity of third-party components.
Grace Bennett · Thehackingpost

Visibility into third-party software supply chains is limited, with only 15% of respondents claiming full insight. Traditional vendor security questionnaires are still widely used, but 71% of CISOs find them inadequate for assessing third-party risk. As a result, two-thirds of CISOs are adopting AI-powered tools to enhance vendor risk assessment.

The adoption of AI tools is increasing, with CISOs recognizing the need for enterprise-wide risk management. AI enables automation in threat assessment, improving accuracy and reducing false positives.

Despite the benefits of AI, only 21% of CISOs have a comprehensive incident response plan for breaches related to external software suppliers. Larger organizations are more likely to have such plans, with 36% of CISOs at enterprises with 10,000 or more employees having proper incident response plans.

Advertisement

Panorays' founder and CEO, Matan Or-El, attributes the rise in third-party security vulnerabilities to the widespread adoption of AI tools but remains optimistic about AI's potential to address these challenges. "CISOs are increasingly seeing the value of AI-driven solutions to increase clarity around the evolving threat landscape," he stated.

Based on reporting by Cyber Security News.

AI transparency. This article was produced with the assistance of artificial intelligence and published under human editorial oversight. AI systems can make mistakes. Read how we use AI (EU AI Act, Art. 50).
Related Stories