Third-Party Risk Management stories
Manufacturing leads ransomware targets in 2025 report
Last week
#
dr
#
vpns
#
ransomware
Manufacturing was the most targeted sector for ransomware in 2025, as Check Point counted 1,466 attacks worldwide amid rising supply chain exposure.
Doppel wins ISO trifecta for AI, security & privacy
Last week
#
firewalls
#
data protection
#
network security
Doppel secures three ISO certifications for AI governance, security and privacy, as enterprise buyers demand stronger assurance against AI-driven cyber threats.
Abacus wins CREST approval for penetration testing
This month
#
firewalls
#
data protection
#
devops
Abacus secures CREST accreditation for penetration testing, bolstering its pitch to regulated sectors as demand rises for verified cyber security assurance.
Manufacturers face CMMC readiness gap in defence chain
Last month
#
ransomware
#
iot security
#
supply chain
Small US defence manufacturers face CMMC readiness shortfalls as cybersecurity checks tighten, with many underestimating the work needed to win contracts.
NetRise launches Provenance to trace open source risk
Last month
#
devops
#
iot security
#
iot
NetRise unveils Provenance, a tool to trace open source maintainers and stop risky dependencies before they spread through software.
Appdome launches Vault for mobile compliance history
Last month
#
mdm
#
application security
#
physical security
Appdome unveils Vault, a mobile app compliance history workspace with an AI agent to track, audit and reconstruct security controls.
Drata launches AI tools for risk reviews & trust centres
Last month
#
cloud security
#
rpa
#
supply chain
Drata rolls out agentic AI tools to speed third-party risk reviews, automate security questionnaires and rapidly build online trust centres.
CSA adds new enterprise tiers for cloud & AI security
Last month
#
cloud security
#
ai security
#
risk & compliance
Cloud Security Alliance launches new enterprise tiers, offering CISOs analyst-led roadmaps to turn cloud and AI security frameworks into action.
Black Kite adds Open FAIR to quantify third-party risk
Last month
#
ransomware
#
digital transformation
#
supply chain
Black Kite weaves Open FAIR into its platform to automate financial loss estimates in third-party cyber risk assessments and reviews.
Cynomi targets MSPs with new third-party risk push
Last month
#
saas
#
digital transformation
#
cloud security
Cynomi is urging MSPs to tap booming demand for third-party risk services as supply chain attacks surge and compliance rules tighten.
Goldman Sachs Alternatives backs Schellman expansion
Last month
#
data protection
#
cloud security
#
partner programmes
Goldman Sachs Alternatives to take stake in Schellman, backing global expansion in AI governance, cybersecurity compliance and digital trust.
UpGuard unveils Risk Automations to speed cyber fixes
Last month
#
uc
#
siem
#
cloud security
UpGuard debuts Risk Automations to link cyber risk findings with security workflows, promising faster fixes after USD $75 million raise.
UpGuard raises USD $75m to expand AI cyber risk tools
Fri, 27th Feb 2026
#
digital transformation
#
cloud security
#
advanced persistent threat protection
UpGuard secures USD $75m Series C to scale its AI cyber risk platform, fuelling product development, global expansion and acquisitions.
CISOs confident on basics but fear AI & supply chain
Thu, 12th Feb 2026
#
data protection
#
digital transformation
#
socs
CISOs rate themselves strong on core cyber resilience but admit worrying gaps on AI-driven threats, deepfakes and software supply chain risk.
Bitsight unveils dark web tool to secure supply chains
Wed, 11th Feb 2026
#
data protection
#
martech
#
advanced persistent threat protection
Bitsight launches an AI-driven dark web monitoring tool to give organisations earlier warning of cyber threats targeting key suppliers.
Coverbase & Crowe team up on AI vendor risk checks
Thu, 5th Feb 2026
#
digital transformation
#
rpa
#
risk & compliance
Coverbase and Crowe forge AI-focused partnership to streamline vendor risk reviews and procurement oversight in tightly regulated sectors.
Nike probes suspected cyberattack & huge data leak
Wed, 28th Jan 2026
#
firewalls
#
data protection
#
ransomware
Nike is probing a suspected cyberattack after a hacker group claimed to leak 1.4TB of internal data, raising supply chain security fears.
Ricoh CloudStream secures SOC 2 Type II audit status
Tue, 27th Jan 2026
#
data protection
#
digital transformation
#
cloud security
Ricoh's CloudStream service has achieved SOC 2 Type II audit status, bolstering its cloud security credentials for regulated industries.
Retail & wholesale hit by exposed shared credentials
Fri, 23rd Jan 2026
#
ransomware
#
supply chain
#
risk & compliance
Over 70% of major retailers and nearly 60% of wholesalers have exposed credentials, leaving shared supply chains ripe for attack.
Privacy shifts from compliance checkbox to market edge
Fri, 23rd Jan 2026
#
data protection
#
data analytics
#
digital transformation
Privacy is shifting from a legal checkbox to a strategic differentiator as watchdogs and customers demand proof of real-world data protection.