Francis Dinha is CEO and cofounder of OpenVPN Inc., a leading enterprise network security company.

When the World Leaks ransomware group published 630 gigabytes of Tata Electronics data on the dark web in June 2026, the files that drew the most attention were not Tata’s own. They were Apple’s and Tesla’s: unreleased iPhone 18 Pro component specifications, engineering drawings, quality inspection standards bearing Apple’s proprietary markings, supplier lists and years of internal event logs. No system was directly breached. Rather, the attack landed on a manufacturing partner in India and traveled from there into some of the most jealously guarded intellectual property in the technology industry.

This is the central irony of modern supply chain security, and one I have come to believe most boardrooms still fundamentally misjudge. The most damaging breaches rarely flow through the vendors that organizations worry about most. They flow through the ones organizations trust most deeply.

The Trust Problem Is Structural

The conventional approach to supply chain risk treats the problem as one of identifying weak links. This methodology is widespread and feels intuitive, yet I would argue it measures the wrong variable entirely. It tells you which vendors look risky on paper. It tells you almost nothing about which vendors you have too much confidence in to question.

According to the Verizon 2026 Data Breach Investigations Report, breaches with third-party involvement have increased 60% since last year and now make up a full 48% of all breaches. Attackers exploit this because vendor relationships carry inherited trust, and inherited trust is an efficient passage into environments that would otherwise be difficult to reach.

I find this to be the uncomfortable truth that most vendor risk programs avoid confronting. A company’s security posture is only ever as strong as the weakest set of controls anywhere in its extended chain, and that chain now runs through partners with more access than most executives realize.​

Depth Of Access And Depth Of Scrutiny Move In Opposite Directions

There is a pattern here. The vendors that accumulate the deepest access to an organization’s sensitive data and systems tend, over time, to accumulate something else: familiarity. Procurement processes that were once rigorous become routine, and security reviews that were once thorough become periodic, until the relationship’s own longevity starts to substitute for evidence of its safety.

I have watched this happen inside organizations that would never describe themselves as complacent, and I think that is exactly the point. Complacency rarely announces itself. It arrives disguised as the faith you have in your most reliable vendor.

This is where zero-trust architecture offers a useful discipline in its own right, not merely as a network design principle but as a philosophy of vendor governance. Zero trust took hold because perimeter-based security could not account for the complexity of modern environments, and the same logic applies directly to supply chain relationships. Assuming a vendor is safe because it has been reliable for years is the organizational equivalent of assuming a device is safe because it is inside the corporate network. Both assumptions fail under exactly the conditions that matter most.

A supply chain compromise now costs an average of $4.91 million and takes 267 days to identify and contain, the longest breach life cycle of any attack vector tracked by IBM’s Cost of a Data Breach research. That extended dwell time reflects how difficult it is to detect malicious activity inside a trusted channel, where the traffic looks, by deliberate design, indistinguishable from legitimate business operations.

​The Perimeter Has Moved, And Most Security Models Have Not Followed

The Tata breach was not a ransomware story in the traditional sense. The attackers’ ambition was not operational disruption but data possession. Group-IB’s High-Tech Crime Trends Report 2026 characterizes this shift in a compelling way, describing how modern cybercrime has “industrialized cybercrime, exposed the limits of perimeter-based defenses, and elevated identity and trust as the new primary attack surfaces.”

Defenders, the report argues, must move beyond the vocabulary of isolated systems and toward securing trust itself as a distinct and governable layer of the security architecture.

I would go a step further: Trust should be treated as a liability on the balance sheet of enterprise risk, one that accrues quietly and comes due without warning.

Vendor risk programs focused on identifying the weakest suppliers are solving an important problem, though an increasingly secondary one. The more consequential challenge lies in governing the relationships where comfortable confidence has silently outpaced scrutiny; where a breach in a deeply embedded partner can travel through familiar, well-worn channels into the most sensitive reaches of the enterprise.

Governing Trust Rather Than Assuming It

Treating trust depth as a risk variable is significantly different from how most vendor risk programs are currently structured. It suggests that the suppliers warranting the most rigorous ongoing attention are precisely those most deeply integrated, rather than those that score poorly on point-in-time security reviews. In practical terms, this means a leadership team should be able to name its most trusted vendor, describe exactly what that vendor can access, and explain when that access was last independently verified. If any part of that chain relies on the vendor’s reputation rather than current evidence, the organization has located its greatest point of exposure.

For organizations willing to follow that logic, the path forward involves moving from periodic attestation toward continuous visibility into third-party environments, with particular attention to the partners whose reach into sensitive systems is broadest. It means defining explicitly what data and infrastructure each supplier can touch, auditing that access frequently, and extending zero-trust principles into the vendor ecosystem itself rather than stopping at the organization’s own walls.

The Tata breach will not be the last of its kind, because the economics of supply chain compromise are simply too favorable to attackers for the pattern to reverse on its own.

I would challenge any executive reading this to make note: The vendor in which you have the most faith and familiarity is likely the one you have stopped examining, and that is precisely the reason it deserves your closest attention now.​

Forbes Technology Council is an invitation-only community for world-class CIOs, CTOs and technology executives. Do I qualify?

Share.
Leave A Reply

Exit mobile version