Supply-chain / third-party attack
In one sentence
A breach that reaches you through a vendor or software provider you trusted and connected to.
Attackers increasingly compromise a vendor, software update, or service provider to reach that vendor's customers. It's why carriers now ask how you vet third parties with access to your systems and data.
Why it's on your cyber insurance application
Third-party involvement appeared in ~48% of breaches in 2026 (Verizon DBIR); vendor questions are rising.
How the Readiness Check scores it
The free Check asks the same question a carrier will. Here it is, why it's asked, and the fix if today's honest answer is no. The full application question list has the rest.
Vendor & third-party risk
Do you review the security of vendors who access your systems or data?
Why carriers ask: Third-party breaches account for a large share of incidents. Applications increasingly ask how you vet vendors with access to your data.
If the answer is no: Start with the inventory: every vendor with system or data access, what they touch, and whether they have MFA. Ten vendors, one page, one hour.
The written evidence carriers accept
A “yes” on the application needs a document behind it. In the Readiness Pack, that document is:
Related terms
Would you pass this question today?
The free Readiness Check scores you across the ten control domains carriers probe, in five minutes, no email required for the score.