48% of data breaches involve a Third-Party Access: key findings from Verizon's 2026 DBIR

Publish on August 06, 2026

Rapport

by Loren Breux

The figure that should alarm CISOs and CIOs

The latest Data Breach Investigations Report (DBIR) published by Verizon reveals a worrying trend: nearly one in two data breaches now involves a third party (service provider, integrator, technical vendor...). This figure reflects a sustained upward trend over several years, with a notable acceleration compared to last year (+60%).

What should really catch the attention of CISOs and CIOs isn't the scale of the figure itself, but its root cause. The report points to basic underlying failures: missing or misconfigured multi-factor authentication, excessive permissions left unreviewed... No sophisticated zero-day, no complex exploit chain. Just a breakdown in control and security over third-party access.

This calls for a shift in posture : third-party risk is no longer a contractual or legal matter left to procurement teams. It's a matter of architecture and privileged access governance.

Why Third-Party Access has become a preferred attack vector

The growing number of service providers (managed IT services, application maintenance, vendor support, specialized integrators) has significantly expanded the attack surface for accessing sensitive systems. Every third party working on a server, database, or network device represents a potential entry point.

The structural problem is well known to security teams : these accesses are created for a specific project or engagement, then rarely revoked or reviewed once the work is done. A vendor account opened two years ago, with admin rights that were never scaled back, becomes low-hanging fruit for an attacker, without a single software vulnerability needing to be exploited.

83% of privilege escalation incidents involve no CVE at all. This is one of the most telling findings in the report. It's not a missing-patch problem. It's a problem of poorly managed privileged accounts, permissions that accumulate without ever being reassessed, and third-party access that falls outside any centralized audit trail.

For a CISO, this finding shifts investment priorities : patch management remains essential, but it doesn't cover the primary risk identified by incident analysis.

NIS2 : regulation is pushing in the same direction

This operational finding converges with an increasingly structuring regulatory requirement : the NIS2 Directive explicitly makes supply chain security one of its compliance pillars.

For entities in scope, this means, in practical terms : being able to demonstrate that access granted to third parties is controlled, time-bound, and scoped. This is no longer an optional best practice, it's a control point expected by supervisory authorities.

For CIOs and CISOs currently working toward compliance, this convergence between field-tested incident data and the regulatory framework provides an additional argument to prioritize a workstream too often postponed : third-party privileged access governance.

Taking back control : traceability and least privilege on Third-Party Access

Given these findings, the structural response follows a well-established cybersecurity logic : the Privileged Access Management (PAM) solution or bastion host.

The principle is simple to state, but far more demanding to implement without the right tools : no direct access from a third party to a sensitive resource (server, database, or device). Every access request goes through a single control point (the bastion host), acting as an access broker.

Four pillars structure this approach :

  • Access control : every third-party connection is authenticated, authorized, and restricted to the scope strictly required for the task at hand (applying the principle of least privilege).
  • Secure access : multi-factor authentication (MFA) is enforced on every connection, reducing the risk that a single compromised credential is enough to reach a sensitive system — precisely one of the root causes identified by the DBIR.
  • Secrets protection : credentials used to access resources (passwords, SSH keys) are stored in an encrypted vault and never pass through the vendor's workstation. They are therefore never disclosed to external parties.
  • Session recording : actions performed by a third party on a sensitive system are logged and recorded, turning privileged access into traceable, auditable access.

This approach directly addresses both root causes identified above : it strengthens authentication (beyond a simple, potentially misconfigured MFA on the vendor's end) and it prevents the silent accumulation of excessive permissions.

PROVE IT : an operational response

This is precisely the role that PROVE IT fulfills. Several factors make it a well-suited response to the third-party risk challenges facing CISOs and CIOs :

  • Operational simplicity : designed for fast deployment and straightforward day-to-day administration, without unnecessary operational complexity.
  • Controlled TCO : pricing positioned to remain accessible without compromising on the control and traceability capabilities expected from this type of solution.
  • Genuine vendor proximity : direct support and a close working relationship with the team — a real advantage in responsiveness for compliance projects under tight deadlines.
  • Recognized certification : PROVE IT holds the CSPN security certification (Visa de sécurité) issued by ANSSI since 2018, renewed in 2023, with a further renewal underway extending validity to 2029. A mark of robustness assessed by France's reference cybersecurity authority.

Conclusion

The message from these incident reports, year after year, remains consistent: technical sophistication isn't the first line of defense that needs strengthening. Access hygiene, particularly for third parties, remains the most exploited weak point.

With a regulatory framework pushing in the same direction, deploying an administration bastion is a workstream to prioritize, not postpone.

Discover PROVE IT Bastion host

Our solution

Our bastion host is designed for organizations that want a high level of security without the complexity of traditional solutions.

Written by

Loren Breux

Marketing project manager