63% of Breaches Come Through Third Parties. Are You Ready?

September 16, 2026

How third-party vendors create hidden cybersecurity risks and what UAE businesses can do to strengthen resilience, visibility, and vendor security.

Cybersecurity shield connected to cloud services, data, AI, and third-party providers, illustrating third-party cyber risk and digital infrastructure security.

What if I told you the biggest threat to your organization is not a hacker in a hoodie? What if I told you it is a trusted partner you gave access to your systems years ago and never thought about again? For decades, we have spent our careers building walls and forging iron-bar door locks to keep the enemy out. But the walls are gone now. The doors are wide open. And nobody is sure what is coming through.

The illusion of control is crumbling across the world. At FutureSec, an event hosted by <a href="https://www.lexology.com/library/detail.aspx?g=f931db7e-eae1-481d-98aa-5efc11b16fd9#1">Khaleej Times</a>, cybersecurity leaders gathered to confront this new reality.

Cybersecurity shield connected to cloud services, AI, vendors, data, compliance, supply chains, and a broken third-party link illustrating cyber risk.
Security is a chain; it’s only as secure as the weakest link. — Bruce Schneier, security technologist

The Cloud Revolution and Its Hidden Cost

Twenty years ago, you owned your IT infrastructure. Today, that model is dead. We rely on cloud services and external providers. According to industry estimates, 94% of enterprises now use cloud services, and the average organization works with over 1,200 third-party vendors. Dee Deu of Chalhoub Group put it perfectly. We use external providers for functions that used to be internal. That changes everything about risk.

Cloud adoption is not bad. It gives us the agility and scale we could never build alone. But there is a downside. We depend on a handful of external players. When one fails, the ripple effects are massive. The 2021 AWS outage affected over 50,000 websites and cost $150 million. Strong security did not matter. Customers could not be served, and that had nothing to do with internal defences.

The Fourth-Party Blind Spot

Here is another layer that does not get enough attention. Fourth-party risk. Everyone focuses on the vendors you work with directly, but what about the vendors your vendors use? A failure at that level could cripple your business, and you might not even know that provider exists until it is too late. Research from Marsh shows that 60% of organizations work with more than 1,000 third parties, making it nearly impossible to track the full chain of dependencies. A failure anywhere can become a failure everywhere.

Patrick Pitchappa, the CISO at Equiti Group, put it bluntly. We become so reliant on third-party providers that we do not realize the exposure we have created. We think we are managing risk, but we are often just hoping the vendor has their act together.

The Shadow IT and Shadow AI Epidemic

Shadow IT makes this worse. Gartner estimates that 30% to 40% of enterprise IT spending is linked to shadow IT, meaning the unofficial technology stack rivals the official one in financial scale. Shadow AI is even more alarming. A PagerDuty survey found that two-thirds (66%) of office professionals have used AI tools or services at work, even though they believed doing so was not permitted under company policy.

Additionally, 88% have shared work-related information with public AI tools like ChatGPT, Claude, or Gemini, including 43% who have shared emails, 40% who have shared meeting notes, 34% who have input customer data, and 31% who have shared financial information or confidential company documents. Most organizations have little to no visibility into their full technology estate. You cannot protect what you do not know exists.

Why the UAE Is Different

This digital maturity makes the UAE a prime target, but it also puts the country ahead of the curve in responding to these challenges. The UAE has built a complete digital ecosystem where government services are accessible through a single mobile app, from renewing passports to paying utility bills. Smart cities like Dubai and Abu Dhabi use real-time data to manage traffic, energy, and public safety, making urban life more efficient every day. Into this connected environment comes a workforce representing over 200 nationalities. These diverse teams bring different cultural perspectives, technical training, and problem-solving styles to every challenge, which leads to more creative and robust security solutions. The UAE government has been proactive.

Through the UAE Cybersecurity Council and initiatives like the National Cybersecurity Strategy, the country has established clear governance frameworks. Regulations mandate data protection and vendor risk assessment. This gives global brands a safe, stable place to do business, but it also demands that they take third-party risk seriously. The ecosystem here does not tolerate complacency.

The Hard Truths from the Front Lines

The panelists at FutureSec were honest. No one has fully figured this out. But here are the survival tactics that emerged from the conversation.

Redefining Critical Infrastructure

First, we have to stop thinking about critical infrastructure as just the things we own. That definition is ancient history. We need to map out every service that our business depends on, even if it is provided by a third party. And we need to ask the hard questions about their resilience and security. If they go down, can we survive? If they get breached, how does that affect us? If they have a vulnerability that gets exploited, what is our exposure? We need answers, not assumptions. Dee Deu captured this perfectly when he said that we have to look at what services are actually critical to us. If you cannot answer that question in thirty seconds, you are already behind.

Building Redundancy into the DNA

Second, we have to build in redundancy. I know this costs money and adds complexity to our architecture. But if you are relying on a single cloud provider or a single vendor for a mission-critical function, you are sitting on a single point of failure. And we have all seen what happens when that single point collapses. Diversification is not just a financial strategy. It is a survival strategy. Spread your critical services across multiple providers where possible, and test your failover mechanisms regularly, not just on paper.

Gaining True Visibility

Third, we have to get deadly serious about visibility. That means actively hunting down every instance of shadow IT and shadow AI in your organization. This is not about punishing employees or locking everything down. It is about understanding the battlefield so you can actually manage the risk. If employees are using AI tools, we need to know about it. We need to provide approved alternatives. We need to educate them on the risks. We cannot bury our heads in the sand and pretend this is not happening.

Embracing Zero Trust as a Mindset

On top of that, we have to rethink our security architecture from the ground up. The old perimeter-based model is dead and buried. There is no wall to build when your infrastructure lives in multiple clouds and your data flows through dozens of third-party services. We have to shift to a zero-trust mindset. Assume nothing is safe. Verify everything. Build security into every layer of the stack, not just at the edges. The castle is gone. We are fighting in the open now.

According to a 2024 Gartner survey, 63% of organizations worldwide have now implemented a zero-trust strategy, either fully or partially. This shows progress, but there is still a long way to go. For 78% of organizations implementing a zero-trust strategy, this investment represents less than 25% of the overall cybersecurity budget. That suggests that for many, zero trust remains a checkbox exercise rather than a complete transformation.

Holding Vendors Accountable

We also have to hold our vendors accountable with an iron fist. That means doing proper due diligence before signing a contract. It means including security requirements in the agreement. It means auditing them regularly, without exception. And it means having a clear, battle-tested plan for what happens if they fail. Too many organizations skip this step because they are in a hurry to get a service up and running. But that is exactly when disaster strikes. Research shows that 51% of organizations do not assess vendors before granting system access, and 64% assess vendors only once a year or less. The average breach cost when no vendor risk programme exists is $4.9 million. That is not a gap. That is a gaping wound.

Accepting the New Normal

And finally, we have to accept that this is the new normal. The era of owning and controlling your entire infrastructure is over. That does not mean we are helpless. It means our approach to security and resilience has to evolve. We have to stop thinking in terms of perimeters and start thinking in terms of ecosystems where every third-party provider is a potential critical infrastructure risk. Treat them as such. The stakes could not be higher. The average cost of a third-party-related data breach now stands at $4.5 million, and that is before you factor in reputational damage, regulatory fines, and lost customer trust.

The Question You Need to Answer

Dee Deu asked a simple but powerful question. What services can you not live without? And who provides them? If you cannot answer in thirty seconds, you are already behind. That is not a rhetorical exercise. It is the starting point for every serious third-party risk management programme.

The conversation at FutureSec was about awareness and action. The organizations that figure this out will thrive. For global brands, the UAE offers a unique opportunity. The ecosystem demands better security. The regulatory framework provides clarity. The pace of adoption forces innovation. If you can build resilient operations here, you can build them anywhere. Your third-party providers are now part of your critical infrastructure. Treat them that way.

The walls are gone. But the fight is only beginning. Bullseye Technology has been watching this space for a while and has some thoughts worth hearing.

Key Takeaway

Third-party risk is no longer just a vendor-management issue. Organizations need clear visibility into the providers they depend on, stronger vendor oversight, redundancy for critical services, and a zero-trust approach to reduce the impact of failures and breaches.

Blog

Insights on Digital Strategy, Technology, and Growth

Lets Talk

Start Building Your Digital Infrastructure

Whether you're launching, scaling, or rebuilding, we help you design the digital foundation your business needs to grow.

Tell us what you're trying to achieve. We'll provide clarity, direction, and recommended next steps.