Why Your Third-Party Risk Program Is a Spreadsheet, Not a Strategy
April 20, 2026 · 5 min read
Most third-party risk programs give organizations a false sense of visibility. They know how many vendors completed questionnaires. They do not know which vendors could take them down.
The typical third-party risk management program I encounter looks something like this: a spreadsheet or GRC platform tracks vendors, assigns risk tiers, and sends out security questionnaires on an annual cycle. Vendors respond — some promptly, some after months of follow-up — and the responses are reviewed, scored, and filed. The program produces metrics. It satisfies the audit. And it provides almost no meaningful insight into which third-party relationships actually pose existential risk to the organization.
I am not saying these programs are worthless. I am saying they are optimized for the wrong outcome.
The Questionnaire Problem
Security questionnaires are the backbone of most third-party risk programs, and they are fundamentally limited in ways that most organizations have accepted without question.
A questionnaire captures a vendor's self-reported security posture at a single point in time. It tells you what the vendor says they do. It does not tell you what they actually do. It does not tell you what changed since they submitted the form. And it does not tell you what would happen to your operations if that vendor experienced a significant security incident tomorrow.
The vendors that pose the greatest risk to your organization are often not the ones with the weakest questionnaire responses. They are the ones with the deepest integration into your environment, the broadest access to your data, or the least substitutability if they go down.
The question is not "did this vendor pass the assessment?" The question is "what happens to us if this vendor has a bad day?" Those are very different questions, and most third-party risk programs only answer the first one.
Concentration Risk Is the Real Threat
The incidents that have caused the most widespread damage in recent years were not caused by obscure vendors with poor security practices. They were caused by widely used platforms and service providers whose compromise cascaded across thousands of organizations simultaneously.
This is concentration risk, and most third-party risk programs are not designed to identify or manage it. Your questionnaire may tell you that your cloud provider has SOC 2 certification. It does not tell you that the same provider also hosts your backup infrastructure, your email, your collaboration platform, and three of your critical SaaS applications. When that provider has an outage or a breach, your exposure is not one vendor relationship. It is five.
Mapping concentration risk requires understanding not just who your vendors are, but what they connect to, what they depend on, and where the same underlying infrastructure appears multiple times in your technology stack. Most organizations have not done this mapping. The ones that have are often surprised by what they find.
What a Strategic Program Looks Like
A third-party risk program that actually reduces risk, rather than just documenting it, has a few characteristics that distinguish it from the spreadsheet approach.
It starts with impact analysis, not vendor enumeration. Instead of asking "how many vendors do we have," it asks "which vendor relationships, if disrupted, would most significantly impact our operations, our data, or our customers?" This produces a much shorter list, and that shorter list is where the real work should be focused.
It includes scenario-based assessment. For each critical vendor relationship, the organization has thought through specific failure scenarios and has at least a preliminary answer to the question: what do we do if this vendor is unavailable for 24 hours? A week? Permanently?
It monitors continuously, not annually. The security posture of a critical vendor in January may bear no resemblance to their posture in October. Annual questionnaires create a false sense of currency. Continuous monitoring — through threat intelligence, breach notification tracking, and ongoing relationship management — provides something closer to an actual picture.
And it has executive visibility. The most critical third-party dependencies should be known and understood at the executive and board level, not buried in a GRC platform that only the risk team accesses.
Where to Start
If your organization has an existing third-party risk program, the most valuable thing you can do is not expand it. It is to sharpen it. Identify your ten most critical vendor relationships based on operational impact, not risk tier. For each of those ten, answer three questions: what is our exposure if they are compromised, what is our continuity plan, and when did we last validate both?
If you cannot answer those questions for your top ten, the spreadsheet with 500 vendors on it is not helping you. It is distracting you from the work that matters.
Next Step
Ready to strengthen your organization's resilience?
A 30-minute discovery call to discuss your cybersecurity posture, incident readiness, and whether advisory support is the right fit.