Panorays Study Reveals 85% of CISOs Lack Visibility into Third-Party Threats
- Securityish
- Threats & Incidents
Quick Summary
The Securityish Brief
The 2026 CISO Survey conducted by Panorays, involving 200 CISOs from US-based companies, highlights critical challenges in managing third-party cyber risks. The survey indicates that while 60% of CISOs have observed an increase in third-party security incidents, only 15% report having full visibility into these risks. This lack of insight is exacerbated by limited resources and outdated technology stacks that are ill-equipped to handle the complexities of modern supply chain threats.
Key findings reveal that preparedness among organizations is alarmingly low, with 77% of CISOs identifying third-party risk as a major threat, yet only 21% have tested their crisis response plans. This gap indicates that organizations may face prolonged outages and financial losses in the event of a security breach. Additionally, 60% of respondents report rising third-party breaches, but only 41% monitor risks beyond direct suppliers, leaving significant blind spots.
The rapid adoption of AI tools has introduced new vulnerabilities, with 60% of CISOs acknowledging that unmanaged third-party AI systems pose unique risks. Despite this, only 22% have formal vetting processes in place for these tools, creating a dangerous situation where high-risk systems can access critical IT environments without adequate scrutiny.
Furthermore, dissatisfaction with compliance stacks is prevalent, as 61% of organizations have invested in Governance, Risk, and Compliance (GRC) software solutions, yet 66% find these platforms ineffective in addressing dynamic external risks. This reliance on outdated systems forces security teams to resort to manual workarounds, increasing the likelihood of missing vulnerabilities.
Static security assessments are also falling short, with 71% of CISOs admitting that traditional questionnaires do not meet their needs. However, there is a shift towards AI-driven assessment tools, with 66% of CISOs embracing these alternatives to enhance their visibility into the threat landscape.
Despite some progress, the overall picture remains concerning, as only 15% of CISOs report having full visibility into their software supply chains, up from just 3% a year ago. The survey emphasizes the need for organizations to adopt advanced, AI-driven tools to improve their security posture and better manage third-party risks.
Implications for Organizations
The findings of the 2026 CISO Survey reveal a pressing need for organizations to reassess their third-party risk management strategies. With a significant percentage of CISOs lacking visibility into their supply chains, organizations must prioritize the implementation of comprehensive monitoring systems that extend beyond direct suppliers. This includes evaluating the risks posed by unmanaged AI tools and ensuring that proper vetting processes are in place.
Organizations should also consider investing in more effective GRC solutions that can adapt to the evolving threat landscape. The dissatisfaction expressed by CISOs regarding current compliance stacks highlights the importance of selecting tools that provide real-time insights into third-party risks. By doing so, organizations can reduce their exposure to potential breaches and enhance their overall security posture.
Key Takeaways
- Assess your organization’s current visibility into third-party risks and identify gaps in monitoring.
- Implement formal vetting processes for any third-party AI tools used within your environment.
- Invest in advanced GRC solutions that can effectively manage dynamic external risks.
- Regularly test and update your crisis response plans to ensure preparedness for potential security incidents.
- Consider adopting AI-driven assessment tools to enhance your understanding of the threat landscape.
Key Terms & Concepts
- CISO: In this article, CISO refers to Chief Information Security Officer, an executive responsible for overseeing an organization’s cybersecurity strategy.
- GRC: GRC stands for Governance, Risk, and Compliance, which are frameworks that help organizations manage their overall governance, enterprise risk management, and compliance with regulations.
- Shadow AI: Shadow AI refers to the use of unmanaged artificial intelligence tools within an organization, which can create security risks if not properly vetted.
Your 5-Minute Securityish Brief
A weekly digest of cybersecurity news, phishing alerts, privacy tips, and emerging threats, simplified so anyone can understand what matters and why.
Securityish
Securityish explains cybersecurity, scams, data breaches, and privacy risks in simple language so you know what’s happening and how to protect yourself.
Navigation
Your 5-Minute Cybersecurity Brief
A weekly digest of cybersecurity news, phishing alerts, privacy tips, and emerging threats, simplified so anyone can understand what matters and why.