惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

雷峰网
雷峰网
MongoDB | Blog
MongoDB | Blog
D
Docker
Martin Fowler
Martin Fowler
人人都是产品经理
人人都是产品经理
GbyAI
GbyAI
Jina AI
Jina AI
酷 壳 – CoolShell
酷 壳 – CoolShell
M
MIT News - Artificial intelligence
腾讯CDC
阮一峰的网络日志
阮一峰的网络日志
H
Hackread – Cybersecurity News, Data Breaches, AI and More
N
Netflix TechBlog - Medium
B
Blog RSS Feed
云风的 BLOG
云风的 BLOG
Blog — PlanetScale
Blog — PlanetScale
Vercel News
Vercel News
The Cloudflare Blog
freeCodeCamp Programming Tutorials: Python, JavaScript, Git & More
有赞技术团队
有赞技术团队
G
Google Developers Blog
Stack Overflow Blog
Stack Overflow Blog
I
InfoQ
U
Unit 42

Forbes - Innovation

Why Do Humans Have Fingerprints? Hint: It’s Not What You Think Booking.com Confirms Data Breach, Reservation PIN Codes Changed Why Major News Sites Are Blocking The Internet Archive’s Wayback Machine iPhone Fold Release Date: New Report Details Frustrating Apple News Comet Tracker: How To See Pan-STARRS And Three Planets On Wednesday NYT Mini Crossword Today: Tuesday, April 14 Hints And Answers Today’s NYT Strands Hints, Spangram, Answers: Tuesday, April 14 (It’s A Little Unclear) Today’s Wordle #1760 Hints And Answer For Tuesday, April 14 Most Of The Microplastics In Urban Air Come From Tires Today’s Wordle #1759 Hints And Answer For Monday, April 13 NYT Mini Crossword Today: Monday, April 13 Hints And Answers NYT Pips Today: Hints, Answers And Walkthrough For Monday, April 13 The YC Chief Who Codes 10,000 Lines A Day Has A Simple Secret Samsung Expands One UI 8.5 Beta To More Galaxy Owners Why You Should Stop Using Your iPhone If It’s On This List Chamath Says Firms That Treat AI As A Strategy Hand Rivals Their Edge 3 Unexpected Habits Of Secure Couples, By A Psychologist The First Lamp That Folds Your Clothes Samsung’s Disappointing Price Update For Galaxy Phone Buyers 3 Subtle Signs Someone Is Falling In Love With You, By A Psychologist Do Mantis Shrimp See More Colors Than Humans? A Biologist Explains NYT Connections Answers Explained For Monday, April 13 (#1,037) NYT Connections Hints Today: Monday, April 13 Clues And Answers (#1,037) LEGO Luigi & Mach 8 (72050) Review: 2026’s Best Set Yet? Marc Andreessen Says AI Productivity Will Trigger A Hiring Boom 3D Printing Is The Ultimate Hack To Reduce Household Spending Apple iPhone Fold: Striking Design Revealed In Leaked Photos Apple Smart Glasses: New Leak Reveals A Major Design Twist To Beat Meta Tested: The AI Coming To The Rivian R2 Quordle Hints Today: Monday, April 13 Clues And Answers
The Cybersecurity Gap No One Owns: You’re Securing The Wr...
Prajkta Wadi · 2026-05-08 · via Forbes - Innovation

Prajkta Waditwar, senior technology sourcing Manager at Box, focused on AI strategy, vendor ecosystems and procurement innovation.

getty

Cybersecurity spending is approaching $240 billion globally, according to Gartner, yet breach costs are nearing $5 million per incident based on IBM’s latest data. If investment is rising and tooling is improving, the obvious question is: Why aren’t outcomes?

From where I sit, working across technology sourcing and vendor strategy, the issue isn’t effort. It’s that most organizations are still securing a perimeter that no longer exists.

The enterprise boundary has dissolved. What remains is a constantly shifting network of vendors—cloud providers, SaaS platforms, data processors and AI systems embedded directly into how work gets done. IBM reports that supply chain attacks have surged significantly in recent years, reflecting how deeply vendor dependencies now shape enterprise risk.

And yet most security strategies still start inside the organization.

Where Risk Actually Gets Decided

Cybersecurity typically shows up after the fact—after a system is deployed, after a vendor is onboarded, after data is already flowing.

But risk doesn’t start there. It starts much earlier, in decisions that don’t get labeled as security decisions at all. It’s in the moment a team selects a vendor to move faster. It’s in how much access that the vendor is given. It’s in how deeply that tool gets integrated into critical workflows.

I’ve seen this pattern play out repeatedly across organizations—what starts as a controlled vendor decision quietly turns into a critical dependency. A vendor is introduced for a narrow use case—limited scope, controlled access. Over time, it expands. It connects to additional systems, handles more sensitive data and becomes embedded in operations. No single step feels risky. But the accumulation is. By the time anyone pauses to reassess, the organization is no longer choosing that vendor—it’s depending on it.

The Myth That Vendor Risk Stays At The Edge

There’s still a tendency to think of third-party risk as something that can be contained at the boundary. That boundary doesn’t really exist anymore.

Vendors don’t stay external. They become operational. They sit inside workflows, handle core data and often have privileges that mirror internal systems. SecurityScorecard has found that nearly all organizations are connected to third parties that have already experienced a breach. That’s not an outlier—it’s the baseline.

What’s changed is not just the number of vendors but the depth of integration. When something breaks, it doesn’t show up as a vendor issue. It shows up as a business problem (downtime, data exposure, customer impact, etc.). And at that point, the organization has very little leverage to quickly reduce that dependency.

That’s where most teams realize the problem too late.

In practice, I’ve rarely seen these dependencies unwind easily once they reach that level of integration.​

The Function That Sees It First—And Gets Used Last

One of the most underutilized control points in cybersecurity today is procurement. It’s still treated as a transactional function that's focused on cost and contracts. In reality, it has one of the clearest views into how external dependencies are introduced and expanded across the business.

Procurement sees patterns early—how vendors are being adopted across teams, how contracts are structured and how access evolves over time. When it’s involved early, the conversation changes. It’s no longer just “Does this tool meet requirements?” It becomes “What happens if this becomes critical?” and “How easily can we exit this relationship?”

Those questions tend to surface later, when the answers are far more constrained.

There’s also a structural issue that doesn’t get enough attention: enforceability. Many organizations still report gaps in third-party risk management tied to weak or unclear contractual controls, as highlighted in Deloitte’s research. I’ve seen situations where risks were well understood internally, but the organization lacked the contractual leverage to act decisively.

At that point, awareness isn’t the problem. Control is.​

Speed Isn’t The Problem—Structure Is

It’s easy to blame speed, especially with how quickly AI tools are being adopted across organizations. But speed isn’t what’s breaking most environments. Lack of structure is.

In organizations with clear guardrails—standard vendor requirements, defined access models and consistent evaluation paths—teams move faster because they don’t have to renegotiate risk every time. Where things break down is when adoption is fast and unstructured. Tools get introduced outside formal processes. Data flows aren’t fully understood. Integrations stack on top of each other.

Most modern exposures stem from misconfigurations and unmanaged assets, many of which are introduced through third-party integrations, according to Palo Alto Networks. AI is accelerating this pattern by making it easier to adopt tools that process and move sensitive data without full visibility up front.

By the time these dependencies are discovered, they’re already embedded. At that point, you’re not governing risk—you’re working around it.

In my experience, this is where most organizations lose visibility—when adoption outpaces structure.​

Moving The Starting Point Of Cybersecurity

The organizations that are getting ahead of this aren’t necessarily the ones with the most tools or the largest budgets. They’re the ones that have shifted where cybersecurity begins.

They’ve moved the cybersecurity upstream—closer to the decisions that introduce risk in the first place. They’ve aligned vendor adoption with ​governance, instead of treating them as separate tracks that meet too late.

​​​In my experience, getting closer to those decisions starts with shifting from a reactive review role to an embedded one. Cybersecurity leaders should be involved earlier in vendor selection, architecture discussions and even budget approvals—not just final sign-offs. That means partnering closely with procurement and business teams, setting clear baseline requirements up front and making security part of how decisions are made, not something applied after. The goal isn’t to slow things down but to shape choices while they’re still flexible—when risk can actually be designed out, not just managed later.

Because cybersecurity doesn’t begin with a threat. It begins with a decision. And if your security strategy starts after a vendor is already embedded in your operations, you’re not managing risk—you’re inheriting it.


Forbes Technology Council is an invitation-only community for world-class CIOs, CTOs and technology executives. Do I qualify?