Opens in a new tab
vmblog logo 2024 wht (updated)

Third-Party Breaches Double to 30%: DigiCert's VP Reveals Critical Supply Chain Security Blind Spots – VMblog QA

Share: 

David Marshall | Published: June 27, 2025

As third-party breaches surge from 15% to 30% of all security incidents, organizations are waking up to a sobering reality: their biggest security vulnerabilities may not be lurking within their own walls, but hidden in the complex web of vendors, partners, and digital services they depend on daily.

In an era where digital perimeters have effectively dissolved, replaced by distributed attack surfaces spanning global partnerships, the traditional approach to cybersecurity is proving inadequate. Mike Nelson, VP of Digital Trust at DigiCert, sees this challenge firsthand and warns that the most dangerous mistake companies make isn’t having weak security, but simply not knowing what security their third-party vendors have at all.

In this VMblog Q&A, Nelson reveals the critical blind spots that leave organizations vulnerable, shares practical strategies for building proactive supply chain security programs, and explains why digital trust has become the new “wall of the hospital” in our interconnected business landscape. From software bills of materials (SBOMs) to certificate lifecycle management, discover the essential practices that separate security-conscious organizations from those heading toward their next breach notification.

++

VMblog:  A lot of companies talk about being “proactive” with supply chain security – but what does that really look like in practice? Where should organizations start?

Mike Nelson:  What does it look like in real practice?

  • Know what is in your supply chain and tier your vendors by risk. (Software providers, cloud services, contractors). Classify vendors based on their access to sensitive data, systems, or operational impact (e.g., high, medium, low risk).
  • Perform risk-based security assessments for your high-risk vendors. Leverage and utilize security questionnaires that were developed by NIST and other institutions and make sure to always request security certifications and reports (e.g., SOC 2, ISO 27001).
  • Include cybersecurity requirements in contracts. You should have security controls expectations for multifactor authentication (MFA), encryption and patching of systems. You should require your vendors to agree to notification timelines when a breach or compromise occurs.
  • Once you have done these things, it’s important to continuously monitor and reassess the security capabilities of your vendors to make sure you maintain your security posture.

VMblog:  As businesses rely more on global partners and services, their attack surface keeps growing. How should they be thinking about digital trust in that context?

Nelson:  As organizations increasingly rely on global partners, their digital perimeter effectively dissolves and is replaced by a complex, distributed attack surface. In this context, digital trust must be built in from the beginning and not treated as an afterthought. That means integrating cybersecurity requirements into procurement processes, thoroughly assessing the risks posed by partners and services, and prioritizing strong identity authentication for users and digital systems alike. All data must be securely encrypted, both at rest and in transit. In a perimeterless environment, digital trust becomes the new “wall of the hospital” and is essential for maintaining operations and protecting sensitive data, particularly in industries like healthcare where patient safety is on the line.

VMblog:  What are some of the most common mistakes you see companies make when it comes to managing third-party risk? And how can they get it right?

Nelson:  The biggest and most common mistake we see organizations make is simply not evaluating third party vendors from a cybersecurity perspective. They remain in the dark regarding the security posture of the products they are bringing into their environment. They may not have a clear understanding of their own security postures and may not be taking advantage of the powerful tools already available to them. Companies ultimately get it right by standardizing their questions around basic cybersecurity hygiene, essentially asking these questions: Do they have strong identity management? Are they encrypting sensitive data? Are their systems updated frequently? Beyond user passwords, this extends to validating digital system identities and monitoring certificate lifecycles. For example, an expiring digital certificate on a third-party system can be a major security liability, so knowing when and how they manage these is crucial.

VMblog:  How is DigiCert helping enterprises gain better visibility and control over their software supply chains-particularly with regard to certificate management, SBOMs, and secure software development?

Nelson:  DigiCert enables organizations to protect the integrity of software packages by offering a strong solution that enforces good signing practices for the entire organization. We put controls around key protection and rotation, signing rights management, and time stamping. In addition, DigiCert provides tools that allow them to generate software bills of materials (SBOMs) that can be used to communicate with customers about the security, or lack of security of their software package. Crucially, we facilitate the generation and utilization of SBOMs, allowing businesses to understand the precise components within all software they use or produce, including third-party elements. This level of transparency is ultimately mandated by governments, like the FDA for medical devices, helping organizations proactively identify and mitigate vulnerabilities before they become exploitable by adversaries.

VMblog:  Many organizations have an in-house software development group and an IT group that buys products for employees to use. These have different supply chain risks, but do they need to be managed separately?

Nelson:  While in-house software development and external product procurement present distinct and glaring supply chain risks, they should use the same requirements or procurement guidelines. While they could operate separately, the business should have zero tolerance for procuring software or products that have significant security vulnerabilities. Embracing a unified procurement strategy across the company with strong security requirements ensures consistent controls.

VMblog:  Given that third-party breaches doubled from 15% to 30% of all incidents last year, what specific red flags or warning signs should companies watch for that might indicate a supply chain partner is becoming a security liability?

Nelson:  Given the alarming rise in these third-party breaches, companies must be hyper-vigilant and be aware of several red flags. A major warning sign is the lack of transparency from a partner regarding their security practices, the use of digital certificates or the components of their software. Other warning signs include a reluctance to discuss their patching frequency, a lack of strong multi-factor authentication for their digital systems or an inability to clearly articulate how they encrypt sensitive data, especially in transit. Essentially, if a partner isn’t openly communicating about their security hygiene or appears to treat it as a “bolt-on” rather than foundational, they are likely becoming a security liability. In addition, cybersecurity vulnerabilities are communicated through various channels, including public disclosure platforms like CISA’s website and CVE (Common Vulnerabilities and Exposures), as well as through vendor advisories, security blogs, and community forums. Organizations need to monitor these lists thoroughly.

VMblog:  As regulations around software supply chain security continue to evolve globally, how should companies balance compliance requirements with actual security effectiveness – especially when they’re operating across multiple jurisdictions?

Nelson:  Many times, regulations are high level and encourage certain security approaches, but don’t get overly prescriptive in how to implement them. Without the prescriptive guidance, organizations can take short cuts and still end up vulnerable to attacks. For example, you can implement code signing, but use one key to sign all files, or fail to adequately protect the private key, leaving you at risk if that key is compromised. When implementing security protections, it’s important to follow best practices and work with partners that can ensure you’re implementing security in a way that will scale and maintain a strong security posture.

##