Skip to main content
Promotional banner ad for the Penetration Testing Report Kit
Vendor Audits Don't Prevent BreachesBreach Response Services
4 min readFor Underwriters & Actuaries

Vendor Audits Don't Prevent Breaches

The Conventional Wisdom

Ask any cyber insurance underwriter about third-party risk, and you'll hear the same prescription: comprehensive vendor risk assessments, security questionnaires, SOC 2 reports, and annual audits. The logic seems airtight: evaluate your vendors rigorously, and you can prevent breaches like the one at Sompo Japan Insurance Inc., where unauthorized access to a contractor's server exposed approximately 60,000 personal records containing names, addresses, phone numbers, and employment information.

This approach treats vendor risk management as a due diligence problem. Complete the assessment checklist, review the attestation reports, and verify the security controls. If your vendor passes the audit, you're protected.

The Flaws in the Approach

Here's what this framework misses: vendor audits measure security posture at a point in time. They don't predict operational execution or account for configuration drift. They certainly don't tell you whether the contractor's night-shift administrator will patch a critical vulnerability before an attacker finds it.

Sompo Japan's breach didn't happen because they failed to assess their contractor. It happened because assessment frameworks can't bridge the gap between documented controls and daily security operations. You can verify that a vendor has incident response procedures, but you can't verify they'll execute them correctly under pressure.

The real issue isn't whether to conduct vendor assessments. It's that underwriters and risk managers treat a passing audit as a transferable warranty of security. It isn't. It's a snapshot of control maturity that becomes outdated the moment the auditor leaves.

The Evidence

Look at what the Sompo Japan incident reveals. The breach occurred at a contractor handling customer inquiries, a function requiring access to Nonpublic Information but not typically involving high-risk data processing. This is the type of vendor relationship where organizations rely on annual assessments rather than continuous monitoring.

The exposed data included employment information, suggesting the contractor maintained more extensive records than necessary for inquiry handling. That's a data minimization failure that no security questionnaire would catch unless you specifically audit data retention practices at the operational level.

Consider the timing asymmetry: security assessments happen annually or at contract initiation. Breaches happen when an attacker finds an exploitable gap, which could be six months after your last audit. The contractor's security controls might have been adequate when you reviewed them. They might have degraded since. You won't know until you receive breach notification.

This isn't theoretical. Review breach disclosures involving third-party vendors, and you'll see the pattern: the vendor had security controls, often documented in SOC 2 reports or ISO certifications. The breach happened anyway because controls documented in an audit framework don't guarantee operational resilience.

What to Do Instead

Replace periodic vendor assessments with continuous risk indicators. Instead of asking whether your contractor has an incident response plan, monitor whether they're executing basic hygiene: patch cadence, authentication failures, and certificate expiration tracking. These operational metrics tell you more about breach likelihood than any control framework attestation.

Structure your vendor contracts around breach response obligations, not security certifications. Specify notification timelines, define data access logging requirements, and require participation in tabletop exercises. These provisions create accountability for execution, not just documentation.

For high-risk vendor relationships, negotiate direct access to security telemetry. If a contractor processes sensitive client data, you should see failed authentication attempts, privilege escalation events, and data transfer volumes in near real-time. This isn't about micromanaging your vendor's security team. It's about detecting operational drift before it becomes a breach.

Implement data minimization as a contract requirement. The Sompo Japan contractor apparently retained employment information for customer inquiry functions. Ask yourself: does this vendor need that data to perform their contracted service? If not, contractually prohibit it. You can't breach data you never transferred.

Underwriters should adjust Pre-Bind Requirements to reflect this operational focus. Instead of requiring evidence of vendor SOC 2 reports, require evidence of continuous monitoring capabilities. Ask applicants how they detect vendor security drift, not how they assess vendor security posture. The distinction matters.

When the Conventional Wisdom Is Right

Vendor risk assessments still serve a critical function: they establish baseline expectations. Before you can monitor operational execution, you need to know what controls your vendor claims to maintain. The assessment creates that documented baseline.

For low-risk vendor relationships, periodic assessments remain sufficient. If you're working with a contractor who handles only public information or provides services that don't touch your data environment, annual questionnaires and SOC 2 reviews provide adequate assurance without imposing unreasonable monitoring overhead.

Initial vendor selection absolutely requires comprehensive assessment. You need to verify that a prospective contractor has basic security maturity before you transfer any data. The problem isn't conducting assessments. It's treating them as ongoing assurance mechanisms rather than point-in-time evaluations.

When you're underwriting cyber risk, vendor assessment evidence still matters. An organization that can't demonstrate basic vendor due diligence represents higher loss exposure. But distinguish between applicants who check compliance boxes and applicants who've built operational vendor risk management. The latter group detects problems like the Sompo Japan breach faster, contains them more effectively, and ultimately generates fewer claims.

The Sompo Japan incident doesn't invalidate vendor risk assessment. It exposes the gap between documented controls and operational security. Close that gap with continuous monitoring, contractual breach response obligations, and data minimization requirements. Save the annual audit for establishing baselines, not providing ongoing assurance.

Promotional banner highlighting failures found in PCI audits and how to spot the gaps

You Might Also Like