Skip to main content

Cybersecurity statistics / Vendor Risk

Among the 140 vendors whose client base is meaningfully concentrated in finance, critical vulnerabilities increased 181%.

PublisherBlack Kite
Report2026 State of Financial Services: The Dual Storm of Ransomware and Vendor Ecosystem Risk
Published3 June 2026
TopicsVendor Risk, Vulnerabilities, Financial Services

Published by Black Kite in 2026 State of Financial Services: The Dual Storm of Ransomware and Vendor Ecosystem Risk, 3 June 2026. The figure is taken from the report as published; the full methodology is in the source.

View the original report

Related statistics

70% of healthcare leaders are confident in their vendors' cybersecurity posture.
Omega Systems, 28/06/2026
85% of healthcare practices experienced at least one operational disruption caused by a third-party or vendor-of-a-vendor failure in the past 12 months.
Omega Systems, 28/06/2026
54% of the 140 vendors whose client base is meaningfully concentrated in finance carry at least one vulnerability listed in CISA's Known Exploited Vulnerabilities (KEV) catalog.
Black Kite, 06/06/2026
From 2024 to 2025, the number of critical vulnerabilities carried across vendors serving the financial sector increased 387%.
Black Kite, 06/06/2026
Vendor-related cybersecurity incidents among schools districts rose from 4% in 2023 to 32% in 2025.
Clever, 27/05/2026
Where IT/OT alignment weakens in organizations in manufacturing and critical infrastructure sectors, vendor-related incident exposure nearly triples.
Secomea, 27/05/2026

Get the newsletter

Weekly cybersecurity statistics by email.