Back to overview

An A Rating Will Not Tell You a Vendor Is Being Targeted

iCOUNTER

August 13, 2026

Cyber Risk Intelligence Blog | iCOUNTER
Share
Copy to Clipboard

Posture scoring and questionnaires measure vendor hygiene. Compromise intelligence answers a different question: is this vendor being targeted right now?

Picture a Tier 1 SaaS vendor. Payroll, CRM, or identity. They hold an A rating on every major security rating platform. Their SOC 2 Type II is current. Their most recent questionnaire response was thorough and came back on time.

At that same moment, a ransomware affiliate is running credential-stuffing against their externally exposed admin console, using credentials leaked in an unrelated breach.

The security rating sees none of this. The questionnaire captures none of this. An enterprise relying on those two tools has no visibility into a targeting event that will, within days, become a vendor compromise. Shortly after that, it becomes an enterprise incident.

Nothing in that scenario is a failure of execution. The vendor did what was asked. The rating platform scored what it was built to score. The questionnaire captured what it was designed to capture. Everything worked as intended and still missed the thing that mattered.

That is an architectural problem, not a process problem.

The scenario is composite. The pattern is not.

Change Healthcare, in February 2024, originated through a third-party access vector. UnitedHealth later disclosed total incident costs exceeding $2.9 billion. The Snowflake customer-tenant campaign of the same year propagated through compromised credentials to reach Ticketmaster, AT&T, and Santander. The MOVEit and Cl0p supply-chain attack was still generating downstream disclosures eighteen months after initial exploitation.

In each case, the breached organization's own posture scores were irrelevant. The exposure lived in the vendor relationship.

Two different questions

Posture scoring answers one question: does this vendor have good security hygiene?

Compromise detection answers another: is this vendor being actively targeted by an adversary right now?

Both questions matter. They are not interchangeable, and most third-party risk programs can only answer the first.

The distinction gets lost because the two feel like they should correlate. Good hygiene ought to mean lower risk, and often it does. But a vendor with mediocre posture scores may face no active targeting at all, while a vendor with immaculate posture can be compromised through a zero-day, a supply chain attack on their own software provider, or a credential exposure they have not detected yet.

A program that relies only on posture is managing probability without measuring intent. AI has compressed adversary timelines. Intent now moves faster than hygiene assessments can track.

Why the assessment layer cannot close this

Questionnaires capture what vendors say about their controls, not what they do. They are self-reported and point-in-time. Between assessments, staff turn over, configurations drift, certifications expire, and environments get compromised. The document stays accurate to the day it was signed and to nothing after it.

John Watters acquired iDEFENSE in 2002, founded iSIGHT Partners in 2007, and served as President and COO of Mandiant through the FireEye divestiture and the Google acquisition. He describes the gap this way:

"Every CISO I talk to manages vendor risk with tools that were built for a different decade: annual questionnaires, static posture scores, and compliance programs that tell you whether controls exist, not whether a critical vendor is actively being targeted."

John Watters, Chairman and CEO, iCOUNTER


That is not an outside critique. It is a description of the category he spent two decades building, from someone who now argues the assessment layer alone cannot hold.

What compromise intelligence is

Compromise intelligence is the detection of adversary activity directed at the vendors, suppliers, and partners inside your ecosystem, determined in real time and routed to whoever owns the response.

It is a detection layer. The TPRM stack has never had one.

It is not threat intelligence, attack surface management, or security ratings, though it sits adjacent to all three. Threat intelligence reports on adversary activity in the world. Attack surface management maps your own externally visible infrastructure. Security ratings score vendor hygiene.

None of them answers the operative question: is this specific vendor in my ecosystem being actively targeted, right now, by an adversary whose behavior intersects with my business?

What that looks like in practice

The mechanism matters less than the sequence.

A signal appears somewhere in the collection layer. Adversary infrastructure staging a campaign, compromise activity, an exposed credential set, chatter on a source your team does not monitor.

That signal is then tested against a live model of your extended enterprise: which vendors you actually depend on, what they connect to, what data moves between you. Most signals fail that test and stop there. That is the point of it.

The ones that survive name a specific vendor, arrive with the evidence behind them and a recommended action, and go to whoever owns the response.

The determination happens at the edge of collection, before anything reaches an analyst queue. That is what separates a detection layer from another feed.

What it does not replace

Posture data remains valuable. Questionnaires still inform governance and still satisfy regulators. Security ratings still give procurement a defensible baseline.

None of that goes away. The existing stack was built to measure hygiene, and hygiene measurement cannot detect targeting. Adding a detection layer does not invalidate the investment already made. It covers the gap that investment was never designed to reach.

Without that layer, a program is managing risk on assumptions rather than evidence.

The question worth asking

If a vendor in your ecosystem were being targeted this week, how would you find out?

For most programs the honest answer is the vendor's own disclosure email, which arrives after the compromise and often weeks after it mattered. That gap is architectural, and it is the one thing a questionnaire can never fix.

We run a complimentary Ecosystem Threat Briefing on what is currently visible across your third-party environment, including which vendors show signs of active targeting. It is a working session, not a presentation.

Learn more at: https://icounter.com/request-ecosystem-threat-briefing

We run a complimentary Ecosystem Threat Briefing on what is currently visible across your third-party environment, including which vendors show signs of active targeting. It is a working session, not a presentation.

Request an Ecosystem Threat Briefing