This is a classic problem. In our increasingly interconnected world, organizations have been trying to assess their vendors before granting them access to sensitive data, systems, or internal business processes. The standard playbook looks something like this: send a questionnaire; collect a SOC 2 report or security certification; review the answers; assign a risk tier; and maybe follow up if internal compliance teams have time. It’s a huge drain on resources, and that process still has value, especially when vendors actually respond.
But recent incidents show why this approach is no longer enough.
In August 2026, the public has seen two very different supply chain incidents that illustrate the same fundamental problem: organizations can inherit significant risk from sources they do not directly control.
In one incident, attackers compromised LiteLLM, an AI-related software package used by major companies like Microsoft, Amazon, Salesforce, and others. They exfiltrated an enormous volume of credentials from over 2,500 organizations using this package. In another incident, sustainability-focused computer maker, Framework, notified all of its customers that attackers had accessed private customer information through its business intelligence provider, Metabase. The exposed information included names, email addresses, phone numbers, and physical addresses in a massive Personally Identifiable Information (“PII”) breach.
Neither scenario could be mitigated by asking a vendor, "Do you have a security program?" Even if there is a response, it can be difficult to trust, especially when many cyber and compliance programs involve checking boxes rather than meaningful security.
The real question that organizations need to answer is:
What can we independently observe about a vendor's risk today, and how does that risk affect our organization?
Answering that question allows for informed decision making and is where VERA can add another layer of intelligence to a traditional third-party risk management program.
The Vendor Risk Problem Has Changed
Modern organizations rarely operate within a clean security perimeter.
They rely on cloud platforms, SaaS applications, managed service providers, imported software libraries, analytics tools, payment processors, data processors, contractors, and countless other third parties. The business world is increasingly connected and for good reason. Vendors allow organizations to focus on doing what they do best.
The hidden cost of that transaction is that you cede control of your risk and security position.
At Vistrada, our research on supplier risk management proves the point directly: all suppliers introduce cybersecurity, compliance, operational, financial, and reputational exposure even when an organization's own internal controls are strong. Effective supplier risk management is a necessary part of any vendor program and requires ongoing monitoring rather than a one-time assessment.
The challenge is that traditional questionnaire assessments require long lead times and only produce a momentary snapshot. A questionnaire can only tell you what the vendor reported when the questionnaire was completed. A certification can only assert what was assessed within the scope and timeframe of that certification. They cannot tell you what has changed since then. And nothing guarantees that an organization will disclose every externally observable risk signal. Why would they? They want your business. This is why having your own research into vendor security is so important. Organizations need a way to assess vendors independently.
The Framework Incident
Framework relied on Metabase as a business intelligence provider. An attacker exploited a zero-day vulnerability at Metabase and gained access to customer databases hosted on its cloud infrastructure. Framework subsequently determined that its customers' personal information had been accessed.
The key takeaway is that Framework did not have to be directly compromised for its customers to be affected. Any organization using SaaS providers is exposed to this kind of risk. And with modern software development pushing more and more updates more and more rapidly, a single point in time assessment just is not enough.
It demonstrates why it is so important for vendor risk to be evaluated at multiple points in the relationship:
- Before onboarding
- During ongoing operations
- Before contract renewal
- When the vendor's access or data scope changes
- When a security incident occurs
- When credible external intelligence indicates that the vendor's risk profile has changed
Vistrada's vendor assessment guidance recommends reassessment after vendor incidents and when meaningful changes to data, access, hosting environments, ownership, or subcontractors occur.
A questionnaire will never be able to address this at the speed of modern development.
The LiteLLM Incident
Attackers were able to infiltrate LiteLLM’s software and upload a package designed to scrape and exfiltrate continuous integration and deployment (CI/CD) pipeline configuration data from more than 2,500 organizations using the package. This resulted in massive credential exposure across countless organizations like Microsoft, Sales force, Amazon, HP, and many others. This breach may not just affect those organizations, but if they hold your data, your organization could be at risk, too. In many cases, this means that your vendor’s vendor’s breach could be your breach.
Credential exposure, leaked secrets, exposed repositories, vulnerable internet-facing systems, breach reports, ransomware activity, and other signals emerge through publicly observable sources or external intelligence.
By the time a vendor's next annual questionnaire arrives, that information may already be available to bad actors looking to gain access to anyone they can, including your organization.
How to protect yourself with VERA
These incidents show the importance of implementing an enhanced TPRM program with VERA. In both cases, companies were compromised not because of their own practices, but because in the modern business ecosystem, everyone is connected. Vendors hold important and private data. Vendors provide services that need access to critical systems. It is more important than ever that organizations understand where they have risk and what that risk really looks like.
Vistrada’s VERA vendor risk intelligence platform is designed to address the gap between what your vendors say and what they do.
VERA does not aim to replace questionnaires, certifications, contractual requirements, audits, or other established TPRM processes. Instead, it adds an independent layer of externally observable intelligence to those workflows and gets your organization the information it needs to make informed decisions on risk mitigation.
VERA collects and verifies security and operational risk indicators without relying on vendor-provided input. This means that your organization can verify that its trusted vendors treat security the same way you would and evaluate new vendors on more than face value.
A strong TPRM program, supplemented with VERA, addresses the evolving risk landscape. VERA fills the gap between questionnaire cycles and missing responses with real, traceable evidence about your vendor’s actual risk.
Learn more about VERA or see how VERA fits into Vistrada's vendor risk assessment approach.


