I spend my days talking to clients and retail brokers about cyber risk, and the questions I'm getting have shifted. Big time.
Clients used to ask how strong their own defenses were. Now I'm getting asked about everything sitting on top of their network instead. Cloud providers, payroll companies, payment processors, suppliers, IT contractors. The vendor ecosystem has exploded, and every one of those relationships is a potential way into the client's business.
Why this risk is growing so fast
Companies have become increasingly dependent on third parties, handing them more and more core functions because it's efficient and cost-effective. But
While security standards try to keep pace with how complex these vendor relationships have gotten, many vendors still operate with weak controls. Our top cyber carriers report that third-party vendor and customer incidents average $145,000 per claim, and in 2025, vendor-related incidents accounted for 14% of all cyber claims. That's a meaningful slice of the loss activity carriers are pricing into their books, and it should carry the same weight in how clients think about their own risk.
How they're getting in
I wish we were still dealing with the theoretical, but headlines continue to provide major reality checks.
Where the policy responds, and where it doesn't
When a vendor is compromised, a cyber policy still has a few places to respond. The third-party liability section can cover lawsuits from your own customers if their data was compromised through your systems. Data breach response coverage picks up notification costs. Business interruption coverage responds to your own lost income.
The gaps I see in practice show up when a client doesn't carry dependent business interruption coverage. They may have no protection at all when the incident happens at a vendor rather than at their own business. And any sublimits or exclusions tied to supply chain events or improperly vetted vendors can quietly cut coverage right when it's needed. That's when the fine print matters most, and where I've seen brokers get caught assuming coverage that isn't actually there.
What brokers should be asking, before there's a claim
The conversation you should be having with clients starts now, because when it's after an incident, it's too late.
Ask if they use third-party vendors. Most will say yes without thinking twice about what that actually means. Then ask if they know their vendors. What's accessing their systems? Has anyone checked those vendors' security, or did procurement sign the contract and move on? There should be a contract in place requiring every vendor to carry its own cyber liability insurance and to protect the client if something happens on the vendor's end.
I'd also put the concentration risk question on the table, because it's the one that tends to land. If a given vendor goes down, how much of the client's data, revenue, or operations goes down with it? Would it cripple them? Most clients haven't sat with that question, and it's a crucial one.
The truth is the businesses I've seen take the hardest hits didn't have weak cybersecurity. They had a good program and a good team, but no real picture of what they didn't control. That's exactly where a specialty wholesale partner earns its keep, by bringing the carrier relationships and coverage expertise brokers need to give their clients real visibility into what's happening outside their walls.










