By Beverly Najarian, Senior Risk Analyst
In November 2025, several major U.S. financial institutions faced a significant supply chain risk when SitusAMC, a key mortgage services vendor, disclosed a breach that may have compromised customer data. This incident was more than a vendor issue — it was a sector-wide stress test that revealed how dependent financial institutions have become on third-party ecosystems and how difficult they are to govern effectively.
Third-party risk remains one of the most persistent and challenging categories of cyber risk, especially in data-intensive environments. Here’s what the breach revealed and what CISOs can do now.
What the Breach Revealed
1. Overextended Vendor Access
SitusAMC processed large volumes of borrower and servicing data for multiple institutions, showing how vendors often hold more sensitive data than business units realize. With limited visibility into where that data resides or how it is protected, organizations face risks they cannot fully quantify. Attackers bypassed traditional malware deployment and exploited unsecured gateways and weak network parameters to exfiltrate sensitive data. This demonstrates that even when controls exist, determined adversaries can still find pathways to compromise vendor environments.
2. Insufficient Monitoring Cadence
Many organizations still rely on annual Due Diligence Questionnaires (DDQs), ad hoc reviews, and trust-based responses. Meanwhile, vendor environments shift constantly due to patching lapses, IAM drift, expired certificates, and unmonitored accounts.
Without continuous, risk-based monitoring, these changes go undetected and create silent exposure.
The SitusAMC breach highlights why proactive measures such as independent penetration testing and red team exercises are essential.
3. Weak IAM Hygiene
Identity and access management failures remain the most common vector in supply chain breaches. Recent incidents consistently involve gaps such as lack of multi-factor authentication (MFA), shared accounts, non-expiring credentials, over-permissioned roles, and insufficient logging.
CISOs should also consider advanced architectural controls such as micro-segmentation to limit lateral movement and egress monitoring to detect and block unauthorized data transfers.
4. Inconsistent Vendor Incident Response
CISOs often learn about vendor incidents only after internal investigations, with unclear timelines and limited forensic visibility. This slows containment and complicates regulatory notifications under frameworks such as GDPR, OCC, NYDFS, and SEC.
The inconsistency of vendor incident response maturity remains a critical weakness across the sector, underscoring the need for vendor-specific playbooks and faster escalation protocols
What CISOs Can Do Now
1. Adopt Tiered, Continuous Monitoring
Shift from annual reviews to a risk-based cadence. High-risk vendors require monthly or quarterly evidence supported by real artifacts such as MFA enforcement, IAM logs, patching proof, and backup test results. Annual questionnaires alone no longer meet the moment.
2. Strengthen Identity Governance Across Vendor Access
Mandatory MFA, just-in-time access, service account rotation, OAuth key lifecycle management, IAM drift detection, and 90-day account certification should be standard expectations for all vendor connections.
Strong identity governance, combined with micro-segmentation and egress monitoring, provides layered defense against modern attack techniques.
3. Demand Transparency into Vendor Data Handling
Security teams must know what data is shared, how long it is retained, where it is stored, who can access it, how it is encrypted, and what logs exist. This clarity reduces regulatory exposure and accelerates incident response when breaches occur.
4. Build Vendor-Specific Incident Response Playbooks
Generic incident response (IR) plans are not enough. CISOs need vendor-focused playbooks with communication matrices, notification decision trees, escalation triggers, and data mapping — supported by a four-to-six-hour internal SLA for vendor breach response. Time loss directly increases risk.
5. Strengthen Contractual Safeguards
Contracts must explicitly require MFA and IAM standards, log retention minimums, right-to-audit clauses, 72-hour breach notification, encryption requirements, and architecture diagrams. If it is not in writing, it is not enforceable.
How Arcova Can Help
Arcova enables organizations to strengthen vendor risk through comprehensive third-party risk management (TPRM) operations, NIST CSF 2.0 alignment, in-depth assessments, vendor incident response readiness, and board-level reporting that translates technical risk into business impact.
The SitusAMC breach is a reminder that supply chain cyber risk is a strategic business issue — not just a compliance checkbox. Your perimeter is no longer the boundary — your vendors are.
Ready to transform your vendor risk strategy from reactive to resilient?
Explore how we help organizations secure their extended perimeter, modernize third-party risk management, and build a foundation for long-term security and trust.
