Third Party Risk Management Knowledge Hub

Third Party Risk Management Guides and Breach Intelligence

Practical TPRM guidance for vendor risk assessments, due diligence, regulatory compliance, continuous monitoring, and third party breach response.

Third Party Risk Analysis and Breach Alerts

Current guidance for vendor assessments, continuous monitoring, compliance, and incident response.

Put the analysis into practice

Build and verify practical third party risk knowledge with free certification paths.

Latest TPRM Insights

Third Party Risk Analysis and Breach Alerts

Current guidance for vendor assessments, continuous monitoring, compliance, and incident response.

Breach News

Instructure Canvas Data Breach May 2026: ShinyHunters Steals 275M Student Records

May 6, 2026 6 min read

In May 2026, education technology giant Instructure confirmed a major data breach affecting its Canvas platform. The ShinyHunters threat group claimed to have stolen data from 275 million students and staff across 9,000 institutions. Here's what happened and what it means for third-party risk managers.

Read More
Articles

NIS2 Third-Party Risk Management: Complete 2026 TPRM Compliance Guide

May 5, 2026 7 min read

The NIS2 Directive significantly expands third-party risk obligations for organisations across 18 sectors in the EU. This guide explains exactly what NIS2 requires from your vendor risk management programme, which sectors are in scope, and the practical steps compliance teams must take in 2026.

Read More
Breach News

Medtronic Data Breach April 2026: ShinyHunters Expose 9 Million Patient Records

May 5, 2026 6 min read

In April 2026, ShinyHunters claimed to have breached Medtronic, exposing over 9 million patient records. Medtronic confirmed the incident after an SEC disclosure, making it one of the most significant medtech data breaches of the year. Here's what happened and what risk professionals need to know.

Read More
Articles

TPRM Program Maturity Model: How to Build and Benchmark a World-Class Third-Party Risk Programme

May 4, 2026 9 min read

Most organisations know they need a third-party risk management programme — but fewer know how mature theirs actually is, or how to systematically improve it. A TPRM maturity model gives risk professionals a structured way to benchmark where they are, identify gaps, and build a roadmap to world-class vendor risk management.

Read More
Breach News

Elementary Data Data Breach April 2026: PyPI Supply Chain Attack Targets Developer Secrets

May 4, 2026 7 min read

A supply chain attack compromised the elementary-data PyPI package, pushing an infostealer to over 1.1 million monthly users. Attackers exploited GitHub Actions CI/CD pipelines to steal cloud credentials, SSH keys, and cryptocurrency wallet data. Here is what risk professionals need to know.

Read More
Articles

ISO 27001 Third-Party Risk Management: Complete 2026 Guide

May 3, 2026 9 min read

ISO 27001:2022 places explicit obligations on organisations to manage third-party and supplier risk. This guide walks risk and compliance professionals through every relevant control, how to map them to your TPRM programme, and what auditors will look for in 2026.

Read More
Breach News

Trellix Data Breach May 2026: Source Code Repository Compromised

May 3, 2026 7 min read

Cybersecurity vendor Trellix disclosed in May 2026 that attackers gained unauthorised access to part of its internal source code repository. The breach raises serious supply chain risk concerns. Here is what risk professionals need to know and act on immediately.

Read More
Articles

Vendor Risk Assessment Questionnaire: Complete Guide with 50 Key Questions 2026

May 2, 2026 9 min read

A vendor risk assessment questionnaire is the foundation of every TPRM programme. This 2026 guide covers 50 essential questions across cybersecurity, compliance, financial stability, and operational resilience — aligned to NIST, ISO 27001, DORA, and FFIEC.

Read More
Breach News

ADT Data Breach May 2026: ShinyHunters Expose 5.5 Million Customers via Vishing Attack

May 2, 2026 6 min read

ADT confirmed a data breach affecting 5.5 million customers in May 2026. The ShinyHunters group used voice phishing to compromise an employee Okta SSO account, then extracted data from Salesforce. ADT refused to pay the ransom and attackers dumped 11GB of records publicly.

Read More
Articles

Vendor Contract Security Clauses: The Complete TPRM Guide 2026

May 1, 2026 8 min read

Vendor contracts are your last line of defence in third-party risk management. This guide covers every critical security clause your organisation needs in 2026, aligned to NIST, ISO 27001, DORA, GDPR, and FFIEC.

Read More
Breach News

Vimeo Data Breach May 2026: ShinyHunters Exploit Anodot Third-Party Compromise

May 1, 2026 6 min read

Vimeo confirmed a data breach in May 2026 linked to a third-party vendor compromise at Anodot. Attackers used stolen tokens to access cloud environments, exposing user emails and video metadata. Here is what TPRM professionals must do now.

Read More
Articles

TPRM Metrics and KPIs: How to Measure Your Third-Party Risk Programme

April 30, 2026 8 min read

Most TPRM programmes fail not because of bad policies, but because nobody is measuring whether they work. This guide covers the essential KPIs and metrics every risk professional needs to prove and improve their third-party risk programme in 2026.

Read More

Put the analysis into practice

Build and verify practical third party risk knowledge with free certification paths.