Third Party Risk Management Knowledge Hub

Third Party Risk Management Guides and Breach Intelligence

Practical TPRM guidance for vendor risk assessments, due diligence, regulatory compliance, continuous monitoring, and third party breach response.

Third Party Risk Analysis and Breach Alerts

Current guidance for vendor assessments, continuous monitoring, compliance, and incident response.

Articles

AI Vendor Risk Management: Complete TPRM Guide 2026

April 26, 2026 8 min read

As organisations adopt AI tools from third-party vendors, the risks are unlike anything traditional TPRM frameworks were built to handle. This guide covers how to assess AI vendors, what unique risks they introduce, and the frameworks that help risk professionals manage them in 2026.

Read More
Breach News

Rituals Data Breach April 2026: Membership Database Exposed

April 26, 2026 6 min read

Cosmetics giant Rituals confirmed in April 2026 that attackers accessed its customer membership database, exposing personal data including names, addresses, and dates of birth. The breach affects millions of loyalty program members across Europe and beyond, with the Dutch data protection authority now involved.

Read More

Put the analysis into practice

Build and verify practical third party risk knowledge with free certification paths.

Latest TPRM Insights

Third Party Risk Analysis and Breach Alerts

Current guidance for vendor assessments, continuous monitoring, compliance, and incident response.

Breach News

Universal Pure Data Breach April 2026: Names and Social Security Numbers Exposed

April 30, 2026 6 min read

In April 2026, Universal Pure disclosed a breach that exposed names and Social Security numbers of affected individuals. The intrusion occurred in mid-2024 but took nearly two years to reach public notification. Here's what risk professionals need to know.

Read More
Articles

Third-Party Vendor Incident Response Plan: Complete Guide 2026

April 29, 2026 7 min read

When a vendor is compromised, every minute without a plan costs you more. This complete guide shows TPRM professionals how to build, test, and activate a third-party vendor incident response plan that meets NIST, ISO 27001, DORA, and FFIEC requirements.

Read More
Breach News

LPL Financial Holdings Data Breach April 2026: Phishing Malware Hits Financial Advisors

April 29, 2026 5 min read

In April 2026, LPL Financial Holdings disclosed a breach affecting 1,581 customers. Phishing-delivered malware compromised affiliated financial advisor devices, enabling unauthorized securities transactions and fund transfers. Here is what risk managers need to know.

Read More
Breach News

France ANTS Data Breach April 2026: IDOR Flaw Exposes 19 Million Citizen Records

April 27, 2026 6 min read

France's national ID agency ANTS suffered a major cyberattack in April 2026, exposing up to 19 million citizens' passport and identity records. An IDOR vulnerability in their public API allowed attackers to harvest records at scale with no sophisticated tools required.

Read More
Articles

Vendor Offboarding Checklist 2026: TPRM Best Practices for Secure Termination

April 27, 2026 9 min read

Vendor offboarding is the most neglected phase of the TPRM lifecycle — and one of the riskiest. This complete 2026 guide covers all six phases of secure vendor termination, including access revocation, data destruction, regulatory obligations under GDPR and DORA, and a 15-point offboarding checklist.

Read More
Articles

AI Vendor Risk Management: Complete TPRM Guide 2026

April 26, 2026 8 min read

As organisations adopt AI tools from third-party vendors, the risks are unlike anything traditional TPRM frameworks were built to handle. This guide covers how to assess AI vendors, what unique risks they introduce, and the frameworks that help risk professionals manage them in 2026.

Read More
Breach News

Rituals Data Breach April 2026: Membership Database Exposed

April 26, 2026 6 min read

Cosmetics giant Rituals confirmed in April 2026 that attackers accessed its customer membership database, exposing personal data including names, addresses, and dates of birth. The breach affects millions of loyalty program members across Europe and beyond, with the Dutch data protection authority now involved.

Read More
Articles

Cybersecurity Vendor Due Diligence: The Complete 2026 TPRM Checklist

April 25, 2026 1 min read

Most vendor assessments miss the questions that matter. Here's the definitive cybersecurity vendor due diligence checklist for TPRM professionals in 2026 — built to expose real risk, not just tick boxes.

Read More
Breach News

Vercel Data Breach 2026: ShinyHunters Steals API Keys via Third-Party AI Tool

April 25, 2026 1 min read

In April 2026, Vercel suffered a high-severity breach when ShinyHunters exploited a compromised third-party AI tool to steal API keys, tokens, and internal employee data. Here's what happened, how it happened, and what it means for third-party risk managers.

Read More
Articles

Supply Chain Attack Prevention: Complete TPRM Guide 2026

March 28, 2026 9 min read

Complete guide to supply chain attack prevention in TPRM covering software integrity, vendor security assessment, threat intelligence, and supply chain resilience strategies.

Read More
Articles

Zero Trust and Third-Party Access: Complete TPRM Guide 2026

March 28, 2026 9 min read

Complete guide to Zero Trust and third-party access management covering ZTNA, vendor identity verification, least privilege, microsegmentation, and continuous access monitoring.

Read More
Articles

Ransomware and Third-Party Risk: Complete TPRM Guide 2026

March 28, 2026 9 min read

Complete guide to ransomware and third-party risk covering vendor assessment, supply chain ransomware prevention, lateral movement controls, and incident response planning.

Read More

Put the analysis into practice

Build and verify practical third party risk knowledge with free certification paths.