Green questionnaires, live exposure: why TPRM owners still get surprised after a KEV week

Green questionnaires, live exposure: why TPRM owners still get surprised after a KEV week

The questionnaire came back green. The attestation was current. The vendor sat in the “acceptable risk” column.

Then a KEV week hit — and someone asked the only question that mattered: which of our third parties actually run this?

That gap is the pain. Not a missing PDF. Not a late follow-up email. The false calm of a completed assessment while the live attack surface of your supply chain moved without you.

The questionnaire was never the whole job

Most third-party risk programs were built for a world where the hard part was collecting answers. Security, legal, and procurement learned to run intake, score evidence, and close tickets. That work still matters. It does not tell you whether a critical dependency is exposed today.

A Known Exploited Vulnerability catalog entry does not care that last quarter’s SOC 2 was clean. It cares whether a product class in your ecosystem is reachable, unpatched, and already being probed. Questionnaire completeness and live exposure are different jobs. When programs treat them as the same job, teams get surprised in public — after the fact, after the board question, after the incident bridge call.

What a KEV week exposes about third-party dependency

In a KEV week the useful work is operational, not theatrical:

  1. Inventory the class of technology, not just the brand names on your preferred-vendor list. Middleware, API gateways, managed service stacks, and “we use their cloud” relationships often sit outside the mental model of who counts as a vendor.
  2. Separate claims from evidence. A questionnaire answer about patch cadence is not the same as confirmation of version and update level for the component that is under active exploitation.
  3. Ask the supply-chain questions out loud. Do our MSPs or SaaS providers run this for us? Was the management plane internet-reachable during the exploitation window? What forensic and credential-rotation work happened if it was?

Those are TPRM owner questions. They are also supply-chain security questions. The teams that answer them fastest are rarely the ones with the thickest questionnaire archive — they are the ones who can see which third parties matter for this exposure, right now.

For technical depth on specific actively exploited issues, see Rescana’s Security Watchtower advisories — for example Adobe Commerce / Magento incorrect authorization (CVE-2026-71362) and WSO2 API Manager JWT authentication bypass (CVE-2026-5430). This piece is about the program pain those advisories keep revealing.

Security and legal feel the same gap differently

Security feels it as coverage: we assessed the vendor; we did not continuously see the surface that failed.

Legal feels it as defensibility: we can show process; we struggle to show timely, evidence-backed decisions when the board asks what changed this week.

Procurement feels it as friction: business units still need the vendor live while security and legal argue about what “remediated” means without live signal.

None of that is fixed by another static form. It is fixed by treating continuous exposure awareness as part of the vendor risk job — alongside assessment, not instead of it.

What “always-on” has to mean in practice

Always-on third-party risk is not a synonym for “more questionnaires, more often.” It means:

  • Discovery that keeps pace with how vendors actually enter the estate (identity, procurement, shadow IT), not only the ones that filed a ticket.
  • Assessment that can be re-opened when external conditions change — a KEV, a breach in the vendor’s class, a material posture shift — without waiting for the annual cycle.
  • Remediation that closes with proof, not with a hopeful email thread.
  • Human judgment where it belongs — approvals, exceptions, and residual-risk calls — without making humans the bottleneck for collection and chase-down.

Agentic TPRM is one way teams are trying to staff that model: specialized agents for discovery, assessment, outreach, and orchestration, with people in the loop on the decisions that carry accountability. The point is not replacing the risk owner. The point is ending the false calm of a green form in a world where attacker attention does not wait for your review calendar.

A diagnostic you can run this week

Before the next KEV headline:

  1. Pick one critical vendor class (identity, payments, API/integration, cloud ops).
  2. Ask: if CISA added a KEV tomorrow for a product in that class, who produces the list of our third parties in scope within hours — not days?
  3. Ask: what evidence do we accept as “patched / not exposed,” and who verifies it after the vendor says yes?
  4. Ask: which former or peripheral vendors still hold our data or access — and would they even appear in that list?

If those answers are fuzzy, the pain is not “we need a better template.” The pain is that assessment theater and live supply-chain risk have drifted apart.

Soft next step

If you are tightening how TPRM, legal, and security share that live picture — without adding headcount to chase questionnaires — we are happy to compare notes on how regulated teams are shifting the balance.

Contact Rescana

Contact us / Book a demo

Talk to Rescana about this advisory, or book a demo of the platform.