Mandiant’s M-Trends 2026 report found that the median time between an initial access partner entering a network and handing that access to a secondary group fell to 22 seconds in 2025, down from more than eight hours in 2022. Annual vendor assessments measure a vendor’s state on one day. Continuous vendor monitoring tracks it between those days, which is where the risk now moves.
Third-party risk teams have been running the same operating model for a decade: assess a vendor at onboarding, reassess annually, and treat the gap in between as acceptable. Mandiant’s M-Trends 2026 report, built on more than 500,000 hours of incident response work conducted during 2025, makes that gap much harder to defend. It is the clearest argument yet for continuous vendor monitoring over point-in-time assessment, and the reason is not the headline number everyone quoted. It is what sits underneath it.
What is the 22 second handoff?
The 22-second handoff is the median time Mandiant observed in 2025 between an initial access partner gaining entry to an environment and handing that access to a secondary threat group, typically a ransomware operation. In 2022, the same measurement was more than eight hours.
Two points of precision, because this figure is widely misquoted:
- Mandiant is measuring the moment the secondary group gains access, not the moment hands-on-keyboard activity begins. It is not a claim that ransomware encrypts within 22 seconds.
- The collapse happened because access partners now pre-stage the secondary group’s preferred malware or tunnels during the initial infection, instead of advertising access on a criminal forum and waiting for a buyer.
The accurate reading: the criminal supply chain has removed the waiting period that used to sit between compromise and exploitation. Defenders were quietly relying on that pause. It is gone.
Why this lands on the vendor risk team
Two other findings in M-Trends 2026 matter more for TPRM than the headline does.
Prior compromise is now the leading way ransomware starts. Access inherited from another threat actor was the most frequently confirmed initial infection vector in ransomware operations at 30%, roughly double the 15% recorded the year before.
Third parties are a primary route into cloud environments. In cloud-related compromises, third-party compromise accounted for 17% of intrusions.
Read together, these say something specific: a growing share of ransomware begins with access somebody else established earlier, and a meaningful share of cloud intrusions arrive through a vendor. Your vendor’s old compromise becomes your new incident.
The timing makes it worse. While access changes hands in seconds, Mandiant put global median dwell time at 14 days in 2025, up from 11. Attackers move fast at handoff and slow once inside. Organizations find out late.
Where point-in-time vendor assessment breaks down
Consider a vendor assessed in January. The questionnaire came back clean, the external scan showed nothing alarming, and you signed off.
In March, a contractor working for that vendor picks up infostealer malware. Saved credentials for the vendor’s VPN land in a log. The log is packaged, listed, and sold. The handoff happens. An environment connected to yours changes hands.
You learn about it in May, when the vendor sends a notification, or when a reporter calls first.
The January assessment was not wrong. It was accurate on the day it was taken and had nothing to say about March. That is the structural limit of point-in-time assessment: it measures state, and the risk changed state without telling anyone. Tightening the questionnaire does not fix it.
What is continuous vendor monitoring?
Continuous vendor monitoring is the practice of tracking a third party’s cyber risk on an ongoing basis rather than at fixed assessment intervals, using external and intelligence-derived signals that do not require the vendor to self-report.
In practice it covers:
- Changes to a vendor’s external attack surface, including assets nobody has claimed ownership of
- Credentials belonging to the vendor appearing in stealer logs or breach data
- Criminal forum and marketplace activity referencing the vendor’s infrastructure or brand
- Changes in the vendor’s risk score between formal review cycles
- Newly acquired subsidiaries, partner networks, and related entities that extend the vendor’s footprint
The distinction that matters is not frequency. It is dependency. A questionnaire depends on the vendor knowing something changed and choosing to tell you. Continuous vendor monitoring does not.
Four shifts worth making this year in your TPRM program
1. Change the question you are asking. Move from “how secure is this vendor” to “how attractive is this vendor to an attacker right now, and how much access do they have to us.” Those produce different priority lists. The second is closer to how the other side actually selects targets.
2. Split the calendars. Assess on a cycle because contracts and auditors require it. Monitor continuously because attackers do not wait for your cycle. Collapsing both jobs into one annual event is what creates the gap.
3. Watch pre-attack signals, not just posture. Credentials surfacing in stealer logs, access being advertised, a vendor’s infrastructure drawing attention in criminal forums. These appear before the handoff. Posture scores describe what is already visible from the outside.
4. Cut time to first assessment. A vendor backlog is unassessed risk sitting on your books. If onboarding a vendor into your risk program takes weeks, the backlog grows faster than you clear it, and your newest vendors stay the least understood.
Where Sling fits
Sling was built on the assumption behind all of this: what attackers already know about your vendors matters more than what an external scan shows you.
The Sling Score combines darknet and criminal intelligence gathered in house over more than ten years with attack surface mapping and historical threat intelligence, and it is designed to estimate the probability of a company being attacked rather than describe its posture on a given afternoon. It updates continuously instead of at review time. Assessment starts with a domain name, requires no agent and no cooperation from the vendor, and produces a full risk picture within 24 hours.
To be clear about the limits: nothing closes a 22-second window. That is not the claim. The claim is narrower and more useful. The conditions that precede a handoff, including exposed credentials, unmanaged assets, and attention on a vendor’s infrastructure, are visible beforehand if you are looking somewhere other than the surface.
Frequently asked questions
Does continuous vendor monitoring replace security questionnaires? No. Questionnaires and evidence review remain the way to verify contractual commitments, process maturity, and audit requirements. Continuous vendor monitoring covers what questionnaires structurally cannot: changes that occur after the questionnaire was answered, and issues the vendor is not aware of.
What is an initial access broker? An initial access broker is a criminal specialist who compromises an organization and sells or transfers that access to other threat actors rather than monetizing it directly. M-Trends 2026 found these actors increasingly work directly with
Does continuous vendor monitoring help with DORA and NIS2? Yes. Both frameworks expect ongoing oversight of ICT third parties rather than periodic checks, and DORA requires financial entities to maintain a register of ICT third-party contractual arrangements including subcontracting chains. Continuous monitoring produces the evidence trail that requirement implies.
Key takeaways
- Mandiant’s M-Trends 2026 found the median handoff from initial access to a secondary threat group dropped to 22 seconds in 2025, from more than eight hours in 2022
- Prior compromise was the top initial infection vector in ransomware operations at 30%, double the previous year
- Third-party compromise accounted for 17% of cloud intrusions
- Point-in-time vendor assessments are accurate only on the day they are taken
- Continuous vendor monitoring closes the gap between review cycles without depending on vendor self-reporting