Back to Blog

Breach Data

The Data Behind Vendor Breach Lag Time

8 min read
Timeline showing a hidden breach interval before detection, gap visualization

When a vendor discloses a security incident, the disclosure date is rarely close to the date the incident actually began. The gap between those two dates is sometimes called "dwell time" in the context of internal breaches. For third-party incidents, a better term is lag time: the period during which something has already gone wrong inside a vendor's environment, but nothing has been communicated to the organizations that depend on that vendor.

Understanding the shape of this lag is important for vendor risk programs because it determines the realistic window in which monitoring can provide warning. If you are waiting for formal vendor disclosure to learn about an incident, you are typically learning about it weeks or months after it began. The question is whether signals exist during the lag period that a monitoring program could detect.

What Public Disclosure Records Show

Regulatory filing requirements and breach notification laws have created a reasonably consistent public record of vendor incidents. HHS breach records, state attorney general notifications, SEC 8-K filings for material cybersecurity incidents, and publicly disclosed class action settlements all include some combination of incident date, discovery date, and notification date. That structure makes it possible to analyze the lag time at a population level.

Looking at third-party vendor incidents disclosed between 2022 and 2025 across public records, a consistent pattern appears. The median time between incident start and formal notification to affected organizations runs in the range of 70 to 90 days. For incidents affecting software supply chain vendors, the median is higher, closer to 100 to 120 days. The distribution is skewed right: a minority of incidents are disclosed within two weeks, but a meaningful portion of incidents takes six months or more to surface through formal channels.

These numbers are not precise averages from a single study. They are industry-realistic ranges derived from the public record of disclosed incidents. The exact figures vary by study, methodology, and time period. What is consistent across analyses is the direction: the gap is measured in months, not days, and vendor-initiated disclosure is not the fastest path to awareness for the organizations affected.

Where Discovery Actually Happens

The formal notification path is not how most organizations actually learn about vendor incidents first. In a substantial proportion of disclosed incidents, the affected organization learned about the problem through one of four other channels before the vendor notified them: a security researcher disclosure, a news report, a regulatory filing by the vendor that caught the attention of someone at the affected organization, or detection of downstream anomalous behavior in the affected organization's own systems.

This is what the lag time problem actually looks like in practice. An incident is in progress at a vendor. The vendor may not yet know, or may know and be managing the disclosure process. During that period, signals that are outside the vendor's direct control are often present: vulnerability reports related to technology the vendor uses, public forum discussions about observed anomalies, regulatory enforcement actions against the vendor for unrelated compliance issues that surfaced alongside the security investigation, financial press coverage triggered by the vendor's incident response costs.

These signals do not directly announce the incident. They are fragments of a picture that is not yet assembled. But for a monitoring system reading those feeds continuously, the fragments add up to a change in signal pattern that a point-in-time assessment would miss entirely.

The Questionnaire Problem Is Structural

Annual questionnaires ask vendors to self-report. The timing of that self-report creates a specific problem with lag time. If your questionnaire cycle runs in Q1 and a vendor experiences an incident in Q3, you will not ask about that incident until the following Q1. Even then, vendors have discretion about whether and how to disclose past incidents in questionnaire responses, particularly for incidents that have been resolved and where legal counsel has advised limited disclosure.

This is not an argument that vendors are generally dishonest on questionnaires. Many are not, and the best-run vendor security programs include disclosure obligations in their vendor contracts. The structural problem is that questionnaire timing and incident timing are independent variables. An incident that occurs in the middle of your review cycle will fall into a documentation gap that is not closed until the next cycle.

Consider how this plays out concretely. A financial services team running quarterly vendor reviews for their Tier 1 vendors still had a 90-day review cycle for a payroll processing vendor. An incident affecting the payroll vendor's data storage infrastructure began in early September 2024. Public indicators appeared in late September: a disclosure from a security researcher about a vulnerability in a storage product the vendor used, followed by an uptick in forum activity from other organizations reporting anomalous API behavior. The vendor issued a formal notification in late November. The financial services team's next scheduled review was January. Their first formal awareness of the incident came through the vendor notification, 10 weeks after the earliest public signals appeared.

What Signals Appear During the Lag

The monitoring value during the lag period depends on what kinds of signals actually appear before formal disclosure. Looking at disclosed incidents where pre-disclosure signals were publicly visible, the most common categories are:

Security advisory publications: Vendors often use software and infrastructure products that have published CVEs or security advisories. An advisory for a product a vendor is known to use is not confirmation of an incident, but it is a signal that the vendor's security team should be responding to, and that response posture itself can sometimes be tracked through public channels.

Regulatory and enforcement activity: Vendors involved in financial services, healthcare, or other regulated industries frequently have regulatory correspondence and examination activity that is partially public. An increase in regulatory inquiry intensity can precede a breach disclosure, particularly when incidents involve compliance failures that regulators are separately investigating.

Financial and operational indicators: Some incidents become visible through financial impacts before formal security disclosure. Vendors who delay a product release, announce unexpected service outages, or begin accelerated hiring in specific security roles can signal that something is being managed internally.

Personnel changes: CISO departures, sudden changes in vendor security leadership, or the arrival of outside incident response consultants sometimes appear in professional network activity before formal disclosure. These are weak signals individually, but they combine with other indicators in ways that a monitoring system tracking multiple feeds can identify as a pattern change.

What This Means for Your Program

The practical implication of lag time data is that formal disclosure is a lagging indicator, not an early warning. If your vendor risk program relies primarily on vendor-initiated notifications and scheduled questionnaire responses to stay aware of third-party incidents, you are systematically behind the actual risk timeline by weeks to months.

We are not saying that pre-disclosure signals are always detectable or that continuous monitoring will catch every incident in progress. Many incidents leave no externally visible signals during their dwell period. The question is whether monitoring captures enough of the incidents that do produce external signals to justify the investment.

For high-consequence vendors, where an incident could result in material regulatory exposure or customer data loss, the answer is yes for most security teams. The monitoring investment for a Tier 1 vendor is small relative to the cost of learning about an incident at formal disclosure versus during the signal-visible window. For Tier 2 and Tier 3 vendors, the calculation is different, and the monitoring cadence can be calibrated accordingly.

The goal is not to replace the vendor notification and questionnaire process. It is to stop treating formal disclosure as the first opportunity for awareness. The signals that appear during the lag period are fragmentary and require judgment to interpret. But they are there, and for the vendors that matter most to your operations, they deserve attention before the notification email arrives.

See continuous vendor monitoring in action

Magnitude monitors your vendor portfolio around the clock for security, regulatory, financial, and operational signals. Request early access and your roster is live within one business week.

Request Access

More from the blog