Skip to content

The zero-day tsunami is here, and most of it will hit you through your vendors.

It is unusual for one of the world's largest banks to warn the market about cyber risk twice in a matter of months.

In July, JPMorgan's Eye on the Market report, "Patchmageddon", described companies facing "a bit of a tsunami here that they're not expecting".[1] Earlier in the year, its technology leadership team published Fortifying the enterprise: 10 actions to take now for AI-ready cyber resilience, a practical playbook for organisations facing faster vulnerability discovery and shrinking patch windows.[2]

When an institution with JPMorgan's resources says patch cycles are moving beyond many organisations' capacity for change, security and risk leaders should assume their own margin is thinner still.

We have both spent years on the practitioner side of this, one as a CISO and one as a Head of Risk Management. For the security and risk leaders we work with every day, purchased software and vendor dependencies will carry much of the exposure. The core question is therefore wider than how quickly an internal team can patch its own systems: it is how quickly the organisations behind critical services can identify, remediate and communicate vulnerabilities across their own technology stacks.

Fast-moving cyber risk is harder to manage when controls, evidence and ownership sit in separate systems. Download Protecht's cyber risk eBook, Too many tools, not enough truth, for practical guidance on building a connected, decision-ready cyber risk model.

fragmented-cyber-programs-ebook-cta_600x300

What has actually changed

For decades, finding serious software flaws was slow, expensive and expert-intensive, which allowed many organisations to patch on quarterly cycles and stay reasonably close to the threat. AI is now changing that balance as frontier models can identify vulnerabilities, including previously unknown flaws, at much greater scale, while exploitation can follow disclosure almost immediately. The mechanics of remediation remain stubbornly physical: patches still need testing, scheduling and safe deployment. The result is a widening gap between discovery and remediation, arriving faster than many change-management processes were designed to handle.

Why this is a third-party problem first

For most organisations, and for virtually every mid-sized bank and credit union, the overwhelming majority of important software was written by someone else. Core platforms, digital banking, payments infrastructure and SaaS tools are all vendor products. Each may depend on hundreds or thousands of open-source components and on further providers that the buyer does not see directly. When a vulnerability appears in purchased software, the vendor controls the patch and the buyer's exposure window depends on that vendor's speed, testing discipline and transparency. The same is true one level further down the chain, where fourth parties can influence how quickly a critical service becomes safe again.

JPMorgan's resilience playbook gives major SaaS and outsourced dependencies their own action. It recommends a current register of critical providers, direct questions about patching cadence and breach notification, contractual commitments, and contingency plans for provider outages or compromise. The framing is useful for risk teams because a compromise at a critical provider still becomes an incident the customer must manage, regardless of where the technical fault began.

Traditional third-party risk is struggling with the new tempo

The standard third-party risk toolkit was built for a slower environment. Annual questionnaires and point-in-time reviews capture a vendor's posture at one moment, then age while the threat landscape continues to change. Questionnaire-based programmes also scale with human effort, so many organisations deeply assess a narrow top tier of vendors and accept limited visibility across the rest. That leaves the long tail, where older or poorly maintained software can accumulate, with less scrutiny. A programme that takes ninety days to assess one vendor cannot give a current view of a portfolio of five hundred when new critical flaws appear continually. Improving cadence and coverage therefore requires a more efficient evidence model and less dependence on manual review.

The CISO focus: Paul Valente

I spent years in the CISO seat, and I recognise where this moment puts security leaders: accountable for an attack surface made up largely of other people's software, using processes that were built for a slower tempo. JPMorgan's ten actions provide a strong foundation, from software currency and reliable asset and SBOM inventories to exploitation-driven vulnerability management. Extending the same evidence standard to vendors makes those internal disciplines more useful across the full attack surface.

Visibility across vendor exposure needs to exist before a vulnerability event. The first question is often "which of our vendors is affected?" Answering it requires current, evidence-based visibility across the portfolio. Modern assessment technology can read vendor security evidence such as audit reports, certifications and penetration-test summaries, then build a substantive view of security maturity without starting every review with a questionnaire. At VISO TRUST, that is the model we built: AI-driven due diligence that allows a lean security team to assess and continuously reassess hundreds or thousands of vendors with a level of rigour that was previously practical for only a small group.

Patch and remediation velocity should influence vendor tiering alongside contract value, data sensitivity and service criticality. Vendors that can demonstrate disciplined patching and current dependencies are better equipped to absorb a faster vulnerability cycle. Those that cannot explain their remediation speed or software currency may represent concentrated exposure. Making patch velocity an explicit assessment criterion gives security teams another way to focus follow-up on the vendors most likely to create a prolonged exposure window.

Vendors should also meet the same evidence standard expected internally. JPMorgan's playbook calls for timely security notifications, right-to-audit provisions, defined recovery objectives and verification that commitments are being met in practice. Boards, insurers and examiners increasingly expect evidence that critical third parties can keep pace. A policy statement or a completed questionnaire can support that view, but stronger assurance comes from current evidence of how controls operate.

 

The CRO focus: Jared Siddle

I spent years as a CRO before moving to the vendor side, and I now work with risk leaders at mid-sized banks and credit unions across North America. From the CRO's seat, the problem quickly crosses the security boundary. A compromised critical vendor can become an operational disruption, a compliance obligation, a customer-harm event and a board conversation within hours. When third-party cyber exposure sits only in security tooling, the enterprise risk picture can be incomplete just when leadership needs a joined-up view.

Vendor cyber posture should connect to enterprise risk before an incident exposes the gap. Each critical vendor can be linked to the business services it supports, the controls that reduce exposure, the obligations it touches and the appetite thresholds that trigger escalation. That connection turns faster assessment into faster decisions because the board can see what a vendor weakness means for the enterprise, rather than receiving a security finding without business context.

Concentration risk also belongs on the enterprise register. For many mid-sized financial institutions, a small number of providers across core banking, digital banking and payments represent genuine single points of failure. Those providers are absorbing the same vulnerability wave as everyone else. A clear appetite statement, severe-but-plausible scenarios and board reporting can show how close the institution sits to tolerance. JPMorgan's playbook reaches the same conclusion from the technology side by recommending that dependency information be shared across technology, risk and continuity teams so concentration and cascading-failure scenarios are visible.

Risk appetite and reporting also need to reflect the new tempo. Statements written when vulnerability disclosure moved more slowly may implicitly tolerate patch lags that no longer fit the threat. Exposure-window metrics for critical vendors, board-endorsed thresholds and regular reporting make that acceptance explicit. When an examiner or incident response team asks why an exposure was carried, the institution should be able to show the decision, the evidence behind it and the controls in place. Beyond exam readiness, boards should be able to see at any point which third-party exposures are material, why they remain within appetite and what stands between those exposures and a loss.

 

The bottom line

JPMorgan has done the market a service by naming the problem and publishing a practical playbook. The harder implication is that organisations cannot patch their way through this alone because much of the software that matters sits outside their direct control. Institutions will be better placed to respond when they can see third-party exposure clearly, keep the evidence current and connect vendor findings to enterprise risk decisions at the speed the situation requires. The wave is already arriving, and the practical response is to meet it with clear accountability, current assurance and a connected view of vendor dependencies.

Next steps for your organisation

Managing this faster threat environment requires a cyber risk model that connects vulnerabilities, controls, incidents, obligations and business impact, alongside current evidence about the third parties carrying critical services. Protecht's cyber solution helps teams bring cyber risks and control assurance into one connected view, while Protecht and VISO TRUST extend that view across the vendor ecosystem with AI-powered assurance and ongoing third- and fourth-party visibility. Together, cyber, vendor and enterprise risk teams can see what has changed, understand what it means for critical services and direct action before exposures move beyond appetite.

A combined demo can show how these capabilities work together in practice: from managing cyber risks, controls, incidents and obligations inside the enterprise to assessing vendor evidence, monitoring third- and fourth-party exposure, and escalating findings and actions through connected workflows.

Request a demo to see how Protecht and VISO TRUST can help you strengthen cyber risk management across your own environment and the vendors on which you depend.

blog-demo-cta_1200x400

References

[1] J.P. Morgan Private Bank, “Patchmageddon”, 22 July 2026, https://privatebank.jpmorgan.com/nam/en/insights/latest-and-featured/eotm/patchmageddon

[2] JPMorganChase Global Technology Leadership Team, “Fortifying the enterprise: 10 actions to take now for AI-ready cyber resilience”, 17 April 2026, https://www.jpmorganchase.com/about/technology/blog/fortifying-the-enterprise-10-actions-to-take-now-for-ai-ready-cyber-resilience

About the author

Jared Siddle is Protecht's VP ERM Sales, North America. He is a Qualified Risk Director who has been Head of Risk Management at three different companies, including two of the world's largest asset managers.

Paul Valente is Co-Founder and Chief Customer Officer at VISO TRUST, a Protecht company. Paul works with customers, product teams and the global CISO community to advance AI-powered third- and fourth-party risk management.