Asaf Kochan, President & Cofounder of Sentra, offering data security for the AI era.
Organizations rely on an expanding ecosystem of security vendors to protect their most critical systems. Identity providers, endpoint platforms, cloud security tools, data security solutions and managed detection services all play an essential role in modern security programs.
Delivering those capabilities often requires visibility into customer environments. Some platforms receive privileged access to infrastructure. Others analyze copies of sensitive customer data in vendor-managed clouds. These models can improve security, but they also force a question security leaders should ask more often. How much trust does this architecture require?
For years, organizations have applied Zero Trust for users, devices and workloads, where permissions are continuously evaluated and every request is verified. Yet vendor relationships often receive a much broader level of confidence. With third-party and supply chain breaches nearly quadrupling over the last five years according to IBM’s 2026 X-Force Threat Intelligence Index, security leaders should extend Zero Trust thinking to vendor architecture and ask how much access and data movement each platform actually requires.
When The Defender Becomes The Target
Security vendors occupy a uniquely valuable position inside the enterprise. They often have extensive visibility across identities, endpoints, cloud infrastructure and sensitive data, allowing them to detect threats that individual organizations might otherwise miss. That reach also makes them high-value targets.
Rather than compromising one organization at a time, attackers increasingly search for opportunities to breach trusted intermediaries that serve hundreds or thousands of customers. Whether through software supply chains, identity platforms or centralized administrative services, compromising a single provider can create downstream risk across organizations.
The Risk Begins When Customer Data Leaves Your Environment
Many modern security platforms improve detection by copying customer telemetry, logs, identities or workloads into vendor-controlled cloud environments. This architecture offers clear operational advantages including centralized analytics to improve detection quality, simplified operations and accelerated product innovation.
Every copy of sensitive customer data creates another environment that must be secured, monitored, governed and trusted. If attackers compromise the vendor’s environment, they may gain access not only to the vendor’s system but to sensitive customer information that exists outside of the customer’s direct control.
The 2023 Okta support system breach demonstrated how attacks against a trusted identity provider can ripple across customer environments. Attackers accessed customer support files for certain customers, including files that contained session tokens in some cases and Okta later determined that a broader report exposed names and email addresses for all customer support system users.
A year later, the BeyondTrust Remote Support SaaS incident highlighted a different form of concentration risk. After exploiting a zero-day vulnerability to obtain an infrastructure API key, attackers gained unauthorized access, ultimately affecting 17 customers, including the U.S. Treasury Department. The incident showed how compromising a trusted administrative platform can quickly become a downstream customer problem.
While these incidents followed different attack paths, they point to the same lesson. When a single platform holds privileged access and administrative control across customer environments, its compromise can extend far beyond the vendor itself.
Why Architecture Is Changing
Regulatory requirements, data sovereignty obligations and AI adoption initiatives are all increasing pressure to minimize unnecessary movement of sensitive information. At the same time, advances in cloud-native computing and in-place processing make it increasingly practical to analyze data where it already resides rather than moving it into centralized vendor platforms.
AI raises the stakes because sensitive data is no longer only being stored or scanned. It is being used to generate answers, guide workflows and support automated actions. Every unnecessary copy creates another place attackers may target and another place AI governance has to account for.
As AI, cloud and third-party ecosystems continue to evolve, evaluating a security platform means looking beyond its capabilities to understand how it is designed to protect customer environments.
The Next Standard for Evaluating Security Vendors
Organizations will always need trusted security partners, but those relationships should be governed by architecture rather than assumption.
As AI adoption accelerates and third-party ecosystems become more interconnected, the way organizations evaluate security vendors will continue to evolve. Detection quality, operational maturity and product capabilities will remain essential, but they will no longer be sufficient on their own. Security leaders will increasingly need to understand how platforms handle sensitive data, manage privileged access and limit the impact of a potential compromise.
Before relying on contractual assurances or vendor reputation, security leaders should ask:
• Where does our data reside, and does it need to leave our environment?
• What level of access does the platform require, and is it limited to the minimum necessary?
• How is privileged access controlled, monitored and separated from customer environments?
• If the vendor itself is compromised, how does the platform’s design contain the impact on our organization?
Moving forward, the strongest security platforms will be those designed to require the least trust from their customers.
Forbes Technology Council is an invitation-only community for world-class CIOs, CTOs and technology executives. Do I qualify?

