{"id":15405,"date":"2026-09-21T14:43:18","date_gmt":"2026-09-21T09:13:18","guid":{"rendered":"https:\/\/threatcop.com\/blog\/?p=15405"},"modified":"2026-09-21T16:39:28","modified_gmt":"2026-09-21T11:09:28","slug":"third-party-ransomware-risk","status":"publish","type":"post","link":"https:\/\/threatcop.com\/blog\/third-party-ransomware-risk\/","title":{"rendered":"Third-Party Ransomware Risk: When Your Vendor&#8217;s Incident Becomes Your Outage"},"content":{"rendered":"\n<p class=\"wp-block-paragraph\">A ransomware attack on one check-in software vendor stopped passenger processing at Heathrow, Brussels, Berlin Brandenburg, and Dublin in September 2025. None of those airports was breached. All of them stopped working, which is the distinction between managing liability and managing continuity.<\/p><div id=\"ez-toc-container\" class=\"ez-toc-v2_0_88 ez-toc-wrap-center counter-hierarchy ez-toc-counter ez-toc-light-blue ez-toc-container-direction\">\n<div class=\"ez-toc-title-container\">\n<p class=\"ez-toc-title\" style=\"cursor:inherit\">Table of Contents<\/p>\n<span class=\"ez-toc-title-toggle\"><a href=\"#\" class=\"ez-toc-pull-right ez-toc-btn ez-toc-btn-xs ez-toc-btn-default ez-toc-toggle\" aria-label=\"Toggle Table of Content\"><span class=\"ez-toc-js-icon-con\"><span class=\"\"><span class=\"eztoc-hide\" style=\"display:none;\">Toggle<\/span><span class=\"ez-toc-icon-toggle-span\"><svg style=\"fill: #414141;color:#414141\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\" class=\"list-377408\" width=\"20px\" height=\"20px\" viewBox=\"0 0 24 24\" fill=\"none\"><path d=\"M6 6H4v2h2V6zm14 0H8v2h12V6zM4 11h2v2H4v-2zm16 0H8v2h12v-2zM4 16h2v2H4v-2zm16 0H8v2h12v-2z\" fill=\"currentColor\"><\/path><\/svg><svg style=\"fill: #414141;color:#414141\" class=\"arrow-unsorted-368013\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\" width=\"10px\" height=\"10px\" viewBox=\"0 0 24 24\" version=\"1.2\" baseProfile=\"tiny\"><path d=\"M18.2 9.3l-6.2-6.3-6.2 6.3c-.2.2-.3.4-.3.7s.1.5.3.7c.2.2.4.3.7.3h11c.3 0 .5-.1.7-.3.2-.2.3-.5.3-.7s-.1-.5-.3-.7zM5.8 14.7l6.2 6.3 6.2-6.3c.2-.2.3-.5.3-.7s-.1-.5-.3-.7c-.2-.2-.4-.3-.7-.3h-11c-.3 0-.5.1-.7.3-.2.2-.3.5-.3.7s.1.5.3.7z\"\/><\/svg><\/span><\/span><\/span><\/a><\/span><\/div>\n<nav><ul class='ez-toc-list ez-toc-list-level-1 ' ><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-1\" href=\"https:\/\/threatcop.com\/blog\/third-party-ransomware-risk\/#What_Happened_and_What_Was_Actually_Confirmed\" >What Happened, and What Was Actually Confirmed<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-2\" href=\"https:\/\/threatcop.com\/blog\/third-party-ransomware-risk\/#The_Detail_That_Proves_the_Point\" >The Detail That Proves the Point<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-3\" href=\"https:\/\/threatcop.com\/blog\/third-party-ransomware-risk\/#Book_a_Free_Demo_Call_with_Our_Expert\" >Book a Free Demo Call with Our Expert<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-4\" href=\"https:\/\/threatcop.com\/blog\/third-party-ransomware-risk\/#Why_the_Regulatory_Filing_Language_Matters\" >Why the Regulatory Filing Language Matters<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-5\" href=\"https:\/\/threatcop.com\/blog\/third-party-ransomware-risk\/#The_Reinfection_Problem\" >The Reinfection Problem<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-6\" href=\"https:\/\/threatcop.com\/blog\/third-party-ransomware-risk\/#Where_Liability_Thinking_and_Resilience_Thinking_Diverge\" >Where Liability Thinking and Resilience Thinking Diverge<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-7\" href=\"https:\/\/threatcop.com\/blog\/third-party-ransomware-risk\/#Concentration_Is_the_Risk_Nobody_Owns\" >Concentration Is the Risk Nobody Owns<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-8\" href=\"https:\/\/threatcop.com\/blog\/third-party-ransomware-risk\/#Questions_to_Ask_a_Critical_Vendor\" >Questions to Ask a Critical Vendor<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-9\" href=\"https:\/\/threatcop.com\/blog\/third-party-ransomware-risk\/#What_to_Rehearse_Before_You_Need_It\" >What to Rehearse Before You Need It<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-10\" href=\"https:\/\/threatcop.com\/blog\/third-party-ransomware-risk\/#Metrics_Worth_Tracking\" >Metrics Worth Tracking<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-11\" href=\"https:\/\/threatcop.com\/blog\/third-party-ransomware-risk\/#Ask_One_Vendor_How_Many_Customers_Share_Your_Platform\" >Ask One Vendor How Many Customers Share Your Platform<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-12\" href=\"https:\/\/threatcop.com\/blog\/third-party-ransomware-risk\/#Frequently_Asked_Questions\" >Frequently Asked Questions<\/a><\/li><\/ul><\/nav><\/div>\n\n\n\n\n<h2 class=\"wp-block-heading\"><span class=\"ez-toc-section\" id=\"What_Happened_and_What_Was_Actually_Confirmed\"><\/span>What Happened, and What Was Actually Confirmed<span class=\"ez-toc-section-end\"><\/span><\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">On the evening of Friday 19 September 2025, ransomware hit systems supporting Collins Aerospace&#8217;s ARINC vMUSE platform, the software airlines use to share check-in desks and boarding gates.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">By Saturday morning, staff at several major European airports were writing boarding passes by hand. Hundreds of flights were delayed or cancelled across the weekend.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Separating confirmed fact from reporting matters here, because much of the coverage blurred the two. ENISA confirmed the disruption was caused by ransomware. RTX, the parent company, confirmed a ransomware incident in a filing with the US Securities and Exchange Commission. The UK&#8217;s National Crime Agency <a href=\"https:\/\/www.infosecurity-magazine.com\/news\/nca-arrest-hardbit-ransomware\/\" rel=\"nofollow noopener\" target=\"_blank\">arrested a 40-year-old man in West Sussex<\/a> under the Computer Misuse Act, later releasing him on conditional bail.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The variant was never officially confirmed. Researchers pointed to HardBit, other reporting suggested Loki, and attribution remained contested throughout. Treat the family as probable rather than established.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\"><span class=\"ez-toc-section\" id=\"The_Detail_That_Proves_the_Point\"><\/span>The Detail That Proves the Point<span class=\"ez-toc-section-end\"><\/span><\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">One characteristic of the suspected variant deserves more attention than it received, because it turns an abstract argument into a concrete mechanism.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">HardBit emerged in October 2022 and became notable for a specific negotiating tactic, as <a href=\"https:\/\/www.securityweek.com\/european-airport-cyberattack-linked-to-obscure-ransomware-suspect-arrested\/\" rel=\"nofollow noopener\" target=\"_blank\">SecurityWeek reported at the time<\/a>. Its operators pegged ransom demands to the victim&#8217;s cyber-insurance limits.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Read that again with the liability question in mind. An organisation buys insurance to transfer financial risk. The attacker then reads the policy limit and prices the demand to it.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Liability transfer does not sit outside the attack. It becomes an input to the attacker&#8217;s pricing model. So &#8220;we are covered&#8221; answers a finance question and leaves the operational one untouched.<\/p>\n\n\n\n<meta charset=\"UTF-8\">\n<meta name=\"viewport\" content=\"width=device-width, initial-scale=1.0\">\n<title>Threatcop \u2013 Book a Free Demo<\/title>\n<link href=\"https:\/\/fonts.googleapis.com\/css2?family=Outfit:wght@300;400;500;600;700&#038;display=swap\" rel=\"stylesheet\">\n<style>\n  .tc-wrap , .tc-wrap ::before, .tc-wrap ::after { box-sizing: border-box; margin: 0; padding: 0; }\n  .tc-wrap { font-family: 'Outfit', sans-serif; width: 100%; display: flex; justify-content: center; padding: 20px 10px; }\n  .tc-card { width: 100%; max-width: 820px; background: #fff; border-radius: 20px; overflow: hidden; box-shadow: 0 20px 60px rgba(24,57,148,0.13), 0 4px 16px rgba(24,57,148,0.07); display: flex; flex-direction: row; }\n  .tc-left { background: linear-gradient(160deg, #1e44b0 0%, #183994 40%, #0e2570 100%); width: 320px; flex-shrink: 0; padding: 40px 32px; display: flex; flex-direction: column; justify-content: center; position: relative; overflow: hidden; }\n  .tc-left::before { content: ''; position: absolute; inset: 0; background-image: radial-gradient(rgba(255,255,255,0.08) 1.5px, transparent 1.5px); background-size: 22px 22px; }\n  .tc-left::after { content: ''; position: absolute; bottom: -60px; right: -60px; width: 220px; height: 220px; background: radial-gradient(circle, rgba(99,179,255,0.22) 0%, transparent 65%); border-radius: 50%; pointer-events: none; }\n  .tc-panel-inner { position: relative; z-index: 1; }\n  .tc-badge { display: inline-flex !important; align-items: center !important; gap: 6px; background: rgba(255,255,255,0.1) !important; border: 1px solid rgba(255,255,255,0.18) !important; border-radius: 20px !important; padding: 4px 14px 4px 10px !important; font-size: 12.5px !important; font-weight: 600 !important; letter-spacing: .09em !important; text-transform: uppercase !important; color: rgba(255,255,255,0.85) !important; margin-bottom: 18px !important; font-family: 'Outfit', sans-serif !important; line-height: 1.4 !important; }\n  .tc-badge-dot { width: 6px; height: 6px; background: #5cd9a0; border-radius: 50%; box-shadow: 0 0 6px #5cd9a0; flex-shrink: 0; display: inline-block; }\n  .tc-left h1, .tc-left h2, .tc-left h3, .tc-left h4, .tc-left h5, .tc-left h6 { color: #ffffff !important; font-family: 'Outfit', sans-serif !important; font-size: 28px !important; font-weight: 700 !important; line-height: 1.35 !important; letter-spacing: -0.3px !important; margin: 0 !important; padding: 0 !important; background: none !important; -webkit-text-fill-color: #ffffff !important; }\n  .tc-left h2 em { font-style: normal !important; color: #7ec8ff !important; -webkit-text-fill-color: #7ec8ff !important; }\n  .tc-left p, .tc-left .tc-sub { color: rgba(255,255,255,0.78) !important; -webkit-text-fill-color: rgba(255,255,255,0.78) !important; font-family: 'Outfit', sans-serif !important; font-size: 14px !important; font-weight: 300 !important; line-height: 1.65 !important; margin-top: 12px !important; background: none !important; }\n  .tc-right { flex: 1; padding: 32px 32px 28px; display: flex; flex-direction: column; justify-content: center; }\n  .tc-form-title { font-size: 13px !important; font-weight: 600 !important; letter-spacing: .12em; text-transform: uppercase; color: #8fa4cc !important; margin-bottom: 20px !important; display: flex !important; align-items: center !important; gap: 10px; font-family: 'Outfit', sans-serif !important; }\n  .tc-form-title::after { content: ''; flex: 1; height: 1px; background: #eef1fa; }\n  .tc-grid { display: grid; grid-template-columns: 1fr 1fr; gap: 14px; }\n  .tc-field { display: flex; flex-direction: column; gap: 5px; }\n  .tc-field.full { grid-column: 1 \/ -1; }\n  .tc-field label { font-size: 13px !important; font-weight: 600 !important; color: #3a4f7a !important; letter-spacing: .04em; text-transform: uppercase; font-family: 'Outfit', sans-serif !important; display: block !important; }\n  .tc-input-wrap { position: relative; display: flex; align-items: center; }\n  .tc-input-wrap .tc-fi { position: absolute; right: 12px; width: 15px; height: 15px; stroke: #c0ccdf; stroke-width: 1.8; pointer-events: none; fill: none; }\n  .tc-wrap input[type=\"text\"], .tc-wrap input[type=\"email\"], .tc-wrap input[type=\"number\"] { width: 100% !important; border: 1.5px solid #e2e9f7 !important; border-radius: 10px !important; padding: 9px 34px 9px 13px !important; font-family: 'Outfit', sans-serif !important; font-size: 15px !important; font-weight: 400 !important; color: #1e2d50 !important; background: #f8faff !important; outline: none !important; transition: border-color .2s, background .2s, box-shadow .2s; -moz-appearance: textfield; box-shadow: none !important; -webkit-text-fill-color: #1e2d50 !important; }\n  .tc-wrap input[type=\"number\"]::-webkit-inner-spin-button, .tc-wrap input[type=\"number\"]::-webkit-outer-spin-button { -webkit-appearance: none; }\n  .tc-wrap input::placeholder { color: #c0ccdf !important; -webkit-text-fill-color: #c0ccdf !important; opacity: 1; }\n  .tc-wrap input:focus { border-color: #183994 !important; background: #fff !important; box-shadow: 0 0 0 3.5px rgba(24,57,148,0.1) !important; }\n  .tc-phone-row { display: flex; gap: 8px; }\n  .tc-flag-select { position: relative; flex-shrink: 0; }\n  .tc-flag-select select { appearance: none !important; -webkit-appearance: none !important; border: 1.5px solid #e2e9f7 !important; border-radius: 10px !important; padding: 9px 26px 9px 12px !important; font-family: 'Outfit', sans-serif !important; font-size: 14px !important; font-weight: 500 !important; color: #1e2d50 !important; background: #f8faff !important; outline: none !important; cursor: pointer; width: 100px !important; transition: border-color .2s, box-shadow .2s; }\n  .tc-flag-select select:focus { border-color: #183994 !important; box-shadow: 0 0 0 3.5px rgba(24,57,148,0.1) !important; }\n  .tc-flag-select::after { content: ''; position: absolute; right: 10px; top: 50%; transform: translateY(-50%); width: 0; height: 0; border-left: 4px solid transparent; border-right: 4px solid transparent; border-top: 5px solid #a0b0cc; pointer-events: none; }\n  .tc-phone-row .tc-input-wrap { flex: 1; }\n  .tc-btn-submit { width: 100% !important; margin-top: 18px !important; padding: 11px !important; background: #183994 !important; border: none !important; border-radius: 10px !important; color: #fff !important; -webkit-text-fill-color: #fff !important; font-family: 'Outfit', sans-serif !important; font-size: 15px !important; font-weight: 600 !important; letter-spacing: .05em; cursor: pointer; display: flex !important; align-items: center !important; justify-content: center !important; gap: 9px; transition: background .2s, transform .15s, box-shadow .2s; box-shadow: 0 6px 24px rgba(24,57,148,0.28) !important; text-decoration: none !important; }\n  .tc-btn-submit:hover { background: #1d46b5 !important; transform: translateY(-1px); box-shadow: 0 10px 32px rgba(24,57,148,0.35) !important; color: #fff !important; }\n  .tc-btn-submit:active { transform: translateY(0); }\n  .tc-btn-submit svg { width: 16px; height: 16px; stroke: #fff; stroke-width: 2.2; fill: none; flex-shrink: 0; }\n  .tc-trust { margin-top: 10px !important; display: flex !important; align-items: center !important; justify-content: center !important; gap: 5px; font-size: 13px !important; color: #a0b0cc !important; font-family: 'Outfit', sans-serif !important; }\n  .tc-trust svg { width: 12px; height: 12px; stroke: #a0b0cc; stroke-width: 2; fill: none; flex-shrink: 0; }\n  @media (max-width: 680px) {\n    .tc-card { flex-direction: column !important; }\n    .tc-left { width: 100% !important; padding: 28px 24px 24px !important; }\n    .tc-right { padding: 24px 20px !important; }\n    .tc-grid { grid-template-columns: 1fr !important; }\n    .tc-field.full { grid-column: 1 !important; }\n  }\n<\/style>\n\n<div class=\"tc-wrap\">\n  <div class=\"tc-card\">\n    <div class=\"tc-left\">\n      <div class=\"tc-panel-inner\">\n        <div class=\"tc-badge\">\n          <span class=\"tc-badge-dot\"><\/span>\n          People Security Management\n        <\/div>\n        <h2><span class=\"ez-toc-section\" id=\"Book_a_Free_Demo_Call_with_Our_Expert\"><\/span>Book a Free<br><em>Demo Call<\/em><br>with Our Expert<span class=\"ez-toc-section-end\"><\/span><\/h2>\n        <p class=\"tc-sub\">Discover how Threatcop protects your workforce from modern cyber threats.<\/p>\n      <\/div>\n    <\/div>\n    <div class=\"tc-right\">\n      <div class=\"tc-form-title\">Your Details<\/div>\n      <form action=\"https:\/\/threatcop.com\/thankyou-blog\" method=\"get\" target=\"_blank\">\n        <input type=\"hidden\" name=\"BlogForm\" value=\"BlogForm\">\n        <input type=\"hidden\" name=\"PageSource\" id=\"tc-page-source\" value=\"\">\n        <div class=\"tc-grid\">\n          <div class=\"tc-field\">\n            <label>Full Name<\/label>\n            <div class=\"tc-input-wrap\">\n              <input type=\"text\" name=\"FullName\" placeholder=\"Jane Smith\" required=\"\">\n              <svg class=\"tc-fi\" viewBox=\"0 0 24 24\" stroke-linecap=\"round\"><circle cx=\"12\" cy=\"8\" r=\"4\"><\/circle><path d=\"M4 20c0-4 3.58-7 8-7s8 3 8 7\"><\/path><\/svg>\n            <\/div>\n          <\/div>\n          <div class=\"tc-field\">\n            <label>Company Name<\/label>\n            <div class=\"tc-input-wrap\">\n              <input type=\"text\" name=\"CompanyName\" placeholder=\"Acme Corp\" required=\"\">\n              <svg class=\"tc-fi\" viewBox=\"0 0 24 24\" stroke-linecap=\"round\"><rect x=\"3\" y=\"3\" width=\"18\" height=\"18\" rx=\"2\"><\/rect><path d=\"M9 3v18M3 9h6M3 15h6\"><\/path><\/svg>\n            <\/div>\n          <\/div>\n          <div class=\"tc-field full\">\n            <label>Corporate Email<\/label>\n            <div class=\"tc-input-wrap\">\n              <input type=\"email\" name=\"email\" placeholder=\"jane@yourcompany.com\" required=\"\">\n              <svg class=\"tc-fi\" viewBox=\"0 0 24 24\" stroke-linecap=\"round\"><rect x=\"2\" y=\"4\" width=\"20\" height=\"16\" rx=\"2\"><\/rect><polyline points=\"2,4 12,13 22,4\"><\/polyline><\/svg>\n            <\/div>\n          <\/div>\n          <div class=\"tc-field full\">\n            <label>Phone Number<\/label>\n            <div class=\"tc-input-wrap\">\n              <input type=\"number\" name=\"Phone\" placeholder=\"98765 43210\" required=\"\">\n              <svg class=\"tc-fi\" viewBox=\"0 0 24 24\" stroke-linecap=\"round\"><path d=\"M22 16.92v3a2 2 0 01-2.18 2A19.79 19.79 0 013.09 4.18 2 2 0 015.07 2h3a2 2 0 012 1.72c.13.96.36 1.9.71 2.81a2 2 0 01-.45 2.11L9.09 9.91a16 16 0 006 6l1.27-1.27a2 2 0 012.11-.45c.91.35 1.85.58 2.81.71A2 2 0 0122 16.92z\"><\/path><\/svg>\n            <\/div>\n          <\/div>\n        <\/div>\n        <button type=\"submit\" class=\"tc-btn-submit\">\n          <svg viewBox=\"0 0 24 24\" stroke-linecap=\"round\"><path d=\"M22 2L11 13M22 2L15 22l-4-9-9-4 20-7z\"><\/path><\/svg>\n          Book My Free Demo\n        <\/button>\n        <div class=\"tc-trust\">\n          <svg viewBox=\"0 0 24 24\" stroke-linecap=\"round\"><rect x=\"3\" y=\"11\" width=\"18\" height=\"11\" rx=\"2\"><\/rect><path d=\"M7 11V7a5 5 0 0110 0v4\"><\/path><\/svg>\n          Your data is safe &amp; never shared with third parties\n        <\/div>\n      <\/form>\n    <\/div>\n  <\/div>\n<\/div>\n<script>document.getElementById('tc-page-source').value = window.location.href;<\/script>\n\n\n\n<h2 class=\"wp-block-heading\"><span class=\"ez-toc-section\" id=\"Why_the_Regulatory_Filing_Language_Matters\"><\/span>Why the Regulatory Filing Language Matters<span class=\"ez-toc-section-end\"><\/span><\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">RTX&#8217;s SEC disclosure included a line worth reading carefully. The MUSE airport systems, it noted, operate outside the RTX enterprise network, residing on customer-specific networks.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">That statement is accurate and appropriate. Investors need to know whether a subsidiary&#8217;s incident reached the parent&#8217;s core systems, and scoping the blast radius is exactly what a disclosure should do.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">It also does nothing for an airport. From Heathrow&#8217;s position, the relevant fact is that passenger processing stopped, and the architectural boundary protecting RTX&#8217;s enterprise network was not a boundary protecting its customers.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">That gap is the whole lesson. A vendor can be truthful about its own containment while your operations are down, because the two of you are measuring different things. Assurance describes their exposure. Continuity describes yours.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\"><span class=\"ez-toc-section\" id=\"The_Reinfection_Problem\"><\/span>The Reinfection Problem<span class=\"ez-toc-section-end\"><\/span><\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Recovery went badly in a way that carries a general lesson. Researchers tracking the response reported that devices kept getting reinfected, forcing recovery to restart repeatedly.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">That is what turns a weekend incident into a multi-day one. Restoring systems into an environment where the threat persists produces a loop rather than a recovery, and each cycle costs another day of manual operations.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Kevin Beaumont, the researcher who tracked it publicly, noted that the payloads were detected by free antivirus using static detections that were years old. Sophistication was not the obstacle.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Cost framing for the human layer sits in <a href=\"https:\/\/threatcop.com\/blog\/how-psm-reduces-compliance-costs\/\">why weak human controls raise compliance costs<\/a>. For a customer organisation, the practical consequence is a planning assumption rather than blame. Fallback procedures need to survive not the outage you imagined, but one that recurs, because a vendor&#8217;s recovery may fail more than once.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\"><span class=\"ez-toc-section\" id=\"Where_Liability_Thinking_and_Resilience_Thinking_Diverge\"><\/span>Where Liability Thinking and Resilience Thinking Diverge<span class=\"ez-toc-section-end\"><\/span><\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Both are legitimate. They answer different questions, and confusing them produces contracts that satisfy legal review and fail during an incident.<\/p>\n\n\n\n<figure class=\"wp-block-table\"><table class=\"has-fixed-layout\"><thead><tr><th><strong>Question<\/strong><\/th><th><strong>Liability answer<\/strong><\/th><th><strong>Resilience answer<\/strong><\/th><\/tr><\/thead><tbody><tr><td>Is the vendor certified?<\/td><td>ISO 27001 and SOC 2 on file<\/td><td>Certification scope checked against the system you depend on<\/td><\/tr><tr><td>What if they are breached?<\/td><td>Indemnity clause and insurance<\/td><td>Named fallback procedure, rehearsed<\/td><\/tr><tr><td>How long until service returns?<\/td><td>Service level agreement with credits<\/td><td>Your own tolerance, measured, with a plan beyond it<\/td><\/tr><tr><td>Who is accountable?<\/td><td>Contractually, the vendor<\/td><td>Operationally, you, in front of your customers<\/td><\/tr><tr><td>What did they tell us?<\/td><td>Written assurances<\/td><td>Evidence of configuration and patch state<\/td><\/tr><tr><td>How exposed are we?<\/td><td>Single-supplier risk noted in the register<\/td><td>Concentration mapped across the sector<\/td><\/tr><\/tbody><\/table><\/figure>\n\n\n\n<p class=\"wp-block-paragraph\">The right-hand column costs more and is the only one that keeps passengers moving. Supply chain patterns of this kind appear in <a href=\"https:\/\/threatcop.com\/blog\/third-party-data-breaches\/\">when a supplier failure becomes your incident<\/a>.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\"><span class=\"ez-toc-section\" id=\"Concentration_Is_the_Risk_Nobody_Owns\"><\/span>Concentration Is the Risk Nobody Owns<span class=\"ez-toc-section-end\"><\/span><\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">The striking feature of this incident is not that one vendor was compromised. It is how many organisations that single compromise stopped.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Sector exposure of this kind is examined in <a href=\"https:\/\/threatcop.com\/blog\/cybersecurity-in-financial-sector\/\">cybersecurity in the financial sector<\/a>, where the same concentration pattern appears. Shared platforms deliver real efficiency. Common-use check-in lets airlines share desks and gates instead of building parallel infrastructure, which is why the model spread.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The cost appears only in failure. When several competing organisations depend on one provider, a single incident becomes a sector event, and no individual customer&#8217;s risk register captures that. Each airport assessed its own vendor exposure. None of them owned the concentration.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Regulators are moving on this. NIS2 pushes supply chain security obligations onto essential and important entities across the EU, and DORA imposes parallel duties on the financial sector for critical ICT providers. Both require looking at dependencies rather than at contracts.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\"><span class=\"ez-toc-section\" id=\"Questions_to_Ask_a_Critical_Vendor\"><\/span>Questions to Ask a Critical Vendor<span class=\"ez-toc-section-end\"><\/span><\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Written assurances are the easiest thing to obtain and the least useful. Six questions produce answers that matter.<\/p>\n\n\n\n<ol class=\"wp-block-list\">\n<li><strong>Which specific system are we depending on, and is it inside your certification scope?<\/strong> Certifications cover a defined boundary that may exclude the product you buy.<\/li>\n\n\n\n<li><strong>What is your patch state on the components serving us?<\/strong> Ask for evidence rather than policy.<\/li>\n\n\n\n<li><strong>How many other customers share this platform instance?<\/strong> Concentration is invisible without asking.<\/li>\n\n\n\n<li><strong>What is your tested recovery time, and when did you last test it?<\/strong> Untested recovery times are estimates.<\/li>\n\n\n\n<li><strong>What happens if recovery fails and reinfection occurs?<\/strong> The incident above makes this a reasonable question rather than a hostile one.<\/li>\n\n\n\n<li><strong>How will you communicate during an incident, and to whom?<\/strong> Settle this in advance, since airports learned about the outage from their own terminals.<\/li>\n<\/ol>\n\n\n\n<p class=\"wp-block-paragraph\">Question 3 is the one most often skipped, and the one that would have surfaced this risk beforehand.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\"><span class=\"ez-toc-section\" id=\"What_to_Rehearse_Before_You_Need_It\"><\/span>What to Rehearse Before You Need It<span class=\"ez-toc-section-end\"><\/span><\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Contracts do not run during an outage. People do, and the manual fallback that airports invoked worked precisely because staff knew it existed.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Three things are worth rehearsing rather than documenting. The decision to invoke fallback, including who makes it and how quickly. The manual process itself, with people who have actually performed it. And the communication path to customers, which is where reputational damage gets decided.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">There is also a human-layer exposure inside vendor risk that audits miss entirely. You can review a supplier&#8217;s certifications. You cannot audit their employees&#8217; susceptibility to the social engineering that frequently opens these intrusions.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Threatcop&#8217;s TPIR shortens the reporting path on your own side, so a member of staff who notices something unusual reaches an analyst quickly rather than filing a ticket. Reporting culture sits in <a href=\"https:\/\/threatcop.com\/blog\/what-is-incident-reporting-culture\/\">why employees stay silent about mistakes<\/a>.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\"><span class=\"ez-toc-section\" id=\"Metrics_Worth_Tracking\"><\/span>Metrics Worth Tracking<span class=\"ez-toc-section-end\"><\/span><\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Vendor risk registers usually record assurance. These record exposure.<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>Critical vendors with a rehearsed fallback<\/strong>, as a proportion of all critical vendors<\/li>\n\n\n\n<li><strong>Date each fallback was last exercised<\/strong>, which is usually older than anyone expects<\/li>\n\n\n\n<li><strong>Concentration count<\/strong>, meaning how many critical functions depend on a single provider<\/li>\n\n\n\n<li><strong>Certification scope verified<\/strong>, rather than certification held<\/li>\n\n\n\n<li><strong>Time from vendor incident to internal awareness<\/strong>, measured on real events<\/li>\n\n\n\n<li><strong>Manual-mode capacity<\/strong>, expressed as how long you can operate without the platform<\/li>\n<\/ul>\n\n\n\n<p class=\"wp-block-paragraph\">The last is the number a board grasps immediately. If the answer is four hours and a vendor incident runs four days, that gap is the risk.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\"><span class=\"ez-toc-section\" id=\"Ask_One_Vendor_How_Many_Customers_Share_Your_Platform\"><\/span>Ask One Vendor How Many Customers Share Your Platform<span class=\"ez-toc-section-end\"><\/span><\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Pick the supplier whose failure would stop your operations fastest, then ask how many other customers run on the same instance. Most contracts do not say, and most relationship managers have never been asked.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Next, check when you last ran the manual fallback with real staff rather than reviewing the document. If the answer is never, the plan is a description rather than a capability.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Finally, <a href=\"https:\/\/threatcop.com\/threatcop-phishing-incident-response\">make it easy for your own people to raise something unusual<\/a>, because in a vendor incident your staff often notice the symptoms before the supplier&#8217;s notification arrives.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\"><span class=\"ez-toc-section\" id=\"Frequently_Asked_Questions\"><\/span>Frequently Asked Questions<span class=\"ez-toc-section-end\"><\/span><\/h2>\n\n\n\t\t<div class=\"sp-easy-accordion-block sp-eab-regular-accordion alignwide\"\n\t\t\t\t>\n\t\t\t<div class=\"sp-eab-wrapper sp-eab-vertical-accordion sp-eab-c9bb9a83a19b\">\n\t\t\t\t\t\t\t\t<div class='sp-eab-accordion sp-eab-mode-vertical sp-eab-vertical-one sp-d-flex' data-accordion-settings=\"{&quot;mode&quot;:&quot;vertical&quot;,&quot;activeEvent&quot;:&quot;click&quot;,&quot;defaultAccordionOpen&quot;:&quot;first-item&quot;,&quot;selectedItemOpen&quot;:0,&quot;openMultiItemAtaTime&quot;:false,&quot;scrollToTopOnLoad&quot;:false,&quot;scrollToTopOnClick&quot;:false,&quot;accordionItemToUrl&quot;:false,&quot;animationEffect&quot;:false,&quot;applyAccessibility&quot;:true}\">\n        \t    \t\n\t\t\t<div\n\t\t\t\tid =\"sp-eab-item-bf13d524af04\"\n\t\t\t\tclass=\"sp-eab-accordion-item eab-item-83a19b\"\n\t\t\t\t\t\t\t>\n\t\t\t\t<div class=\"sp-eab-accordion-item-wrapper\">\n\t\t\t\t\t\t\t\t<h3 class='sp-eab-accordion-heading sp-d-flex sp-align-center eab-heading-83a19b'\n\t\t\t\t\t\t>\n\t\t\t\t<span class='sp-eab-accordion-header-wrapper sp-d-flex sp-align-center eab-icon-position-end'>\n\t\t\t\t\t<span class='sp-eab-accordion-header-start sp-d-flex sp-justify-left sp-align-center'>\n\t\t\t\t\t\t<span class='sp-eab-title-subtitle-wrapper sp-d-flex'>\n\t\t\t\t\t\t\t<span class='sp-eab-accordion-title-wrapper sp-d-flex sp-align-center'>\n\t\t\t\t\t\t\t\t<span class='sp-eab-accordion-title-text'>\n\t\t\t\t\t\t\t\t\tWhat happened in the September 2025 European airport cyberattack?\t\t\t\t\t\t\t\t<\/span>\n\t\t\t\t\t\t\t<\/span>\n\t\t\t\t\t\t<\/span>\n\t\t\t\t\t<\/span>\n\t\t\t\t\t<span class='sp-eab-accordion-header-end eab-icon-animated'>\n\t\t\t\t\t\t\t\t\t\t\t\t<span class='sp-eab-expand-collapse-icon sp-d-block'>\n\t\t\t\t\t\t\t<i class='sp-eab-expand-icon eab-icon-angle-down-solid'><\/i>\n\t\t\t\t\t\t\t<i class='sp-eab-collapse-icon eab-icon-angle-up-solid'><\/i>\n\t\t\t\t\t\t<\/span>\n\t\t\t\t\t\t\t\t\t\t\t<\/span>\n\t\t\t\t<\/span>\n\t\t\t<\/h3>\n\t\t\t\t\t\t\t<!-- accordion body -->\n\t\t\t\t\t<div class='sp-eab-accordion-content eab-content-83a19b'>\n\t\t\t\t\t\t\t\t\t\t\t\t<div class='sp-eab-accordion-content-wrapper'>\n\t\t\t\t\t\t\t<div class='sp-eab-accordion-body'>\n\t\t\t    \t\t\t\t\n\n<p class=\"wp-block-paragraph\">On the evening of 19 September 2025, ransomware affected systems supporting Collins Aerospace&#8217;s ARINC vMUSE check-in platform, used by airlines to share desks and boarding gates. Automated passenger processing stopped at Heathrow, Brussels, Berlin Brandenburg, and Dublin, forcing manual check-in and causing hundreds of delays and cancellations across the weekend.<\/p>\n\n\t\t\t\t\t\t\t<\/div>\n\t\t\t\t\t\t<\/div>\n\t\t\t\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t<\/div>\n\t\t\n\n\t\t\t<div\n\t\t\t\tid =\"sp-eab-item-4f391a049c7d\"\n\t\t\t\tclass=\"sp-eab-accordion-item eab-item-83a19b\"\n\t\t\t\t\t\t\t>\n\t\t\t\t<div class=\"sp-eab-accordion-item-wrapper\">\n\t\t\t\t\t\t\t\t<h3 class='sp-eab-accordion-heading sp-d-flex sp-align-center eab-heading-83a19b'\n\t\t\t\t\t\t>\n\t\t\t\t<span class='sp-eab-accordion-header-wrapper sp-d-flex sp-align-center eab-icon-position-end'>\n\t\t\t\t\t<span class='sp-eab-accordion-header-start sp-d-flex sp-justify-left sp-align-center'>\n\t\t\t\t\t\t<span class='sp-eab-title-subtitle-wrapper sp-d-flex'>\n\t\t\t\t\t\t\t<span class='sp-eab-accordion-title-wrapper sp-d-flex sp-align-center'>\n\t\t\t\t\t\t\t\t<span class='sp-eab-accordion-title-text'>\n\t\t\t\t\t\t\t\t\tWas the ransomware variant confirmed?\t\t\t\t\t\t\t\t<\/span>\n\t\t\t\t\t\t\t<\/span>\n\t\t\t\t\t\t<\/span>\n\t\t\t\t\t<\/span>\n\t\t\t\t\t<span class='sp-eab-accordion-header-end eab-icon-animated'>\n\t\t\t\t\t\t\t\t\t\t\t\t<span class='sp-eab-expand-collapse-icon sp-d-block'>\n\t\t\t\t\t\t\t<i class='sp-eab-expand-icon eab-icon-angle-down-solid'><\/i>\n\t\t\t\t\t\t\t<i class='sp-eab-collapse-icon eab-icon-angle-up-solid'><\/i>\n\t\t\t\t\t\t<\/span>\n\t\t\t\t\t\t\t\t\t\t\t<\/span>\n\t\t\t\t<\/span>\n\t\t\t<\/h3>\n\t\t\t\t\t\t\t<!-- accordion body -->\n\t\t\t\t\t<div class='sp-eab-accordion-content eab-content-83a19b'>\n\t\t\t\t\t\t\t\t\t\t\t\t<div class='sp-eab-accordion-content-wrapper'>\n\t\t\t\t\t\t\t<div class='sp-eab-accordion-body'>\n\t\t\t    \t\t\t\t\n\n<p class=\"wp-block-paragraph\">No. ENISA confirmed that ransomware caused the disruption, and RTX confirmed a ransomware incident in an SEC filing, but the specific family was never officially established. Researchers pointed to HardBit while other reporting suggested Loki. The UK National Crime Agency arrested a man in West Sussex under the Computer Misuse Act and later released him on conditional bail.<\/p>\n\n\t\t\t\t\t\t\t<\/div>\n\t\t\t\t\t\t<\/div>\n\t\t\t\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t<\/div>\n\t\t\n\n\t\t\t<div\n\t\t\t\tid =\"sp-eab-item-6c7ccc3122fb\"\n\t\t\t\tclass=\"sp-eab-accordion-item eab-item-83a19b\"\n\t\t\t\t\t\t\t>\n\t\t\t\t<div class=\"sp-eab-accordion-item-wrapper\">\n\t\t\t\t\t\t\t\t<h3 class='sp-eab-accordion-heading sp-d-flex sp-align-center eab-heading-83a19b'\n\t\t\t\t\t\t>\n\t\t\t\t<span class='sp-eab-accordion-header-wrapper sp-d-flex sp-align-center eab-icon-position-end'>\n\t\t\t\t\t<span class='sp-eab-accordion-header-start sp-d-flex sp-justify-left sp-align-center'>\n\t\t\t\t\t\t<span class='sp-eab-title-subtitle-wrapper sp-d-flex'>\n\t\t\t\t\t\t\t<span class='sp-eab-accordion-title-wrapper sp-d-flex sp-align-center'>\n\t\t\t\t\t\t\t\t<span class='sp-eab-accordion-title-text'>\n\t\t\t\t\t\t\t\t\tWhy does cyber insurance not solve ransomware risk?\t\t\t\t\t\t\t\t<\/span>\n\t\t\t\t\t\t\t<\/span>\n\t\t\t\t\t\t<\/span>\n\t\t\t\t\t<\/span>\n\t\t\t\t\t<span class='sp-eab-accordion-header-end eab-icon-animated'>\n\t\t\t\t\t\t\t\t\t\t\t\t<span class='sp-eab-expand-collapse-icon sp-d-block'>\n\t\t\t\t\t\t\t<i class='sp-eab-expand-icon eab-icon-angle-down-solid'><\/i>\n\t\t\t\t\t\t\t<i class='sp-eab-collapse-icon eab-icon-angle-up-solid'><\/i>\n\t\t\t\t\t\t<\/span>\n\t\t\t\t\t\t\t\t\t\t\t<\/span>\n\t\t\t\t<\/span>\n\t\t\t<\/h3>\n\t\t\t\t\t\t\t<!-- accordion body -->\n\t\t\t\t\t<div class='sp-eab-accordion-content eab-content-83a19b'>\n\t\t\t\t\t\t\t\t\t\t\t\t<div class='sp-eab-accordion-content-wrapper'>\n\t\t\t\t\t\t\t<div class='sp-eab-accordion-body'>\n\t\t\t    \t\t\t\t\n\n<p class=\"wp-block-paragraph\">Because insurance transfers financial loss rather than operational disruption, and attackers may factor it in. HardBit became notable for pegging ransom demands to a victim&#8217;s cyber-insurance limits, which makes coverage an input to the attacker&#8217;s pricing rather than a defence. Insurance also cannot restore a service your customers depend on.<\/p>\n\n\t\t\t\t\t\t\t<\/div>\n\t\t\t\t\t\t<\/div>\n\t\t\t\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t<\/div>\n\t\t\n\n\t\t\t<div\n\t\t\t\tid =\"sp-eab-item-4a03da54248b\"\n\t\t\t\tclass=\"sp-eab-accordion-item eab-item-83a19b\"\n\t\t\t\t\t\t\t>\n\t\t\t\t<div class=\"sp-eab-accordion-item-wrapper\">\n\t\t\t\t\t\t\t\t<h3 class='sp-eab-accordion-heading sp-d-flex sp-align-center eab-heading-83a19b'\n\t\t\t\t\t\t>\n\t\t\t\t<span class='sp-eab-accordion-header-wrapper sp-d-flex sp-align-center eab-icon-position-end'>\n\t\t\t\t\t<span class='sp-eab-accordion-header-start sp-d-flex sp-justify-left sp-align-center'>\n\t\t\t\t\t\t<span class='sp-eab-title-subtitle-wrapper sp-d-flex'>\n\t\t\t\t\t\t\t<span class='sp-eab-accordion-title-wrapper sp-d-flex sp-align-center'>\n\t\t\t\t\t\t\t\t<span class='sp-eab-accordion-title-text'>\n\t\t\t\t\t\t\t\t\tHow do you manage third-party ransomware risk?\t\t\t\t\t\t\t\t<\/span>\n\t\t\t\t\t\t\t<\/span>\n\t\t\t\t\t\t<\/span>\n\t\t\t\t\t<\/span>\n\t\t\t\t\t<span class='sp-eab-accordion-header-end eab-icon-animated'>\n\t\t\t\t\t\t\t\t\t\t\t\t<span class='sp-eab-expand-collapse-icon sp-d-block'>\n\t\t\t\t\t\t\t<i class='sp-eab-expand-icon eab-icon-angle-down-solid'><\/i>\n\t\t\t\t\t\t\t<i class='sp-eab-collapse-icon eab-icon-angle-up-solid'><\/i>\n\t\t\t\t\t\t<\/span>\n\t\t\t\t\t\t\t\t\t\t\t<\/span>\n\t\t\t\t<\/span>\n\t\t\t<\/h3>\n\t\t\t\t\t\t\t<!-- accordion body -->\n\t\t\t\t\t<div class='sp-eab-accordion-content eab-content-83a19b'>\n\t\t\t\t\t\t\t\t\t\t\t\t<div class='sp-eab-accordion-content-wrapper'>\n\t\t\t\t\t\t\t<div class='sp-eab-accordion-body'>\n\t\t\t    \t\t\t\t\n\n<p class=\"wp-block-paragraph\">Move from assurance to evidence. Verify that the system you depend on falls inside the vendor&#8217;s certification scope, ask for patch state rather than policy, establish how many customers share the same platform instance, confirm when recovery was last tested, and rehearse your own manual fallback with the people who would run it.<\/p>\n\n\t\t\t\t\t\t\t<\/div>\n\t\t\t\t\t\t<\/div>\n\t\t\t\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t<\/div>\n\t\t\n\n\t\t\t<div\n\t\t\t\tid =\"sp-eab-item-e29b85964d2a\"\n\t\t\t\tclass=\"sp-eab-accordion-item eab-item-83a19b\"\n\t\t\t\t\t\t\t>\n\t\t\t\t<div class=\"sp-eab-accordion-item-wrapper\">\n\t\t\t\t\t\t\t\t<h3 class='sp-eab-accordion-heading sp-d-flex sp-align-center eab-heading-83a19b'\n\t\t\t\t\t\t>\n\t\t\t\t<span class='sp-eab-accordion-header-wrapper sp-d-flex sp-align-center eab-icon-position-end'>\n\t\t\t\t\t<span class='sp-eab-accordion-header-start sp-d-flex sp-justify-left sp-align-center'>\n\t\t\t\t\t\t<span class='sp-eab-title-subtitle-wrapper sp-d-flex'>\n\t\t\t\t\t\t\t<span class='sp-eab-accordion-title-wrapper sp-d-flex sp-align-center'>\n\t\t\t\t\t\t\t\t<span class='sp-eab-accordion-title-text'>\n\t\t\t\t\t\t\t\t\tWhat is concentration risk in vendor management?\t\t\t\t\t\t\t\t<\/span>\n\t\t\t\t\t\t\t<\/span>\n\t\t\t\t\t\t<\/span>\n\t\t\t\t\t<\/span>\n\t\t\t\t\t<span class='sp-eab-accordion-header-end eab-icon-animated'>\n\t\t\t\t\t\t\t\t\t\t\t\t<span class='sp-eab-expand-collapse-icon sp-d-block'>\n\t\t\t\t\t\t\t<i class='sp-eab-expand-icon eab-icon-angle-down-solid'><\/i>\n\t\t\t\t\t\t\t<i class='sp-eab-collapse-icon eab-icon-angle-up-solid'><\/i>\n\t\t\t\t\t\t<\/span>\n\t\t\t\t\t\t\t\t\t\t\t<\/span>\n\t\t\t\t<\/span>\n\t\t\t<\/h3>\n\t\t\t\t\t\t\t<!-- accordion body -->\n\t\t\t\t\t<div class='sp-eab-accordion-content eab-content-83a19b'>\n\t\t\t\t\t\t\t\t\t\t\t\t<div class='sp-eab-accordion-content-wrapper'>\n\t\t\t\t\t\t\t<div class='sp-eab-accordion-body'>\n\t\t\t    \t\t\t\t\n\n<p class=\"wp-block-paragraph\">Concentration risk arises when many organisations, often competitors, depend on one provider for a critical function. Each customer&#8217;s risk register records a single vendor relationship, while none captures that one incident becomes a sector-wide event. The September 2025 airport disruption illustrates it, since no individual airport was breached.<\/p>\n\n\t\t\t\t\t\t\t<\/div>\n\t\t\t\t\t\t<\/div>\n\t\t\t\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t<\/div>\n\t\t\n\t\t\t\t<\/div>\n\t\t\t<\/div>\n\t\t<\/div>\n\t\t","protected":false},"excerpt":{"rendered":"<p>One vendor&#8217;s ransomware stopped four European airports. See what was actually confirmed, why insurance is priced into the attack, and what to rehearse.<\/p>\n","protected":false},"author":19,"featured_media":15408,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[41],"tags":[],"class_list":["post-15405","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-cyber-attacks"],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v28.5 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>Third-Party Ransomware Risk: Your Vendor, Your Outage<\/title>\n<meta name=\"description\" content=\"One vendor&#039;s ransomware stopped four European airports. See what was actually confirmed, why insurance is priced into the attack, and what to rehearse.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/threatcop.com\/blog\/third-party-ransomware-risk\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Third-Party Ransomware Risk: Your Vendor, Your Outage\" \/>\n<meta property=\"og:description\" content=\"One vendor&#039;s ransomware stopped four European airports. See what was actually confirmed, why insurance is priced into the attack, and what to rehearse.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/threatcop.com\/blog\/third-party-ransomware-risk\/\" \/>\n<meta property=\"og:site_name\" content=\"Threatcop\" \/>\n<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/people\/Threatcop\/100083109892339\/\" \/>\n<meta property=\"article:published_time\" content=\"2026-09-21T09:13:18+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2026-09-21T11:09:28+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/threatcop.com\/blog\/wp-content\/uploads\/2026\/09\/Third-Party-Ransomware-Risk-blog-banner.png\" \/>\n\t<meta property=\"og:image:width\" content=\"1280\" \/>\n\t<meta property=\"og:image:height\" content=\"720\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/png\" \/>\n<meta name=\"author\" content=\"Pallavi Verma\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:creator\" content=\"@threatcop\" \/>\n<meta name=\"twitter:site\" content=\"@threatcop\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"Pallavi Verma\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"8 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\\\/\\\/threatcop.com\\\/blog\\\/third-party-ransomware-risk\\\/#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/threatcop.com\\\/blog\\\/third-party-ransomware-risk\\\/\"},\"author\":{\"name\":\"Pallavi Verma\",\"@id\":\"https:\\\/\\\/threatcop.com\\\/blog\\\/#\\\/schema\\\/person\\\/d27272c93727aa42a015e50ee1c12aa6\"},\"headline\":\"Third-Party Ransomware Risk: When Your Vendor&#8217;s Incident Becomes Your Outage\",\"datePublished\":\"2026-09-21T09:13:18+00:00\",\"dateModified\":\"2026-09-21T11:09:28+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/threatcop.com\\\/blog\\\/third-party-ransomware-risk\\\/\"},\"wordCount\":1694,\"commentCount\":0,\"publisher\":{\"@id\":\"https:\\\/\\\/threatcop.com\\\/blog\\\/#organization\"},\"image\":{\"@id\":\"https:\\\/\\\/threatcop.com\\\/blog\\\/third-party-ransomware-risk\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/threatcop.com\\\/blog\\\/wp-content\\\/uploads\\\/2026\\\/09\\\/Third-Party-Ransomware-Risk-blog-banner.png\",\"articleSection\":[\"Cyber Attacks\"],\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"CommentAction\",\"name\":\"Comment\",\"target\":[\"https:\\\/\\\/threatcop.com\\\/blog\\\/third-party-ransomware-risk\\\/#respond\"]}]},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/threatcop.com\\\/blog\\\/third-party-ransomware-risk\\\/\",\"url\":\"https:\\\/\\\/threatcop.com\\\/blog\\\/third-party-ransomware-risk\\\/\",\"name\":\"Third-Party Ransomware Risk: Your Vendor, Your Outage\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/threatcop.com\\\/blog\\\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/threatcop.com\\\/blog\\\/third-party-ransomware-risk\\\/#primaryimage\"},\"image\":{\"@id\":\"https:\\\/\\\/threatcop.com\\\/blog\\\/third-party-ransomware-risk\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/threatcop.com\\\/blog\\\/wp-content\\\/uploads\\\/2026\\\/09\\\/Third-Party-Ransomware-Risk-blog-banner.png\",\"datePublished\":\"2026-09-21T09:13:18+00:00\",\"dateModified\":\"2026-09-21T11:09:28+00:00\",\"description\":\"One vendor's ransomware stopped four European airports. See what was actually confirmed, why insurance is priced into the attack, and what to rehearse.\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/threatcop.com\\\/blog\\\/third-party-ransomware-risk\\\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/threatcop.com\\\/blog\\\/third-party-ransomware-risk\\\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/threatcop.com\\\/blog\\\/third-party-ransomware-risk\\\/#primaryimage\",\"url\":\"https:\\\/\\\/threatcop.com\\\/blog\\\/wp-content\\\/uploads\\\/2026\\\/09\\\/Third-Party-Ransomware-Risk-blog-banner.png\",\"contentUrl\":\"https:\\\/\\\/threatcop.com\\\/blog\\\/wp-content\\\/uploads\\\/2026\\\/09\\\/Third-Party-Ransomware-Risk-blog-banner.png\",\"width\":1280,\"height\":720,\"caption\":\"Threatcop blog banner reading Third-Party Ransomware Risk, Your Vendor's Incident Your Outage, over an abstract branching diagram on a dark navy background\"},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/threatcop.com\\\/blog\\\/third-party-ransomware-risk\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/threatcop.com\\\/blog\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Third-Party Ransomware Risk: When Your Vendor&#8217;s Incident Becomes Your Outage\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/threatcop.com\\\/blog\\\/#website\",\"url\":\"https:\\\/\\\/threatcop.com\\\/blog\\\/\",\"name\":\"Threatcop\",\"description\":\"Cybersecurity Blogs, News, Updates, and Articles\",\"publisher\":{\"@id\":\"https:\\\/\\\/threatcop.com\\\/blog\\\/#organization\"},\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/threatcop.com\\\/blog\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/threatcop.com\\\/blog\\\/#organization\",\"name\":\"Threatcop\",\"url\":\"https:\\\/\\\/threatcop.com\\\/blog\\\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/threatcop.com\\\/blog\\\/#\\\/schema\\\/logo\\\/image\\\/\",\"url\":\"https:\\\/\\\/threatcop.com\\\/blog\\\/wp-content\\\/uploads\\\/2026\\\/08\\\/threatcop-logo-black-1.png\",\"contentUrl\":\"https:\\\/\\\/threatcop.com\\\/blog\\\/wp-content\\\/uploads\\\/2026\\\/08\\\/threatcop-logo-black-1.png\",\"width\":432,\"height\":102,\"caption\":\"Threatcop\"},\"image\":{\"@id\":\"https:\\\/\\\/threatcop.com\\\/blog\\\/#\\\/schema\\\/logo\\\/image\\\/\"},\"sameAs\":[\"https:\\\/\\\/www.facebook.com\\\/people\\\/Threatcop\\\/100083109892339\\\/\",\"https:\\\/\\\/x.com\\\/threatcop\",\"https:\\\/\\\/www.linkedin.com\\\/company\\\/threatcop\\\/\",\"https:\\\/\\\/www.instagram.com\\\/threatcop_official\\\/\"]},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/threatcop.com\\\/blog\\\/#\\\/schema\\\/person\\\/d27272c93727aa42a015e50ee1c12aa6\",\"name\":\"Pallavi Verma\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/threatcop.com\\\/blog\\\/wp-content\\\/uploads\\\/2025\\\/08\\\/avatar_user_19_1755866814.png\",\"url\":\"https:\\\/\\\/threatcop.com\\\/blog\\\/wp-content\\\/uploads\\\/2025\\\/08\\\/avatar_user_19_1755866814.png\",\"contentUrl\":\"https:\\\/\\\/threatcop.com\\\/blog\\\/wp-content\\\/uploads\\\/2025\\\/08\\\/avatar_user_19_1755866814.png\",\"caption\":\"Pallavi Verma\"},\"description\":\"Pallavi Verma is a Partner Success Specialist at Threatcop, helping organizations strengthen their People Security Management programs. She works closely with clients and partners to reduce human-layer risk, improve security awareness, and ensure employees are equipped to make safer decisions every day. Pallavi is passionate about making cybersecurity practical, measurable, and people-friendly\",\"sameAs\":[\"https:\\\/\\\/threatcop.com\\\/\",\"https:\\\/\\\/www.linkedin.com\\\/in\\\/pallavi-verma-238809229\\\/\"]}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"Third-Party Ransomware Risk: Your Vendor, Your Outage","description":"One vendor's ransomware stopped four European airports. See what was actually confirmed, why insurance is priced into the attack, and what to rehearse.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/threatcop.com\/blog\/third-party-ransomware-risk\/","og_locale":"en_US","og_type":"article","og_title":"Third-Party Ransomware Risk: Your Vendor, Your Outage","og_description":"One vendor's ransomware stopped four European airports. See what was actually confirmed, why insurance is priced into the attack, and what to rehearse.","og_url":"https:\/\/threatcop.com\/blog\/third-party-ransomware-risk\/","og_site_name":"Threatcop","article_publisher":"https:\/\/www.facebook.com\/people\/Threatcop\/100083109892339\/","article_published_time":"2026-09-21T09:13:18+00:00","article_modified_time":"2026-09-21T11:09:28+00:00","og_image":[{"width":1280,"height":720,"url":"https:\/\/threatcop.com\/blog\/wp-content\/uploads\/2026\/09\/Third-Party-Ransomware-Risk-blog-banner.png","type":"image\/png"}],"author":"Pallavi Verma","twitter_card":"summary_large_image","twitter_creator":"@threatcop","twitter_site":"@threatcop","twitter_misc":{"Written by":"Pallavi Verma","Est. reading time":"8 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/threatcop.com\/blog\/third-party-ransomware-risk\/#article","isPartOf":{"@id":"https:\/\/threatcop.com\/blog\/third-party-ransomware-risk\/"},"author":{"name":"Pallavi Verma","@id":"https:\/\/threatcop.com\/blog\/#\/schema\/person\/d27272c93727aa42a015e50ee1c12aa6"},"headline":"Third-Party Ransomware Risk: When Your Vendor&#8217;s Incident Becomes Your Outage","datePublished":"2026-09-21T09:13:18+00:00","dateModified":"2026-09-21T11:09:28+00:00","mainEntityOfPage":{"@id":"https:\/\/threatcop.com\/blog\/third-party-ransomware-risk\/"},"wordCount":1694,"commentCount":0,"publisher":{"@id":"https:\/\/threatcop.com\/blog\/#organization"},"image":{"@id":"https:\/\/threatcop.com\/blog\/third-party-ransomware-risk\/#primaryimage"},"thumbnailUrl":"https:\/\/threatcop.com\/blog\/wp-content\/uploads\/2026\/09\/Third-Party-Ransomware-Risk-blog-banner.png","articleSection":["Cyber Attacks"],"inLanguage":"en-US","potentialAction":[{"@type":"CommentAction","name":"Comment","target":["https:\/\/threatcop.com\/blog\/third-party-ransomware-risk\/#respond"]}]},{"@type":"WebPage","@id":"https:\/\/threatcop.com\/blog\/third-party-ransomware-risk\/","url":"https:\/\/threatcop.com\/blog\/third-party-ransomware-risk\/","name":"Third-Party Ransomware Risk: Your Vendor, Your Outage","isPartOf":{"@id":"https:\/\/threatcop.com\/blog\/#website"},"primaryImageOfPage":{"@id":"https:\/\/threatcop.com\/blog\/third-party-ransomware-risk\/#primaryimage"},"image":{"@id":"https:\/\/threatcop.com\/blog\/third-party-ransomware-risk\/#primaryimage"},"thumbnailUrl":"https:\/\/threatcop.com\/blog\/wp-content\/uploads\/2026\/09\/Third-Party-Ransomware-Risk-blog-banner.png","datePublished":"2026-09-21T09:13:18+00:00","dateModified":"2026-09-21T11:09:28+00:00","description":"One vendor's ransomware stopped four European airports. See what was actually confirmed, why insurance is priced into the attack, and what to rehearse.","breadcrumb":{"@id":"https:\/\/threatcop.com\/blog\/third-party-ransomware-risk\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/threatcop.com\/blog\/third-party-ransomware-risk\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/threatcop.com\/blog\/third-party-ransomware-risk\/#primaryimage","url":"https:\/\/threatcop.com\/blog\/wp-content\/uploads\/2026\/09\/Third-Party-Ransomware-Risk-blog-banner.png","contentUrl":"https:\/\/threatcop.com\/blog\/wp-content\/uploads\/2026\/09\/Third-Party-Ransomware-Risk-blog-banner.png","width":1280,"height":720,"caption":"Threatcop blog banner reading Third-Party Ransomware Risk, Your Vendor's Incident Your Outage, over an abstract branching diagram on a dark navy background"},{"@type":"BreadcrumbList","@id":"https:\/\/threatcop.com\/blog\/third-party-ransomware-risk\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/threatcop.com\/blog\/"},{"@type":"ListItem","position":2,"name":"Third-Party Ransomware Risk: When Your Vendor&#8217;s Incident Becomes Your Outage"}]},{"@type":"WebSite","@id":"https:\/\/threatcop.com\/blog\/#website","url":"https:\/\/threatcop.com\/blog\/","name":"Threatcop","description":"Cybersecurity Blogs, News, Updates, and Articles","publisher":{"@id":"https:\/\/threatcop.com\/blog\/#organization"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/threatcop.com\/blog\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/threatcop.com\/blog\/#organization","name":"Threatcop","url":"https:\/\/threatcop.com\/blog\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/threatcop.com\/blog\/#\/schema\/logo\/image\/","url":"https:\/\/threatcop.com\/blog\/wp-content\/uploads\/2026\/08\/threatcop-logo-black-1.png","contentUrl":"https:\/\/threatcop.com\/blog\/wp-content\/uploads\/2026\/08\/threatcop-logo-black-1.png","width":432,"height":102,"caption":"Threatcop"},"image":{"@id":"https:\/\/threatcop.com\/blog\/#\/schema\/logo\/image\/"},"sameAs":["https:\/\/www.facebook.com\/people\/Threatcop\/100083109892339\/","https:\/\/x.com\/threatcop","https:\/\/www.linkedin.com\/company\/threatcop\/","https:\/\/www.instagram.com\/threatcop_official\/"]},{"@type":"Person","@id":"https:\/\/threatcop.com\/blog\/#\/schema\/person\/d27272c93727aa42a015e50ee1c12aa6","name":"Pallavi Verma","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/threatcop.com\/blog\/wp-content\/uploads\/2025\/08\/avatar_user_19_1755866814.png","url":"https:\/\/threatcop.com\/blog\/wp-content\/uploads\/2025\/08\/avatar_user_19_1755866814.png","contentUrl":"https:\/\/threatcop.com\/blog\/wp-content\/uploads\/2025\/08\/avatar_user_19_1755866814.png","caption":"Pallavi Verma"},"description":"Pallavi Verma is a Partner Success Specialist at Threatcop, helping organizations strengthen their People Security Management programs. She works closely with clients and partners to reduce human-layer risk, improve security awareness, and ensure employees are equipped to make safer decisions every day. Pallavi is passionate about making cybersecurity practical, measurable, and people-friendly","sameAs":["https:\/\/threatcop.com\/","https:\/\/www.linkedin.com\/in\/pallavi-verma-238809229\/"]}]}},"_links":{"self":[{"href":"https:\/\/threatcop.com\/blog\/wp-json\/wp\/v2\/posts\/15405","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/threatcop.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/threatcop.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/threatcop.com\/blog\/wp-json\/wp\/v2\/users\/19"}],"replies":[{"embeddable":true,"href":"https:\/\/threatcop.com\/blog\/wp-json\/wp\/v2\/comments?post=15405"}],"version-history":[{"count":1,"href":"https:\/\/threatcop.com\/blog\/wp-json\/wp\/v2\/posts\/15405\/revisions"}],"predecessor-version":[{"id":15410,"href":"https:\/\/threatcop.com\/blog\/wp-json\/wp\/v2\/posts\/15405\/revisions\/15410"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/threatcop.com\/blog\/wp-json\/wp\/v2\/media\/15408"}],"wp:attachment":[{"href":"https:\/\/threatcop.com\/blog\/wp-json\/wp\/v2\/media?parent=15405"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/threatcop.com\/blog\/wp-json\/wp\/v2\/categories?post=15405"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/threatcop.com\/blog\/wp-json\/wp\/v2\/tags?post=15405"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}