Third-party access is still the front door.
Another month, another run of breaches through a supplier. The lesson runs both ways: to the company exposed and the vendor selling the fix.

It happened again in June. Large companies breached through a vendor rather than through their own systems. Intrusions that arrive by way of suppliers are among the most dependable patterns in the field, and the breach reports have said so for years.
Awareness has never been the gap. Everyone knows. The trouble is that third-party risk gets handled as paperwork, and paperwork has never stopped an attack anyone could see coming.
If you own the risk.
The questionnaire in your files is not the same as control. Find the standing privileged access your vendors hold right now, look at the map of who can reach into your environment, and treat that picture as the real assessment. Buy the control, not another form.
If you sell the control.
Move the conversation from assessing vendors to controlling what vendors can reach. Name the breach keeping the buyer up, show the access map they have never actually seen, and point at a breach in the news to say plainly, this is the path it took.
Everyone admits third-party risk is real. Almost no one believes anything they buy will change it. That belief is the whole conversation.
When a risk is this widely admitted and this widely ignored, the wall is a quiet doubt that anything will fix it. Buyers get past it by demanding proof of control, and vendors get past it by showing it. Same wall, two sides.