Third-party risk management has always depended on trust. Organizations trust vendors to follow the security requirements written into contracts, answer assessments accurately, and maintain the controls they say are in place. But the recent breach involving hardware wallet manufacturer Trezor and fulfillment provider ShipMonk is a reminder that trust alone is not a control.