Third-party vendors have quietly become one of the most critical parts of the modern enterprise, and one of the least well-defended.
From SaaS platforms and payment processors to niche service providers, large organizations now run on thousands of external vendors. Gartner reports that 60% of companies rely on more than 1,000 third parties, each with some level of access to internal systems and data. A McKinsey report shows nearly one-third of recent cyber breaches originate from those third parties.
Despite this, most third-party risk is still managed with spreadsheets, one-off questionnaires, and point-in-time compliance checks. On paper, the boxes are ticked. In practice, enterprises are blind to how vendors actually behave inside their environment, what they can reach, and how that exposure changes over time.
Lema was founded to change that.
Lema is building an agentic AI security platform that transforms TPRM teams from compliance auditors into Risk Engineers, empowering them to treat third-party risk as a core security problem. The company has emerged from stealth with $24M in funding, led by Team8, and is already trusted by Fortune 500 customers in sectors like financial services and healthcare.
We see Lema the only platform to seriously answer a simple question:
What is the real vendor attack surface inside the enterprise, and how do you continuously secure it?
Third-party risk is a security problem, not a questionnaire
Most organizations approach third-party risk through a compliance lens. Vendors complete security questionnaires. Certifications are reviewed. Risk scores are assigned. The process is largely manual, slow, and static.
The problem is that checklists don’t catch risks. None of this reflects what matters most: what the vendor can actually do in your environment.
Vendors may be “external” in legal and contractual terms, but operationally they often look like insiders. They connect to production data stores, payment systems, identity providers, support tools, and internal APIs. A single compromise in the wrong vendor can quickly become an enterprise-wide incident.
This discrepancy between process and reality shows up in very specific ways: a vendor’s assessment can look clean on paper, but over time their permissions and integrations quietly expand far beyond what was originally scoped; a compromise in one environment can end up exposing multiple business units or regions because of shared access patterns; and when something does go wrong, security teams often cannot say with confidence how many critical assets depend on that vendor, or what the real blast radius of a breach would be.
Team8’s own CISO Village survey has consistently shown third-party risk management among the top three innovation priorities for CISOs, yet most organizations are still defending this expanding perimeter with static forms and annual reviews. The result is predictable: blind spots, slow response, and high-impact incidents when a vendor fails.
Lema’s starting point is straightforward: if third-party risk is one of the largest and fastest-growing attack surfaces in the enterprise, it has to be treated with the same rigor as any other security domain - continuous visibility, attack-path thinking, and automation that reflects reality, not just policy.
Lema’s approach: agentic AI for the vendor attack surface
Lema’s platform is powered by an AI agent trained to think like a vulnerability researcher. The goal is not to automate more forms; it is to replace checklist-driven assessments with continuous forensic analysis of how vendors actually interact with the enterprise.
Instead of stopping at “Does this vendor have ISO/SOC2?”, Lema asks:
- What internal systems does this vendor really touch?
- How does data move between the vendor and the enterprise over time?
- Which permissions, identities, and integrations define this vendor’s potential blast radius?
- What realistic attack paths could an attacker exploit through this vendor?
To answer these questions, Lema monitors vendor behavior continuously. It tracks vendor access to critical assets, observes data movement, and evaluates permission changes as they happen. By combining this telemetry with its agentic AI, the platform builds and maintains an up-to-date model of the vendor attack surface inside the enterprise.
On top of that model, Lema prioritizes risk: it identifies which vendors pose the greatest threat, why they are risky, and what specific mitigation steps can reduce that exposure. This moves third-party risk from abstract scores to concrete, actionable insights that security teams can act on.
A key outcome of this approach is speed. Because Lema focuses on mapping actual access and potential attack paths, it can help enterprises assess a new vendor in under five minutes, based on how that vendor would really interact with their environment, not just on what a questionnaire says.
As CEO and Co-Founder Eddie Dovzhik puts it:
“We founded Lema because third-party risk needs to be treated like a security problem, not a compliance checklist. The industry is relying on manual assessments that miss the real-time business context and impact third parties have on the organization. We built Lema to think like an elite security researcher, transforming TPRM teams from compliance auditors into Risk Engineers who reveal the risks that genuinely threaten your business, and deliver the exact steps to shut them down."
This is what we found compelling: Lema links third-party behavior directly to business-critical assets, turning third-party risk from a static compliance artifact into a dynamic, attack-surface view.
Why now: supply chains as the new perimeter
Two macro trends make Lema’s timing especially important.
First, the scale and centrality of vendors has changed. Where third-party tools used to be add-ons, they are now the operational core of many enterprises. Payment platforms, CRM systems, collaboration tools, and SaaS applications are not “dependencies” in the abstract; they are where the work happens. As the PR notes, 60% of companies rely on more than 1,000 external vendors.
Second, the threat data is unambiguous. McKinsey’s finding that roughly one-third of cyber breaches now originate from third parties is not a theoretical warning; it is a backward-looking observation. The damage is already happening.
Yet the dominant model for managing this risk has barely evolved. Organizations still rely on static questionnaires, point-in-time attestations, and manual review cycles that were designed for a different era—when vendors were fewer, more isolated, and less deeply integrated.
At Team8, we spend a lot of time with CISOs through our CISO Village community. Third-party risk comes up again and again as a top concern:
- They know the numbers.
- They see the complexity in their own vendor landscapes.
- They recognize that their current processes are inadequate.
What has been missing is a platform that approaches third-party risk the way modern security teams think about the rest of their environment: mapping attack paths, monitoring behavior, and continuously updating the picture as reality changes.
Lema is the first company we’ve seen that applies agentic AI and forensic analysis directly to this problem at enterprise scale.
The founders
Lema was founded in 2023 by Eddie Dovzhik (CEO), Omer Yehudai (CPO), and Tomer Roizman (CTO) with a clear objective: close the security gap left by compliance-first third-party risk tools.
The founding team comes from a background of security research and building systems that look at real behavior rather than static declarations. Lema’s platform was “built by elite security researchers to think like an elite security researcher,” and you can see that mindset in both the product design and the early customer base: large, regulated enterprises in financial services, healthcare, and the Fortune 500 that cannot afford to treat third-party incidents as edge cases.
From our earliest conversations, what stood out was their insistence on tying risk to concrete attack paths and business impact, not just vendor questionnaires and generic scores. That alignment between how modern defenders think and how Lema’s system models risk was a strong signal for us.
Looking ahead
Lema’s $24M in funding will be used to accelerate R&D for its autonomous vendor risk analysis engine and to expand go-to-market efforts with highly regulated, digitally driven enterprises. The platform is already in use with major customers across industries, and demand is rising as boards and regulators push for clearer, more operational answers on third-party risk.
In our view, Lema is the first of a new generation of third-party security platforms:
- focused on behavior, not forms
- powered by agentic AI that thinks like a researcher, not a workflow engine
- and grounded in a continuous, forensic view of how vendors affect the enterprise attack surface
Third-party risk is not going away; it will only grow as supply chains become more interconnected and software ecosystems more dense. The organizations that handle it well will be those that stop treating vendors as boxes on a spreadsheet and start treating them as part of their dynamic security perimeter.
That is the future Lema is building toward. We’re proud to lead their Series A and to support the team as they redefine how enterprises secure their extended ecosystem.
Co-Founder & Managing Partner
Liran Grinberg is the Co-founder and Managing Partner of Team8, where he invests in Cyber and Software Infra companies.