What the 2023 Business Registration Surge Tells Us About Emerging Market Risks for Security Leaders

What the 2023 Business Registration Surge Tells Us About Emerging Market Risks for Security Leaders

There’s a particular kind of unease that settles in when a procurement email lands in your inbox with a vendor name you’ve never seen before, an LLC formed six months ago, and a pitch deck that looks like it was assembled over a weekend. I felt that unease a lot more in 2023 than in any prior year I can remember. And I don’t think that’s coincidence.

According to the U.S. Census Bureau’s Business Formation Statistics, applications for new employer identification numbers — a reliable proxy for new business entity formation — remained historically elevated through 2023, continuing a trend that began sharply in 2020. Certain states saw particularly dense registration activity. Florida, for instance, processed hundreds of thousands of new entity filings through the Division of Corporations, with counties like Broward and Collier seeing consistent upticks in LLCs and professional service firms. That’s Fort Lauderdale and Naples territory, and it matters because those markets feed directly into enterprise supply chains across healthcare, logistics, real estate services, and IT consulting. New entities emerge, pitch contracts, and land on approved vendor lists before anyone has had a proper look at them.

For a chief security officer or corporate security director, this isn’t an abstract trend. It’s a daily operational problem. The question isn’t whether your organization will encounter a vendor formed within the last twelve to twenty-four months — it will, repeatedly. The question is whether your vetting process was designed for that reality or for a world where your major suppliers had twenty years of auditable history behind them.

Why Shallow History Is a Structural Risk, Not Just a Red Flag

Most enterprise vendor risk frameworks were built around the assumption that a legitimate company leaves a trail. Credit history, litigation records, regulatory filings, news coverage, verifiable customer references — these are the signals that conventional due diligence aggregates into a risk score. A company registered in late 2022 or 2023 simply hasn’t had time to accumulate that trail, which means your standard scoring model returns something close to a neutral result. Neutral is not the same as safe. It means the model doesn’t have enough information to flag anything, and that absence of signal gets misread as a clean bill of health.

This is the structural problem that the 2023 registration surge has made harder to ignore. When you have a modest number of young companies entering your vendor pipeline in a given year, the gaps in their history are manageable. You make some calls, you ask for references, you maybe require a smaller initial contract scope. When the number of new entities is large enough to stress your procurement and security teams simultaneously, those workarounds collapse. The informal compensating controls that kept things manageable in a slower market simply don’t scale.

I’ve watched this play out in a specific and recurring pattern. A regional IT services firm, incorporated in Florida in early 2023, wins a subcontract through a prime vendor your organization has trusted for years. The prime vendor did its own vetting, which was superficial because the subcontractor came recommended by a shared contact. Your team never sees the subcontractor’s name until an incident response engagement reveals they had access to a shared environment. The chain of custody for that access was never clearly documented. That scenario isn’t hypothetical — versions of it have appeared in breach disclosures and post-incident reports with enough regularity that it should be considered a pattern, not an anomaly.

The SolarWinds breach, which the Cybersecurity and Infrastructure Security Agency documented extensively, demonstrated how deeply a single compromised vendor relationship can propagate through an enterprise. That vendor had a long history. The risk with newly registered entities is different in character but potentially worse in practice: you don’t even have the false comfort of longevity to lean on.

What a Practical Vetting Adjustment Actually Looks Like

The answer isn’t to refuse to work with young companies. That would eliminate a meaningful portion of the innovative vendor market and create its own procurement problems. The answer is to adjust what you look for when conventional signals are thin on the ground.

Start with beneficial ownership. The Corporate Transparency Act, which took effect for most new entities on January 1, 2024, now requires companies formed after that date to file beneficial ownership information with FinCEN. For entities formed in 2023 — which is the cohort we’re most concerned about — the deadline for compliance fell in early 2025. That filing record, or its absence, is itself a data point. A company that was formed in mid-2023, pitched you a contract in late 2024, and has not filed its beneficial ownership information has already given you something concrete to work with. Ownership transparency is a minimum threshold, not a differentiator.

Next, cross-reference state registration data against what the company claims about itself. Business registration records are public in Florida and most other states, and they tell you things that a pitch deck won’t: registered agent identity, whether the company has changed its name, how many prior entities share the same registered agent address, and whether there are any administrative dissolution actions in the history. For security leaders who want to do this kind of cross-referential research at scale, aggregated 2023 business entity filings can surface patterns that individual state lookups would miss — particularly useful when a vendor claims a multi-state footprint that doesn’t hold up under scrutiny.

The third adjustment is about velocity. If a company was incorporated in January 2023 and is already claiming enterprise clients in five verticals by December of the same year, that growth trajectory deserves scrutiny. Legitimate high-growth firms exist, but their growth leaves evidence: job postings, LinkedIn headcount changes, press coverage, contract announcements. A company that claims rapid scale without that evidence trail is either misrepresenting its size or operating in a way that deliberately minimizes its public footprint. Either possibility warrants a harder conversation before you extend any access.

There’s also a relational dimension that security frameworks tend to undervalue. The people behind a new entity are often more knowable than the entity itself. A company formed in 2023 with principals who have fifteen years of verifiable industry history, prior entity registrations you can trace, and professional references you can actually call presents a very different risk profile than one where the principals are difficult to locate independently. Ownership history follows people across entity formations, and a CSO who builds the habit of looking at founders rather than just companies will catch things that document-based screening misses entirely.

None of this is a perfect system. New entities can be legitimate, well-run, and low-risk. Old entities can be hollowed out, compromised, or operating under changed ownership that your records haven’t caught up with. What the 2023 registration surge should do for corporate security risk management is reset the default assumption. The default should not be that a vendor is safe until proven otherwise. It should be that every vendor relationship carries inherent uncertainty, and the younger the entity, the more actively you need to construct the picture that their history hasn’t yet painted for you.

The volume of new business entity vetting requests isn’t going to slow down. The market created a lot of new companies in 2023, and those companies are now old enough to be winning real contracts. Security leaders who built their processes for a different market are going to feel that friction. The ones who adapted their frameworks to treat thin history as a specific risk category — not an absence of risk — are going to be in a substantially better position when the next incident report crosses their desk.