.png)
Over half of survey respondents suffered an IT security incident in last two years due to flawed third-party software and services
New York, NY, February 2, 2023 – The pandemic rush to cloud computing proved costly for organizations who experienced a security incident stemming from vulnerabilities in their third-party relationships, according to new research from CyberRisk Alliance Business Intelligence, the research and content arm of cybersecurity data and insights company CyberRisk Alliance.
Sponsored by AuditBoard, the January Cybersecurity Buyer Intelligence Research report draws on responses from over 200 security and IT executives and leaders, security administrators, and compliance professionals across the United States. Many respondents indicated that their organizations’ increased dependencies on vendors and other partners such as manufacturers, suppliers, and sub-contractors, as well as increasingly complex supply chains, have vastly elevated their exposure to attacks due to the lack of visibility into third and fourth-party partners (i.e., their vendors’ partners) and the scope of data accessible to them.
“We use more third parties for services throughout the enterprise, and vulnerabilities for data, security and performance are even more visible and critical,” said one survey respondent who cited the uncertainty around “downstream data processing in these third-party vendors.”
Despite increased awareness and more demands to secure third parties, respondents stated that simply getting a third-party vendor or partner to implement good security controls can be a formidable challenge. When a third-party breach did occur, respondents said they didn’t always receive timely notifications from their vendor or partner, limiting their ability to proactively notify customers and other stakeholders.
Organizations recognize that they must adopt a comprehensive risk appetite when they work with vendors and other partners and put greater pressure on third parties to respond to questionnaires about their security practices.
Key takeaways from the survey:
Some respondents noted plans to advance their third-party programs beyond the basics in the next 12 months, investing in human resources and technology to bolster their programs.
The full research report is available for download here.
About CyberRisk Alliance
CyberRisk Alliance (CRA) is a business intelligence company serving the high growth, rapidly evolving cybersecurity community with a diversified portfolio of services that inform, educate, build community, and inspire an efficient marketplace. Our trusted information leverages a unique network of journalists, analysts and influencers, policymakers, and practitioners. CRA’s brands include SC Media, Security Weekly, ChannelE2E, MSSP Alert, InfoSec World, Identiverse, Cybersecurity Collaboration Forum, its research unit CRA Business Intelligence, the peer-to-peer CISO membership network, Cybersecurity Collaborative, and now, the Official Cyber Security Summit and TECHEXPO Top Secret. Click here to learn more.
About AuditBoard
AuditBoard is the leading cloud-based platform transforming audit, risk, and compliance management. More than 35% of the Fortune 500 leverage AuditBoard to move their businesses forward with greater clarity and agility. AuditBoard is top-rated by customers on G2, Capterra, and Gartner Peer Insights, and was recently ranked for the fourth year in a row as one of the fastest-growing technology companies in North America by Deloitte. To learn more, visit: AuditBoard.com.