Business Wire

SecurityScorecard Research Shows 98% of Organizations Globally Have Relationships With At Least One Breached Third-Party

Share

SecurityScorecard, the global leader in cybersecurity ratings, and The Cyentia Institute, an independent cybersecurity research firm, today published research that found 98 percent of organizations have vendor relationships with at least one third-party that has experienced a breach in the last two years. The study, Close Encounters of the Third (and Fourth) Party Kind , also found that 50 percent of organizations have indirect relationships with at least 200 breached fourth-party vendors in the last two years.

“An organizations’ attack surface spans beyond just the technology that they own or control, ” said Aleksandr Yampolskiy, co-founder and CEO of SecurityScorecard. “Organizations need visibility into the security ratings of their entire third and fourth party ecosystem so that they can know in an instant whether an organization deserves their trust and can take proactive steps to mitigate risk.”

The study, which analyzed data from over 235,000 (primary) organizations across the globe and more than 73,000 vendors and products used by them directly (third-parties) or used by their vendors (fourth-parties), offers an in-depth examination of how the interdependence of modern digital supply chains impacts organizational cyber risk exposure.

Key Report Findings:

  • Security Suffers The More Third- and Fourth-Parties You Have
    For every third-party vendor in their supply chain, organizations typically have indirect relationships with 60 to 90 times that number of fourth-party relationships. Research showed that compared to the primary organization, third-party vendors are five times more likely to exhibit poor security. Approximately 10% of third-party vendors receive an F rating among organizations that earn an A rating for their own security posture.
  • Information Services Leads in Third-parties
    The research revealed the Information Services sector maintained an average of 25 vendors-- 2.5 times the number of third party-relationships than the overall average of 10. The Finance sector was on the other end of the spectrum averaging 6.5 third-party relationships. The healthcare sector averaged 15.5 vendors per organization and the Insurance sector averaged 11 vendors. “Each of these third-party relations represents exposure to risk,” continued Baker. “In some cases due to compromised third-party code, or in others due to usage of an insecure hosting provider.”
  • Exposing Data to International Third-parties Increases Regulatory and Security Requirements
    While examining the regional dimension of third-party relationships, SecurityScorecard found that 59% of organizations have vendors from five or fewer countries, while roughly 14% work with vendors spanning 10 or more countries.

“SecurityScorecard’s data demonstrates why managing cyber risk across the digital supply chain is absolutely critical as threat actors work to exploit any vulnerabilities an organization may have. Identifying and continuously monitoring all partners and customers within the digital supply chain is key to staying ahead of any potential risk,” said Wade Baker, partner and co-founder at The Cyentia Institute. “By having full visibility into the security posture of their third and fourth parties, organizations can work with their vendors to address any cybersecurity gaps they may have in their infrastructure and, in turn, reduce their own level of cyber risk.”

Additional resources:

  • Access the full report, “Close Encounters of the Third (and Fourth) Party Kind”
  • Read our blog to better understand what can organizations do to minimize risk stemming from their business ecosystems
  • Register for the informational webinar, presented by SecurityScorecard and the Cyentia Institute.
  • Learn more about how Automatic Vendor Detection enables organizations to identify the products and vendors in their third- and fourth-party ecosystem to identify potential risk, automate their workflows, and drive targeted data-driven decisions.

About SecurityScorecard

Funded by world-class investors including Evolution Equity Partners, Silver Lake Waterman, Sequoia Capital, GV, Riverwood Capital, and others, SecurityScorecard is the global leader in cybersecurity ratings with more than 12 million companies continuously rated. Founded in 2013 by security and risk experts Dr. Aleksandr Yampolskiy and Sam Kassoumeh, SecurityScorecard's patented rating technology is used by over 30,000 organizations for enterprise risk management, third-party risk management, board reporting, due diligence, cyber insurance underwriting, and regulatory oversight. SecurityScorecard is the first cybersecurity ratings company to offer digital forensics and incident response services, providing a 360-degree approach to security prevention and response for its worldwide customer and partner base. SecurityScorecard continues to make the world a safer place by transforming the way companies understand, improve and communicate cybersecurity risk to their boards, employees and vendors. Every organization has the universal right to their trusted and transparent Instant SecurityScorecard rating. For more information, visit securityscorecard.com or connect with us on LinkedIn.

About The Cyentia Institute

The Cyentia Institute is a research and data science firm working to advance cybersecurity knowledge and practice. Cyentia pursues this goal through data-driven studies like this one and through a growing portfolio of analytic services. Learn more at www.cyentia.com.

To view this piece of content from cts.businesswire.com, please give your consent at the top of this page.

Contact information

Derek Delano
SecurityScorecard
ddelano@securityscorecard.io
(646) 457-4513

About Business Wire

For more than 50 years, Business Wire has been the global leader in press release distribution and regulatory disclosure.

Subscribe to releases from Business Wire

Subscribe to all the latest releases from Business Wire by registering your e-mail address below. You can unsubscribe at any time.

Latest releases from Business Wire

Ex- DocuSign, Oracle Leader Appointed to 6sense Senior Vice President of GTM International6.5.2024 11:00:00 EEST | Press release

6sense®, the leading platform to revolutionize the way B2B organizations create, manage, and convert pipeline to revenue, today announced the recent appointment of Andy Champion as Senior Vice President of GTM International. Champion’s impressive background brings over three decades of highly relevant experience to the organization which includes sales and marketing expertise at high growth, globally focused, private and public companies. “Andy’s track record of scaling organizations, both in headcount and revenue, will be instrumental in our global growth plans,” said Mark Ebert, SVP of Sales at 6sense. "But he also carries with him a unique ability to foster and develop both a fun and high-performing team culture. With a new London office space opening soon, I am incredibly excited for this next chapter for 6sense." The announcement highlights 6sense’s growing influence in the B2B sales and marketing landscape, with continued expansion efforts into new geographies and verticals servi

Kindeva Drug Delivery Invests in Second Manufacturing Line for Greener Inhalers at UK Manufacturing Site6.5.2024 10:00:00 EEST | Press release

Kindeva Drug Delivery (Kindeva), a global leader in drug-device combination products, today announced its investment in a second manufacturing line for the production of pressurized metered-dose inhaler (pMDI) products containing low-GWP (Global Warming Potential) propellants in its Loughborough, U.K., facility. This new line will be capable of handling both HFA-152a and HFO-1234ze propellants — that have a GWP of 90% and 99.9% lower than the industry standard HFA-134a, respectively — and is anticipated to be operational in 2026. Kindeva’s first pMDI manufacturing line, which was announced in 2022, is in its installation phase and will be completed later in 2024. Milton Boyer, Kindeva’s CEO said: “This investment will bring to the market one of the first large-volume commercial green propellant lines to the contract manufacturing market capable of supplying up to 50 million pMDI units per year. This second investment in low-GWP GMP manufacturing capacity further underscores Kindeva’s c

INRED and SES to Provide High-Throughput Connectivity Across Colombia’s Amazonas6.5.2024 09:50:00 EEST | Press release

Following a series of successful collaborations to close the digital divide, Colombian local connectivity service provider INRED and SES will deliver high-throughput connectivity services via SES’s Medium Earth Orbit (MEO) satellites to more than 500 homes, schools, government entities, and thousands of habitants in the department of Amazonas, both companies announced today. With the aim of supporting the Colombian government’s efforts to connect remote and hard-to-reach locations under the Amazonas Digital initiative, INRED is leveraging SES’s MEO satellites to connect the city of Leticia and other rural areas in Amazonas. SES’s MEO satellites, which orbit at 8,000 km above the Earth’s surface, will play a major role in complementing the government’s digital inclusion initiatives to deliver connectivity to even the most hard-to-reach regions in the country, ensuring people and businesses in these areas have equal access to social and economic opportunities. “Having a long-term partner

SES to acquire Intelsat: Investor Relations Frequently Asked Questions6.5.2024 09:00:00 EEST | Press release

SES S.A.: 1) What is the rationale of the transaction? What is the benefit for SES shareholders? This combination creates a stronger and more competitive multi-orbit operator with expanded network, increased revenue in highly valuable and growth segments, stronger financial profile, and greater ability to invest in the future to better compete in a dynamic, fast-moving, and competitive satellite communications landscape. The combined company’s capabilities, alongside complementary partnerships, will provide customers with enhanced coverage, improved resilience, and greater flexibility, as well as enabling the company to develop and deliver compelling solutions to drive the specific applications that customers need. The transaction is highly accretive to free cash flow per share from Year 1 and delivers €2.4 billion net present value of synergies (representing 85% of the equity value for Intelsat and an annualised run rate of around €370 million) of which 70% will be executed within 3 y

Xylem Unveils 'Reuse Brew'6.5.2024 09:00:00 EEST | Press release

In an innovative move to tackle Europe's escalating water scarcity, global water technology leader Xylem (NYSE: XYL), today announced the launch of Reuse Brew. This unique Bavarian beer, crafted from high-quality treated wastewater, marks a significant advancement in water recycling technologies and offers a sustainable solution to the increasing challenges posed by climate change. The development of Reuse Brew is the culmination of a partnership between the Chair of Brewery and Beverage Technology at Technical University of Munich (TUM), the Chair of Urban Water Systems Engineering at TUM, the city of Weissenburg in Bavaria, and Xylem. This collaboration showcases the transformative potential of advanced water treatment technologies in producing a palatable beer, promoting sustainable water management practices across Europe. "Reuse Brew is not merely an exceptional beer; it exemplifies the vast capabilities of water recycling in combating the pressing issue of water scarcity," said R

In our pressroom you can read all our latest releases, find our press contacts, images, documents and other relevant information about us.

Visit our pressroom
HiddenA line styled icon from Orion Icon Library.Eye