Business Wire

SecurityScorecard Research Shows 98% of Organizations Globally Have Relationships With At Least One Breached Third-Party

Share

SecurityScorecard, the global leader in cybersecurity ratings, and The Cyentia Institute, an independent cybersecurity research firm, today published research that found 98 percent of organizations have vendor relationships with at least one third-party that has experienced a breach in the last two years. The study, Close Encounters of the Third (and Fourth) Party Kind , also found that 50 percent of organizations have indirect relationships with at least 200 breached fourth-party vendors in the last two years.

“An organizations’ attack surface spans beyond just the technology that they own or control, ” said Aleksandr Yampolskiy, co-founder and CEO of SecurityScorecard. “Organizations need visibility into the security ratings of their entire third and fourth party ecosystem so that they can know in an instant whether an organization deserves their trust and can take proactive steps to mitigate risk.”

The study, which analyzed data from over 235,000 (primary) organizations across the globe and more than 73,000 vendors and products used by them directly (third-parties) or used by their vendors (fourth-parties), offers an in-depth examination of how the interdependence of modern digital supply chains impacts organizational cyber risk exposure.

Key Report Findings:

  • Security Suffers The More Third- and Fourth-Parties You Have
    For every third-party vendor in their supply chain, organizations typically have indirect relationships with 60 to 90 times that number of fourth-party relationships. Research showed that compared to the primary organization, third-party vendors are five times more likely to exhibit poor security. Approximately 10% of third-party vendors receive an F rating among organizations that earn an A rating for their own security posture.
  • Information Services Leads in Third-parties
    The research revealed the Information Services sector maintained an average of 25 vendors-- 2.5 times the number of third party-relationships than the overall average of 10. The Finance sector was on the other end of the spectrum averaging 6.5 third-party relationships. The healthcare sector averaged 15.5 vendors per organization and the Insurance sector averaged 11 vendors. “Each of these third-party relations represents exposure to risk,” continued Baker. “In some cases due to compromised third-party code, or in others due to usage of an insecure hosting provider.”
  • Exposing Data to International Third-parties Increases Regulatory and Security Requirements
    While examining the regional dimension of third-party relationships, SecurityScorecard found that 59% of organizations have vendors from five or fewer countries, while roughly 14% work with vendors spanning 10 or more countries.

“SecurityScorecard’s data demonstrates why managing cyber risk across the digital supply chain is absolutely critical as threat actors work to exploit any vulnerabilities an organization may have. Identifying and continuously monitoring all partners and customers within the digital supply chain is key to staying ahead of any potential risk,” said Wade Baker, partner and co-founder at The Cyentia Institute. “By having full visibility into the security posture of their third and fourth parties, organizations can work with their vendors to address any cybersecurity gaps they may have in their infrastructure and, in turn, reduce their own level of cyber risk.”

Additional resources:

  • Access the full report, “Close Encounters of the Third (and Fourth) Party Kind”
  • Read our blog to better understand what can organizations do to minimize risk stemming from their business ecosystems
  • Register for the informational webinar, presented by SecurityScorecard and the Cyentia Institute.
  • Learn more about how Automatic Vendor Detection enables organizations to identify the products and vendors in their third- and fourth-party ecosystem to identify potential risk, automate their workflows, and drive targeted data-driven decisions.

About SecurityScorecard

Funded by world-class investors including Evolution Equity Partners, Silver Lake Waterman, Sequoia Capital, GV, Riverwood Capital, and others, SecurityScorecard is the global leader in cybersecurity ratings with more than 12 million companies continuously rated. Founded in 2013 by security and risk experts Dr. Aleksandr Yampolskiy and Sam Kassoumeh, SecurityScorecard's patented rating technology is used by over 30,000 organizations for enterprise risk management, third-party risk management, board reporting, due diligence, cyber insurance underwriting, and regulatory oversight. SecurityScorecard is the first cybersecurity ratings company to offer digital forensics and incident response services, providing a 360-degree approach to security prevention and response for its worldwide customer and partner base. SecurityScorecard continues to make the world a safer place by transforming the way companies understand, improve and communicate cybersecurity risk to their boards, employees and vendors. Every organization has the universal right to their trusted and transparent Instant SecurityScorecard rating. For more information, visit securityscorecard.com or connect with us on LinkedIn.

About The Cyentia Institute

The Cyentia Institute is a research and data science firm working to advance cybersecurity knowledge and practice. Cyentia pursues this goal through data-driven studies like this one and through a growing portfolio of analytic services. Learn more at www.cyentia.com.

To view this piece of content from cts.businesswire.com, please give your consent at the top of this page.

Contact information

Derek Delano
SecurityScorecard
ddelano@securityscorecard.io
(646) 457-4513

About Business Wire

For more than 50 years, Business Wire has been the global leader in press release distribution and regulatory disclosure.

Subscribe to releases from Business Wire

Subscribe to all the latest releases from Business Wire by registering your e-mail address below. You can unsubscribe at any time.

Latest releases from Business Wire

Kyriba Unveils Agentic AI TAI to Transform Finance with Security, Compliance & Trust13.5.2025 14:35:00 EEST | Press release

Kyriba, a global leader in liquidity performance, today introduced its agentic AI solution, TAI – a significant advancement in the safe, compliant use of generative AI in finance operations to improve productivity and efficiency amid continued economic uncertainty. Powered by Kyriba's embedded Large Language Model (LLM) and over 20 years of unmatched global liquidity data, TAI simplifies complex workflows, identifies risks with predictive analytics, and enhances data-driven decision-making across treasury, payments, risk management and working capital. Poised to transform finance and treasury operations without relying on third-party LLM integrations, TAI is a key component of Kyriba’s Trusted AI portfolio. This platform-wide approach prioritizes industry-leading data privacy while empowering enterprise leaders to make faster, smarter decisions with human judgement and responsibility at the center. Kyriba’s approach directly addresses the "Trust Gap" – the growing divide between the pr

BeiGene to Present at the RBC Capital Markets Global Healthcare Conference13.5.2025 13:01:00 EEST | Press release

BeiGene, Ltd. (NASDAQ: ONC; HKEX: 06160; SSE: 688235), a global oncology company that will change its name to BeOne Medicines Ltd., today announced it will participate in the RBC Capital Markets Global Healthcare Conference on May 20, 2025, with a fireside chat at 10 a.m. EDT. The live webcast of this event can be accessed from the investors section of the Company’s website at http://ir.beigene.com/, https://hkexir.beigene.com/, https://sseir.beigene.com/. An archived replay will be available for 1 year following the event. About BeiGene BeiGene, which will change its name to BeOne Medicines, is a global oncology company that is discovering and developing innovative treatments that are more accessible and affordable to cancer patients worldwide. With a broad portfolio, we are expediting development of our diverse pipeline of novel therapeutics through our internal capabilities and collaborations. We are committed to radically improving access to medicines for far more patients who need

IQM’s First Quantum Computer in Asia-Pacific Goes Online, Set to Open Office in Seoul13.5.2025 12:09:00 EEST | Press release

IQM Quantum Computers, a global leader in superconducting quantum computers, has announced expanding its presence in Asia-Pacific with a new office opening in South Korea in June 2025, following the installation of its first quantum system at Chungbuk National University (CBNU). This press release features multimedia. View the full release here: https://www.businesswire.com/news/home/20250513710683/en/ From left to right: Ben Lee and Mikko Välimäki of IQM Quantum Computers, Professor Kim Kiwoong of Chungbuk National University, Jyri Järviaho, Ambassador of Finland to South Korea, Jaana Tuomi, of Enter Espoo, Guensuk Ko of CBIST The office in Seoul reinforces IQM’s dedication to collaborating with research and academic institutions, high-performance computing (HPC) centers, and enterprises in advancing quantum technology. It also supports South Korea in building a vibrant quantum ecosystem and achieving the goals of its national quantum strategy. As part of the expansion, IQM has appoin

Ink Innovation and Riyadh Air Partner to Rethink Experience for Digital-first Travellers13.5.2025 12:06:00 EEST | Press release

Riyadh Air, the digitally native national carrier of Saudi Arabia, is joining forces with Ink Innovation to deliver a flexible and convenient air travel experience. Together, they aim to redefine standards of delivery management in a world influenced by e-commerce, cloud computing, and evolving traveller expectations. This press release features multimedia. View the full release here: https://www.businesswire.com/news/home/20250513792260/en/ Tony Douglas, CEO of Riyadh Air, said: “Ink is a key partner to Riyadh Air and continues to foster innovation at every step of the journey. As a like-minded tech-innovator, it is an ideal collaborator as we aim to provide an outstanding digital experience for our guests at their first travel touchpoint.” Moving beyond legacy systems Airlines have long struggled with outdated infrastructure—systems built to move passengers from point A to B, but not to delight or adapt. This partnership aims to change that. Riyadh Air and Ink are implementing a full

Green Street Expands Private Market Coverage with European Self-Storage Data and Analytics13.5.2025 11:00:00 EEST | Press release

Green Street, the foremost provider of commercial real estate intelligence and insights, has expanded its private market research coverage to the European self-storage sector. Utilising 5 years of forecasted insights and 10 years of historical data, Green Street’s new Self-Storage Outlook focuses on investment opportunities available in 30 European cities. “Living quarters are becoming more compact and storage space is being cut back in urban developments, necessitating off-premises storage solutions for residential occupiers. Additionally, approximately 40% of the business customer base consists of small-to-medium-sized entities, particularly online retailers in the region,” said Marie Dormeuil, Head of European Market Analytics. “The growth in real spending on storable goods is expected to increase at 2% per annum over the next five years, supporting healthy demand growth.” Green Street continues to invest in product innovation and expanding its breadth of research coverage by unveil

In our pressroom you can read all our latest releases, find our press contacts, images, documents and other relevant information about us.

Visit our pressroom
World GlobeA line styled icon from Orion Icon Library.HiddenA line styled icon from Orion Icon Library.Eye