Business Wire

SecurityScorecard Research Shows 98% of Organizations Globally Have Relationships With At Least One Breached Third-Party

Share

SecurityScorecard, the global leader in cybersecurity ratings, and The Cyentia Institute, an independent cybersecurity research firm, today published research that found 98 percent of organizations have vendor relationships with at least one third-party that has experienced a breach in the last two years. The study, Close Encounters of the Third (and Fourth) Party Kind , also found that 50 percent of organizations have indirect relationships with at least 200 breached fourth-party vendors in the last two years.

“An organizations’ attack surface spans beyond just the technology that they own or control, ” said Aleksandr Yampolskiy, co-founder and CEO of SecurityScorecard. “Organizations need visibility into the security ratings of their entire third and fourth party ecosystem so that they can know in an instant whether an organization deserves their trust and can take proactive steps to mitigate risk.”

The study, which analyzed data from over 235,000 (primary) organizations across the globe and more than 73,000 vendors and products used by them directly (third-parties) or used by their vendors (fourth-parties), offers an in-depth examination of how the interdependence of modern digital supply chains impacts organizational cyber risk exposure.

Key Report Findings:

  • Security Suffers The More Third- and Fourth-Parties You Have
    For every third-party vendor in their supply chain, organizations typically have indirect relationships with 60 to 90 times that number of fourth-party relationships. Research showed that compared to the primary organization, third-party vendors are five times more likely to exhibit poor security. Approximately 10% of third-party vendors receive an F rating among organizations that earn an A rating for their own security posture.
  • Information Services Leads in Third-parties
    The research revealed the Information Services sector maintained an average of 25 vendors-- 2.5 times the number of third party-relationships than the overall average of 10. The Finance sector was on the other end of the spectrum averaging 6.5 third-party relationships. The healthcare sector averaged 15.5 vendors per organization and the Insurance sector averaged 11 vendors. “Each of these third-party relations represents exposure to risk,” continued Baker. “In some cases due to compromised third-party code, or in others due to usage of an insecure hosting provider.”
  • Exposing Data to International Third-parties Increases Regulatory and Security Requirements
    While examining the regional dimension of third-party relationships, SecurityScorecard found that 59% of organizations have vendors from five or fewer countries, while roughly 14% work with vendors spanning 10 or more countries.

“SecurityScorecard’s data demonstrates why managing cyber risk across the digital supply chain is absolutely critical as threat actors work to exploit any vulnerabilities an organization may have. Identifying and continuously monitoring all partners and customers within the digital supply chain is key to staying ahead of any potential risk,” said Wade Baker, partner and co-founder at The Cyentia Institute. “By having full visibility into the security posture of their third and fourth parties, organizations can work with their vendors to address any cybersecurity gaps they may have in their infrastructure and, in turn, reduce their own level of cyber risk.”

Additional resources:

  • Access the full report, “Close Encounters of the Third (and Fourth) Party Kind”
  • Read our blog to better understand what can organizations do to minimize risk stemming from their business ecosystems
  • Register for the informational webinar, presented by SecurityScorecard and the Cyentia Institute.
  • Learn more about how Automatic Vendor Detection enables organizations to identify the products and vendors in their third- and fourth-party ecosystem to identify potential risk, automate their workflows, and drive targeted data-driven decisions.

About SecurityScorecard

Funded by world-class investors including Evolution Equity Partners, Silver Lake Waterman, Sequoia Capital, GV, Riverwood Capital, and others, SecurityScorecard is the global leader in cybersecurity ratings with more than 12 million companies continuously rated. Founded in 2013 by security and risk experts Dr. Aleksandr Yampolskiy and Sam Kassoumeh, SecurityScorecard's patented rating technology is used by over 30,000 organizations for enterprise risk management, third-party risk management, board reporting, due diligence, cyber insurance underwriting, and regulatory oversight. SecurityScorecard is the first cybersecurity ratings company to offer digital forensics and incident response services, providing a 360-degree approach to security prevention and response for its worldwide customer and partner base. SecurityScorecard continues to make the world a safer place by transforming the way companies understand, improve and communicate cybersecurity risk to their boards, employees and vendors. Every organization has the universal right to their trusted and transparent Instant SecurityScorecard rating. For more information, visit securityscorecard.com or connect with us on LinkedIn.

About The Cyentia Institute

The Cyentia Institute is a research and data science firm working to advance cybersecurity knowledge and practice. Cyentia pursues this goal through data-driven studies like this one and through a growing portfolio of analytic services. Learn more at www.cyentia.com.

To view this piece of content from cts.businesswire.com, please give your consent at the top of this page.

Contact information

Derek Delano
SecurityScorecard
ddelano@securityscorecard.io
(646) 457-4513

About Business Wire

For more than 50 years, Business Wire has been the global leader in press release distribution and regulatory disclosure.

Subscribe to releases from Business Wire

Subscribe to all the latest releases from Business Wire by registering your e-mail address below. You can unsubscribe at any time.

Latest releases from Business Wire

Tezos Activates ‘Mumbai’ Upgrade Enabling More Than a Million Transactions Per Second29.3.2023 22:45:00 EEST | Press release

Tezos, a pioneering blockchain for Proof-of-Stake consensus and on-chain governance, has activated Mumbai, its thirteenth core protocol upgrade. The Mumbai upgrade introduces Smart Rollups, a new Layer 2 scaling solution built directly into the protocol, which puts Tezos at the forefront of optimistic rollup technology. Smart Rollups enable decentralized applications (dApps) to benefit from their own dedicated hardware resources in order to process a high amount of transactions, while the integrity and security of the Smart Rollup is guaranteed by the Tezos main chain, or Layer 1. Due to this approach, the Tezos ecosystem will be able to surpass the milestone of one million transactions per second in 2023 without sacrificing decentralization. Secure, flexible, developer friendly Smart Rollups come with state-of-the-art technical features, namely: Fully decentralized and open interactive fraud proofs guarantee rollup security and integrity, provided there is at least one honest particip

Spring 2023 Maxon One Release Adds Extraordinary Value29.3.2023 19:00:00 EEST | Press release

Maxon, developers of professional software solutions for editors, filmmakers, motion designers, visual effects artists and creators of all types, announced today a comprehensive update to Maxon One. Maxon’s Spring 2023 release offers exciting new features and workflow enhancements across the entire product line that will empower designers and artists to turn their creative ideas into reality with stunning results. Cinema 4D 2023.2 offers an improved Commander, enhancements to its Nodes system, simulation improvements and a new Thicken generator for modeling. Updates to the Red Giant toolset feature new tools and augmentations; most notably the introduction of Symbol Mapper for Universe 2023.1, anamorphic lens support for Real Lens Flares for VFX 2023.3, and Trapcode 2023.3 includes performance optimizations for Particular and a new collection of Atomic Age sprites. Redshift 3.5.14 brings a fantastic new Sky and Sun Model, a new Flakes Shader and new Camera Backplates. The latest releas

Nasdaq Congratulates Signifier Medical Technologies for Treating 10,000 Patients With eXciteOSA, a Daytime Therapy for Sleep Apnea29.3.2023 18:24:00 EEST | Press release

Signifier Medical Technologies LLC (“Signifier” or the “Company”), a Boston-based medical technology company, announces that eXciteOSA, the only FDA-authorized daytime therapy for sleep-disordered breathing, has treated over 10,000 patients since the commercial launch in 2021. Nasdaq recognized this milestone by congratulating Signifier Medical on the Nasdaq Tower in the heart of Times Square, New York. This press release features multimedia. View the full release here: https://www.businesswire.com/news/home/20230329005432/en/ (Photo: Business Wire) Akhil Tripathi, Signifier’s co-founder and CEO said, “This is a proud moment knowing that our therapy has made a positive impact on the lives of so many patients. It’s been a great team effort among our employees, clinicians, distributors, and most of all, our patients.” Signifier Medical is simplifying the complex standard of care for obstructive sleep apnea with eXciteOSA by tackling a root cause -- empowering patients to restore their ni

Flare gas reduction: Graforce a winner at Petronas Race2Decarbonise for groundbreaking solution29.3.2023 18:00:00 EEST | Press release

Out of more than 500 global solutions, Graforce was recognized at the Petronas Race2Decarbonise with its methane electrolysis technology (plasmalysis) in the category “Gas Flaring Reduction or Elimination.” The competition is aimed at accelerating the development of low-carbon solutions and reducing greenhouse gas emissions. This press release features multimedia. View the full release here: https://www.businesswire.com/news/home/20230329005084/en/ Gas flaring causes more than 400 million tons of CO2 emissions every year. Graforce’s methane electrolysis technology is a groundbreaking solution that converts flare gas and other hydrocarbons into clean hydrogen and solid carbon. (Photo: Business Wire) Gas flaring results in more than 400 million tons of CO2 emissions every year. Thousands of gas flares at production sites around the globe burn approximately 150 billion cubic meters of natural gas each year, thus wasting a valuable resource. Plasmalysis, on the other hand, converts methane

SRMG launches new venture capital arm, SRMG Ventures, with first investments in regional content studio and immersive platform companies29.3.2023 17:36:00 EEST | Press release

SRMG, a global integrated media group, yesterday announced the launch of its corporate venture capital arm, SRMG Ventures. In line with SRMG’s transformative growth strategy, SRMG Ventures will invest in early-stage companies and technologies within the core target areas: media creators, digital media, media enablers and tools, including generative AI, as well as immersive and interactive entertainment. SRMG Ventures will initially target investments from the seed to Series B stage. SRMG Ventures will enable SRMG to back and empower regional talent and entrepreneurs, acting as a catalyst for further growth of the rapidly evolving media industry in the region. SRMG Ventures will provide SRMG with direct access to innovative technologies, as well as new media talent and content creators, that will continue to enhance SRMG’s own media portfolio and drive forward the future of media. The new corporate venture capital arm will additionally help SRMG penetrate new markets and further diversi

In our pressroom you can read all our latest releases, find our press contacts, images, documents and other relevant information about us.

Visit our pressroom