Business Wire

SecurityScorecard Research Shows 98% of Organizations Globally Have Relationships With At Least One Breached Third-Party

Share

SecurityScorecard, the global leader in cybersecurity ratings, and The Cyentia Institute, an independent cybersecurity research firm, today published research that found 98 percent of organizations have vendor relationships with at least one third-party that has experienced a breach in the last two years. The study, Close Encounters of the Third (and Fourth) Party Kind , also found that 50 percent of organizations have indirect relationships with at least 200 breached fourth-party vendors in the last two years.

“An organizations’ attack surface spans beyond just the technology that they own or control, ” said Aleksandr Yampolskiy, co-founder and CEO of SecurityScorecard. “Organizations need visibility into the security ratings of their entire third and fourth party ecosystem so that they can know in an instant whether an organization deserves their trust and can take proactive steps to mitigate risk.”

The study, which analyzed data from over 235,000 (primary) organizations across the globe and more than 73,000 vendors and products used by them directly (third-parties) or used by their vendors (fourth-parties), offers an in-depth examination of how the interdependence of modern digital supply chains impacts organizational cyber risk exposure.

Key Report Findings:

  • Security Suffers The More Third- and Fourth-Parties You Have
    For every third-party vendor in their supply chain, organizations typically have indirect relationships with 60 to 90 times that number of fourth-party relationships. Research showed that compared to the primary organization, third-party vendors are five times more likely to exhibit poor security. Approximately 10% of third-party vendors receive an F rating among organizations that earn an A rating for their own security posture.
  • Information Services Leads in Third-parties
    The research revealed the Information Services sector maintained an average of 25 vendors-- 2.5 times the number of third party-relationships than the overall average of 10. The Finance sector was on the other end of the spectrum averaging 6.5 third-party relationships. The healthcare sector averaged 15.5 vendors per organization and the Insurance sector averaged 11 vendors. “Each of these third-party relations represents exposure to risk,” continued Baker. “In some cases due to compromised third-party code, or in others due to usage of an insecure hosting provider.”
  • Exposing Data to International Third-parties Increases Regulatory and Security Requirements
    While examining the regional dimension of third-party relationships, SecurityScorecard found that 59% of organizations have vendors from five or fewer countries, while roughly 14% work with vendors spanning 10 or more countries.

“SecurityScorecard’s data demonstrates why managing cyber risk across the digital supply chain is absolutely critical as threat actors work to exploit any vulnerabilities an organization may have. Identifying and continuously monitoring all partners and customers within the digital supply chain is key to staying ahead of any potential risk,” said Wade Baker, partner and co-founder at The Cyentia Institute. “By having full visibility into the security posture of their third and fourth parties, organizations can work with their vendors to address any cybersecurity gaps they may have in their infrastructure and, in turn, reduce their own level of cyber risk.”

Additional resources:

  • Access the full report, “Close Encounters of the Third (and Fourth) Party Kind”
  • Read our blog to better understand what can organizations do to minimize risk stemming from their business ecosystems
  • Register for the informational webinar, presented by SecurityScorecard and the Cyentia Institute.
  • Learn more about how Automatic Vendor Detection enables organizations to identify the products and vendors in their third- and fourth-party ecosystem to identify potential risk, automate their workflows, and drive targeted data-driven decisions.

About SecurityScorecard

Funded by world-class investors including Evolution Equity Partners, Silver Lake Waterman, Sequoia Capital, GV, Riverwood Capital, and others, SecurityScorecard is the global leader in cybersecurity ratings with more than 12 million companies continuously rated. Founded in 2013 by security and risk experts Dr. Aleksandr Yampolskiy and Sam Kassoumeh, SecurityScorecard's patented rating technology is used by over 30,000 organizations for enterprise risk management, third-party risk management, board reporting, due diligence, cyber insurance underwriting, and regulatory oversight. SecurityScorecard is the first cybersecurity ratings company to offer digital forensics and incident response services, providing a 360-degree approach to security prevention and response for its worldwide customer and partner base. SecurityScorecard continues to make the world a safer place by transforming the way companies understand, improve and communicate cybersecurity risk to their boards, employees and vendors. Every organization has the universal right to their trusted and transparent Instant SecurityScorecard rating. For more information, visit securityscorecard.com or connect with us on LinkedIn.

About The Cyentia Institute

The Cyentia Institute is a research and data science firm working to advance cybersecurity knowledge and practice. Cyentia pursues this goal through data-driven studies like this one and through a growing portfolio of analytic services. Learn more at www.cyentia.com.

To view this piece of content from cts.businesswire.com, please give your consent at the top of this page.

Contact information

Derek Delano
SecurityScorecard
ddelano@securityscorecard.io
(646) 457-4513

About Business Wire

For more than 50 years, Business Wire has been the global leader in press release distribution and regulatory disclosure.

Subscribe to releases from Business Wire

Subscribe to all the latest releases from Business Wire by registering your e-mail address below. You can unsubscribe at any time.

Latest releases from Business Wire

Binarly Launches Next-Generation Transparency Platform to Elevate Software Supply Chain Security23.4.2024 19:00:00 EEST | Press release

Binarly, provider of an industry leading AI-powered firmware and software supply chain security platform, announces the release of the Binarly Transparency Platform v2.0 with features for continuous post-build compliance, visibility into the security posture of IoT and XIoT devices, and the ability to identify malicious behavior and hidden backdoors within binaries based on their behavior. Learn more here. Based on the company’s proprietary Binary Risk Intelligence technology, the new innovations underscore Binarly's commitment to pioneering solutions that enhance transparency and security across firmware and software ecosystems. Founded in 2021 with a vision to increase transparency in the software supply chain through advanced program analysis, Binarly’s flagship platform has automated the discovery of hundreds of new vulnerabilities, preemptively addressing our customers' security risks before they could escalate. Binarly’s patented approach, powered by modern AI, has proactively ne

Making History: ASPIRE to Launch Inaugural ‘Abu Dhabi Autonomous Racing League’ Redefining Future of Extreme Sport on April 2723.4.2024 18:54:00 EEST | Press release

On Saturday, April 27th, Abu Dhabi will host a groundbreaking event, welcoming 10,000 spectators to witness the inaugural ASPIRE Abu Dhabi Autonomous Racing League (A2RL) at the iconic Yas Marina Circuit. This brand-new autonomous racing competition marks a significant milestone in motorsport history, billed as the largest league of its kind globally. This press release features multimedia. View the full release here: https://www.businesswire.com/news/home/20240423980323/en/ Making History: ASPIRE to Launch Inaugural ‘Abu Dhabi Autonomous Racing League’ Redefining Future of Extreme Sport on April 27 (Photo: AETOSWire) Eight teams will compete: Code19 Racing (one of the first independent autonomous racing entity from the USA), Constructor University (based in Germany and Switzerland), Fly Eagle (representing Beijing Institute of Technology from China and Khalifa University from the UAE), HUMDA Lab (a member of the Széchenyi István University Group from Hungary), KINETIZ (a collaboration

DataXstream Expands into Nordic Region with Successful Go Live for Martin & Servera23.4.2024 16:07:00 EEST | Press release

DataXstream LLC, an SAP solution provider focused on order management and point of sale for sales and distribution, today announced it is expanding into the Nordic region after a successful implementation of its OMS+ platform across two key business units for the Martin & Servera group, Sweden’s leading restaurant and catering distributor that specializes in the needs of the restaurant industry. Learn more about DataXstream OMS+ here. Martin & Servera is a group of companies based in Stockholm who was faced with the challenge of managing multiple ERP systems that were facing end of life, so they decided to consolidate onto a single instance of SAP S/4 HANA for all their business units. As part of this migration, Martin & Servera turned to DataXstream’s OMS+ cross-channel order management platform to help them enable faster order entry and streamline their sales and order processes between all companies within their organization. Working with DataXstream’s LATAM delivery team, Kötthalle

Autel Energy’s Global ESG Launch Is A Success: Around 5,000 Trees Planted In EVergreen's Inaugural Tree Planting Initiative23.4.2024 16:00:00 EEST | Press release

Autel Energy, a leading provider of electric vehicle (EV) charging solutions and services, proudly announces the successful conclusion of its first EVergreen Global Tree Planting Initiative, which saw hundreds of participants around the globe plant an estimated 5,000 trees in the initial phase. This activity offsets an estimated 2,190,000 kilograms of carbon emissions (CO2), and emphasizes Autel Energy's and partners' commitment to their ESG goals towards a sustainable tomorrow. This press release features multimedia. View the full release here: https://www.businesswire.com/news/home/20240423142946/en/ Autel Energy’s Global ESG Launch A Success (Graphic: Business Wire) Partner Experience and NGO Feedback Reflecting on the Initiative, one partner remarked, “We show the world we are not only talking about a better world and clean energy, but we are really taking steps by putting shovels in the ground.” The non-governmental organizations (NGO) involved expressed sincere gratitude for the

EIG’s MidOcean Energy Completes Acquisition of 20 Percent Stake in Peru LNG23.4.2024 15:00:00 EEST | Press release

MidOcean Energy (“MidOcean” or the “Company”), a liquefied natural gas (LNG) company formed and managed by EIG, a leading institutional investor in the global energy and infrastructure sectors, today announced the completion of its previously announced agreement to acquire SK earthon’s (“SK”) 20 percent interest in Peru LNG (“PLNG”), owner and operator of the first LNG export facility in South America. PLNG’s assets comprise a natural gas liquefaction plant with 4.45 mmtpa processing capacity, a fully-owned 408km-long pipeline with 1,290 mmcf/d capacity, two 130,000 m3 storage tanks, a fully-owned 1.4 km-long marine terminal and a truck loading facility with capacity of up to 19.2 mmcf/d. PLNG, operated by Hunt Oil Company, is one of only two LNG production facilities in Latin America, located in Pampa Melchorita, 170km south of Lima. De la Rey Venter, MidOcean Energy’s CEO, said, “The completion of this investment is an important milestone in our efforts to create a global, diversifie

In our pressroom you can read all our latest releases, find our press contacts, images, documents and other relevant information about us.

Visit our pressroom
HiddenA line styled icon from Orion Icon Library.Eye