Le Lézard
Classified in: Science and technology
Subjects: Event, Product/Service, Webcast

Organizations Deprioritize Third-Party Relationships as Potential Breach Sources, CyberGRX Study Reveals


CyberGRX, provider of the world's first and largest global risk exchange, today announced the results of their commissioned study on how organizations prioritize third-party risk. Conducted by Forrester Consulting, the research comprises surveys from 319 respondents in IT, security, and risk roles covering technology, retail, oil and gas, healthcare, financial services, and other highly regulated industries. The study highlights that while organizations recognize third-party threats expose them to great risk, many organizations fail to take adequate measures to mitigate it. In fact, while they grapple with third-party cyber risk management (TPCRM), the weak points in their current mitigation strategies exacerbate the threat of cyber incidents.

The Forrester study, Why Isn't Your Organization Prioritizing Third-Party Risk?, identifies four major themes:

  1. Today's organizations constantly exchange confidential information with third parties. This exposes both sides to significant cyber risk. These information supply lines enabled by cloud and software-as-a-service (SaaS) adoptions are expected to grow in importance for many enterprises. The percentage of data shared with third parties will ramp up over the next five years (from 30%-41% by 2026).

  2. Current third-party risk prevention strategies leave organizations vulnerable. Businesses struggle to manage the risk that their third parties present because of a lack of prioritization and a matter of approach. Ninety-five percent of respondents said their organizations experienced a strategy- or technology-based challenge in managing third-party risk. Without proper oversight, companies become vulnerable to cybersecurity threats, including data loss and ransomware.

  3. Organizations stung by third-party cyber incidents tend to ignore safe risk management practices. Organizations that have experienced a third-party cyber incident express a higher level of concern about managing such risks. However, organizations that have experienced an incident also tend to share a higher percentage of their critical data (30%) than firms that haven't been hit (22%). And firms that have experienced an incident are less likely to have tools in place to mitigate third-party cyber risks.

  4. Mitigating third-party risk requires a different approach to strategy and technology. Organizations need to approach third-party risk with a new holistic, ecosystem-focused, and cybersecurity-focused strategic mindset. This includes updated third-party assessment analysis, standardized processes, and higher-quality technology solutions.

"Organizations that fail to take thoughtful steps to monitor, defend, and prepare for third-party cyber incidents have undermined their entire cybersecurity posture," said Dave Stapleton, CISO, of CyberGRX. "As the Forrester study highlights, many organizations recognize the hazards posed by third parties; however, their actions do not reflect effective mitigation. Lacking a defined TPCRM strategy creates the opportunity for a breach, even if internal risk management strategies are otherwise solid and effective."

To improve third-party cyber risk practices, organizations must consider vendors as an extension of their own brand, and set a strict baseline and expectations for their cyber maturity. Companies should leverage data and automation to ensure that their entire supply chain will meet the outlined cyber requirements. Additionally, it is imperative to continuously monitor the changing cyber risk of vendors. As new attack vectors are unleashed, a vendor's security posture can be rapidly altered. Finally, constant communication regarding cyber posture and compliance among all parties involved is critical and security training for employees and stakeholders should be mandatory.

CyberGRX's Chief Information Security Officer, Dave Stapleton, and guest speaker, Forrester principal analyst Renee Murphy will present key findings and recommendations from the research during a webinar on Tuesday, October 12 at 2:00 pm EDT. To learn more:

Register for the webinar
Download the full report

About CyberGRX

CyberGRX is on a mission to modernize third-party cyber risk management. Built on the market's first and largest third-party cyber risk exchange, CyberGRX's dynamic and scalable approach is innovating TPCRM for enterprises and third parties. Armed with fast and accurate data and a proven and innovative approach, CyberGRX customers make rapid, informed decisions and confidently engage with partners. Based in Denver, CO, CyberGRX was designed with partners including Aetna, Blackstone and MassMutual.


These press releases may also interest you

at 11:45
Information Services Group (ISG) , a leading global technology research and advisory firm, has launched a research study examining providers that help customers get the most out of the Workday cloud-based enterprise management platform. The study...

at 11:45
Vertex Pharmaceuticals today announced that the European Commission has granted approval for the label expansion of KALYDECO® (ivacaftor) for the treatment of infants down to 1 month of age with cystic fibrosis (CF) who have one of the following...

at 11:30
New research from the global research and advisory firm explains the challenges federal departments and agencies face in serving vulnerable communities. In its recently published blueprint, Info-Tech highlights the potential for AI initiatives to...

at 11:30
Corporate sustainability is about more than simply putting a recycling bin by the copy machine or a water cooler in the breakroom. It is a company's conscious effort to make environmentally responsible choices at every possible opportunity. That is...

at 11:15
Variantyx, a leader in molecular diagnostics, announced today that it has secured an additional $36 million in funding from its portfolio of investors which includes Peregrine Ventures, Pitango HealthTech, New Era Capital Partners and Bosch Ventures....

at 11:06
Semiconductors power the world. From computers to medical equipment, to electric vehicles, semiconductors ? or microchips ? produce so much of what we depend on. They are also critical in the global race to scale up and adopt artificial intelligence,...



News published on and distributed by: