Le Lézard
Classified in: Science and technology
Subjects: Survey, Business Update

Third-Party Data Breaches Rose 49% in 2023, Reaching Record Level, New Prevalent Study Finds


Prevalent Inc. published its 2024 Third-Party Risk Management Study today, finding that 61% of companies experienced a third-party data breach or cybersecurity incident last year. Breaches rose 20 points ? or 49% ? year over year, increasing threefold since 2021.

"What stands out in our report isn't only the number of breaches, which is the highest we've tracked, but also the scale," said Prevalent CEO Kevin Hickey. "Breaches in 2023 impacted huge supply chains ? from Okta and LastPass to Change Healthcare and PJ&A ? exposing sensitive records of millions of people worldwide. There has never been a more urgent time to take third-party security more seriously."

Conducted this February and March, the survey's respondents include heads of information security, data privacy, risk management, procurement, and other IT executives at companies spanning dozens of industries and whose supply chains collectively represent half a million vendors.

Prevalent's study identified multiple areas of concern that could explain the unprecedented breadth and depth of third-party breaches.

"Although most organizations report having TPRM programs in place, half still rely on spreadsheets and use a patchwork of tools to assess their vendors," said Prevalent COO Brad Hibbert, adding that 60% of respondents are not using a dedicated TPRM platform.

According to the report, the consequence of companies' reliance on multiple tools is a lack of coordination, leaving their supply chains unguarded. Only a third of respondents indicated their third-party security programs were highly coordinated.

While the survey respondents' average number of third parties was 3,200, respondents reported assessing or monitoring only 33% of those vendors. "There is a lot of risk hiding among those unassessed relationships," said Mr. Hibbert.

More than 62% of respondents reported understaffing was the biggest obstacle to better safeguarding their organizations from third-party breaches. The average respondent said they need double their current staff dedicated to third-party security.

"Later stages of third-party lifecycles lack adequate risk assessment and monitoring, and overall remediation is woefully lacking," per Prevalent's report. While nearly 90% of companies track risks from the sourcing and selection phases, fewer than 80% track service-level agreements (SLAs) and offboarding risks later in the relationship lifecycle.

"What surprised us was the disparity between the share of organizations tracking risks and the share remediating them," explained Mr. Hibbert. "A shockingly low 46% of companies report remediating risk as a result of risk assessments ? the stage where risks must be mitigated."

??Prevalent found that AI use remains low in the sector, with only 5% of companies actively leveraging AI in their TPRM programs. However, interest remains high, with 61% saying they are actively investigating its uses.

Prevalent advises creating cross-functional teams and establishing clear ownership of TPRM programs as well as automating TPRM processes around a single platform to unify teams, data, and risk lifecycles.

Read the blog post and download the full e-book and infographic for additional statistics, context and recommendations on benchmarking existing TPRM practices.

About Prevalent

Prevalent takes the pain out of third-party risk management (TPRM). Companies use our software and services to eliminate the security and compliance exposures that come from working with vendors and suppliers throughout the third-party lifecycle. Our customers benefit from a flexible, hybrid approach to TPRM, where they not only gain solutions tailored to their needs but also realize a rapid return on investment. Regardless of where they start, we help our customers stop the pain, make informed decisions, and adapt and mature their TPRM programs over time. To learn more, please visit www.prevalent.net.


These press releases may also interest you

at 17:20
The Phase IIa COURSE trial was a proof-of-concept study in people with moderate to very severe chronic obstructive pulmonary disease (COPD) with a broad range of blood eosinophil counts (BEC) and irrespective of emphysema, chronic bronchitis or...

at 14:15
Endeavor BioMedicines, a clinical-stage biotechnology company developing medicines with the potential to deliver transformational clinical benefits to patients with life-threatening diseases, announced results from a completed Phase 2a clinical trial...

at 12:20
Savara Inc. (the Company), a clinical stage biopharmaceutical company focused on rare respiratory diseases, presented a poster at the American Thoracic Society (ATS) 2024 International Conference that is taking place May 17-22, 2024, in San Diego,...

at 11:10
Orion Health, a global leader in digital health solutions, announced today that it has been awarded partner status by Panda Health for its Orchestral Health Intelligence Platform, one of three pillars of the Unified Healthcare Platform. Panda Health...

at 06:13
eWTP Arabia Capital Technology Fund I ("Techology Fund I"), managed by eWTP Arabia Capital ("eWTPA"), one of the leading private equity firms in the Middle East, was listed in the Preqin League Tables as the the fifth top-performing VC funds in the...

18 mai 2024
Celltrion partners with TV star Mollie Pearce to launch the second installation of the Where's Crohn's & Colitis (CC)? campaign for this year's World IBD Day (19 May 2024). The campaign focuses on access to IBD care and treatment as the burden of...



News published on and distributed by: