With 62% of network intrusions originating from a partner, third parties are now the biggest source of cyber risk. Yet, many vendors are hesitant to share information about their security postures and the risks they might pose to their customers and partners.
In this blog, we explore why cybersecurity transparency matters and how you can achieve it across your supply chain – with or without your vendors’ participation.
Why cybersecurity transparency matters
Worry about supply chain cyber risk is growing. According to Gartner, 56% of B2B and B2C customers express frequent concerns about the cybersecurity posture of their vendors and business partners. However, most organizations do not have stringent measures in place to identify these risks. In an earlier study, Gartner found that only 23% of security and risk management leaders monitor their third parties in real time for cybersecurity exposure.
Meanwhile, regulations such as the U.S. Securities and Exchange Commission incident reporting rules and European Union’s General Data Protection Regulation (GDPR) mandate that businesses are transparent about cyber incidents.
Given these developments, organizations are using cybersecurity risk as a determining factor when doing business with third parties. These parties should take note of Gartner’s warning: “You can no longer expect to keep the failures and successes of your cybersecurity function a secret.”