Partner security risk is an important topic in the minds of risk officers today. With the number of companies being breached via third parties on the rise (New York Times, Bank of America, Twitter), this is clearly a big area of concern. In a survey conducted by Ponemon in February 2013, 65% of participants said their organization had a breach involving the loss or theft of their organization’s information when it was outsourced to a third party. In April 2013, the Information Security Forum (ISF) wrote "Of all the supply chain risks, information risk is the least well managed."
So, how real is this risk and how is it being addressed today?
According to the ISF, its member organizations have approximately 2,030 external supplier relationships on average. True - not all organizations are as large as some of the ISF members (including IBM, Nokia and P&G) - but the fact is that in today’s hyper-networked world, corporations are operating with more and more business partners. In addition to manufacturing and support services, companies commonly outsource other functions such as IT, legal, payroll, marketing, and human resources. That’s a lot of information exposed to third party risk. Take the example of Bank of America. In March 2013, Bank of America confirmed that a third party compromise was responsible for a 14 terabyte data leak! Yes – this is absolutely a REALLY BIG RISK.
Unfortunately, tools to manage third party security risk are limited. Here is what the typical process looks like for large financial institutions – i.e. this is the “state of the art” today.