When third party vendors, partners, processors and contractors find out about a breach of your customers' data, do you know what their notification practices are? Would you be surprised to know that almost a full third of them probably won't ever let you know that they've put your data at risk?
It's true, though. According to figures from the Ponemon Institute, only about 6 percent of third-parties let their clients know about loss of their data immediately upon discovery. And 29 percent of companies said that when they suffer a breach involving a partner or client's data they simply don't notify their business partners at all.
As we mentioned in a previous post, breach notification laws and standards today are very spotty in their requirements for third parties who have compromised partner or client data. The void has led to extremely inconsistent notification practices among third parties, with only about 41 percent claiming to have some kind of timely notification policy in place.
Often times, though, businesses can work around these issues through crafty vendor risk management practices and shrewd contract negotiations. Placing more rigorous cybersecurity audit and breach notification stipulations in contracts can greatly improve the chances of being told when problems crop up (I recommend organizations that are still figuring out vendor risk management best practices to check out this article, which offers a good primer on some of the considerations).
But that's only a start. Because even more troubling than these low notification figures is the consideration that these are only a percentage of a subgroup, namely those third parties that actually know that they've been breached. Case in point: the high profile Adobe and Neiman Marcus breaches both went on for months before the incidents were discovered, giving criminals unfettered access to data for an incredible amount of time. So how can you rely on your partner to tell you they've been breached when often times they don't know themselves?