The incidents are symptomatic of the heightening risks organizations face from third parties providing various business services, says Stephen Boyer, CTO and co-founder of BitSight. With many companies essentially becoming a combination of outsourced services, risks from insecure third parties have grown significantly in recent years, he says.
He estimates that between 60% and 70% of all breaches currently result from third-party security failures. The trend is the result of organizations not properly vetting the security practices of partners and outside vendors when letting them access enterprise data and services, he says.
When the European Union's General Data Protection Regulation goes into effect next month, organizations such as Delta and Sears will bear much greater direct responsibility for such breaches, Boyer notes. The mandate requires data controllers — or the data owners — to include specific requirements pertaining to data security in all contractual agreements with third-party processors.