Interesting statistics related to Third Party Cyber Risk Management on the World Economic Forum's Global Cybersecurity Outlook 2024 report.
54% of organizations have insufficient visibility of the vulnerabilities of their supply chains, including 64% of executives who believe their own organizations meet their minimum resilience requirements.
To me this clearly shows just how big of a blind spot #TPCRM still is for most companies. After all only companies that don't outsource any critical functions and don't give any third parties access to critical data could simultaenously believe that a) they meet their resilience requirements and b) they don't understand their third parties' vulnerabilities... and how many of those are out there? I have personally never bumped into any companies this vertically integrated, even in regulated markets.
The report also highlights the real impacts of neglecting this discipline. It claims 41% of companies that suffered a material impact from a cyberattack said it originated from a third party. This dovetails nicely from data we've seen elsewhere, including a figure that incidents originated at third parties were the leading source of cyber insurance claims in Q2 of last year.
You can read the full report here: https://www.weforum.org/publications/global-cybersecurity-outlook-2024/
This is why here at @TenchiSecurity@infosec.exchange we decided to tackle #TPCRM, which is gradually starting to get the visibility and prioritization it deserves. Get in touch if you want to learn more about how we are disrupting this market by going beyond risk reporting and focusing on risk reduction through a cooperative approach.