CyberGRX Study Finds Current Third-Party Cyber Risk Management Practices and Technologies Fall Short Despite Significant Investment
Summary
Surveying over 600 IT security professionals, the study illustrates a persistent theme that organizations and third parties see their third-party cyber risk management (TPCRM) practices as important but ineffective. Taking the time to prioritize third parties and apply an appropriate level of due diligence to them will reduce costs and increase efficiencies in the long run. Over 53% of respondents experienced a third-party data breach in the past 2 years, costing them on average $7.5 million, yet surprisingly, the market has yet to adopt new approaches to manage third party cyber risk. The results of this study illustrate beyond a doubt, that organizations and their third parties are wasting critical human and financial resources on programs that aren’t optimized to help them reduce cyber risk in their shared ecosystems. Our goal is to enable organizations in both the private and public sectors to have a clearer understanding of the trends in regulations and the threat landscape that will affect the collection, management and safeguarding of information assets.