How to Mitigate the Risk Third-Party Providers Pose to Security

cyber security - GDT

Fortune 500 technology giant General Electric (GE) recently disclosed that one of their service providers experienced a security incident in which personally identifiable information (PII) of current and former employees and beneficiaries was exposed. This is the latest in a LONG line of third-party breaches going back to at least 2013, yet most companies still do not have adequate third-party controls. What, if anything, can businesses do to help ensure their valued partners are not setting them up for a major security breach?

In 2013, a Target breach resulted in a loss of 70 million customers’ data. Though certainly not the first of its kind, it was at that time the largest. Yet it seems that, in the seven years since, corporate America learned nothing from the Target breach. In that time, approximately 163 breaches have occurred, with the number of companies, hospitals, schools, city governments, and other organizations affected totaling well over 200. In some cases, the same third party was responsible for over a dozen breaches, yet is still heavily used by numerous entities.

With the advent of the California Consumer Privacy Act (CCPA), as well as other state privacy laws, the need for adequate third-party security evaluations has become more important than ever. Companies must take greater action to ensure their third-party service providers are providing an adequate security environment for the data with which they are entrusted. This includes a greater level of due diligence than just a questionnaire. Third-party providers must also take steps to have an independent assessment and certification of their security processes. The most common of these is the AICPA’s SOC 2 Trusted Criteria assessment, although an ISO 27001 certification or other independent security assessment certification against an accepted security standard will help provide a level of assurance that security controls are in place AND fully operational.

GDT’s Advisory Services practice can assist our clients in preparing for these assessments by providing gap analysis assessments, developing a remediation plan to achieve compliance with many of the security frameworks and regulatory requirements such as CCPA, GDPR, ISO, NIST, and others. We can also assist in developing a security roadmap and strategy to ensure continued regulatory compliance, and provide guidance in the selection, implementation, and operation of security products and services to maximize your security program’s effectiveness while optimizing its cost.

Author

Share this article

You might also like:

As businesses look to boost productivity, many are turning to Microsoft Copilot. This AI-powered productivity capability is embedded into Microsoft 365 applications like Word, Excel, and PowerPoint, tools most employees already know. This familiarity promises a more friction-free experience from an employee onboarding perspective. When implemented successfully, it can automate

Microsoft Copilot promises AI-powered productivity gains that will redefine how work gets done. Already, Microsoft Copilot is transforming the way organizations and their workforce communicate and function via streamlined automation and AI workflow. In practice, however, many cybersecurity professionals face significant adoption hurdles related to Microsoft Copilot security, including AI

Are you making the most of your Cisco renewals? Most organizations treat renewals as tactical exercises: a check-the-box task to extend coverage, process a purchase order, and avoid service disruption. But this reactive approach misses a tremendous opportunity. When approached strategically, a Cisco renewal can be far more than a