Fortress
Third-Party Risk Management Insights from DBIR
Pages
2
Time to read
4 mins
Publication
Language
English
Pages
2
Time to read
4 mins
Publication
Language
English
This document is a perspective piece from a Chief Information Security Officer (CISO) regarding the annual Data Breach Investigation Report (DBIR) published by Verizon. It discusses the increasing prevalence of third-party incidents in cybersecurity, noting that 30% of breaches in the 2024 report involved third parties, which is double the figure from 2023. The CISO emphasizes the importance of understanding how third-party vendors secure data and the risks associated with generative AI companies. Recommendations for managing third-party risk are provided, including the need to inventory and assess vendors rigorously, reduce potential impacts through network segmentation, and demand secure practices from vendors. The document underscores the necessity of planning for potential problems that may arise from third-party relationships, highlighting that while perfection in third-party risk management (TPRM) is unattainable, proactive measures can mitigate risks effectively.