How to Prevent Third-Party Vendor Data Breaches
The article explains that third-party vendor data breaches, which account for 62% of all breaches and often take an average of 277 days to detect, pose significant risks and costs—averaging $9.48 million per breach in the U.S.—highlighting recent examples such as breaches involving Click Studios’ Passwordstate, Toyota, and Elekta, and emphasizes the importance of understanding and mitigating these vulnerabilities to protect sensitive organizational data.
Third-party data breaches can happen at any time to any organization. This type of breach occurs when a vendor or business partner holding your company’s data suffers a breach, exposing your data. According to the Verizon 2022 Data Breach Investigations Report, 62 percent of all data breaches happen via third-party vendors.
Even worse, IBM and the Ponemon Institute report that on average, a company takes 277 days to identify and contain a third-party data breach. This lengthy detection period is due to threat actors operating in stealth mode and, in some cases, vendors attempting to hide breaches to avoid damaging partnerships.
The consequences and cost of recovering from a breach can be detrimental to your business. The average cost of a data breach in the United States was $9.48 million in 2023. Major targets include healthcare organizations, credit card companies, email service providers, and cloud service providers.
This post covers examples of common third-party breaches and what to do when a third-party data breach strikes your organization.
Examples of Third-Party Security Breaches
Third-party suppliers, partners, and vendors are prime targets for cybercriminals. Here are a few instances of third-party violations from recent history:
- Customers of Click Studios’ business password manager Passwordstate received a breach notification in 2021 after hackers used the app’s update mechanism to spread malware to users. Click Studios instructed affected customers to change every password in the Passwordstate database.
- Toyota experienced a third-party data breach in 2022, resulting in the temporary closure of its manufacturing plant in Japan and implications for other subsidiaries.
- The Cancer Centers of Southwest Oklahoma’s third-party cloud storage provider, Elekta, found that 8,000 cancer patients’ sensitive health information was accessed without authorization, including names, Social Security numbers, locations, birthdates, and medical diagnoses.
- Saudi Aramco had 1 terabyte of data stolen, including employee, customer, and project information. The breach was attributed to a flaw at a third party, and cybercriminals demanded a $50 million ransom.
Common Data Breaches Caused by Third-Party Vendors
Phishing and ransomware attacks have increased, especially during the COVID-19 pandemic. These attacks can lead to various types of data breaches:
- Unauthorized access via a company email account. General Electric experienced a breach that exposed employees’ personal data such as marriage certificates, passports, driver’s licenses, and tax withholding forms.
- Hacking of a telecommunications provider. Sensitive information of more than 50 million T-Mobile customers was exposed when an unprotected router was accessed.
- Lack of encryption. A vendor for Health Share of Oregon had an unencrypted laptop stolen, exposing the personal information of more than 650,000 people.
- Unsecure websites and improperly stored log-in information. A website bug allowed access to thousands of passwords and usernames for an Instagram account via the third-party Social Captain.
These breaches are serious, and the stolen information is often quickly available for sale on the dark web, leading to further scams against affected individuals.
Preventing Third-Party Vendor Data Breaches and Holding Vendors Accountable
Holding third-party vendors accountable can be difficult without a third-party security policy or program. Ideally, vendors should enforce the same strict standards and internal data security controls as your company.
A robust and responsive vendor risk management policy can be divided into several action areas:
Consider Information Security During Vendor Selection
When selecting a vendor, consider how they handle information security. Discuss their security processes early and ensure their internal security aligns with your objectives. Only sign contracts with vendors whose security processes meet your standards.
Audit Third-Party Vendors for Compliance
Perform audits as necessary, especially with high-risk data. Audits evaluate how the vendor executes its security compliance framework and its performance in previous audits. Look for indicators of compromise and assess how well the vendor manages cybersecurity risk.
Require Proof of the Third-Party Vendor’s Cybersecurity Program
Vendors should demonstrate a commitment to risk management and vulnerability management. Request recent results from internal risk assessments, penetration testing, and compliance frameworks. Ensure the vendor has a robust risk management program, supply chain risk mitigation strategy, and breach remediation plans.
Ongoing third-party risk monitoring provides continuous insights into the vendor’s cybersecurity program. Hold quarterly reviews to evaluate performance metrics and security posture.
Set Clear Policies and Expectations for Data Storage and Transfer
Establish clear guidelines for data storage and transfer to set boundaries and expectations. This ensures third-party vendors treat your data with the same standards as their own, protecting data integrity at all levels.
Adopt a Least-Privileged Model for Data Access
Many breaches occur because third parties have more access than necessary. Enforce least-privileged access management to improve network security. Restrict vendor access to the lowest possible level to minimize potential damage.
Continuous Monitoring for Third-Party Vendors
Monitor vendors on an ongoing basis, not just at the start of the relationship. Continuous monitoring keeps you informed of changes in vendor risk profiles and allows you to adapt compliance strategies. Early detection of threats fosters transparency and accountability, strengthening trust in the partnership.
Measure Fourth-Party Risk
Fourth-party risk refers to the risk from your vendors’ vendors. Assessing fourth-party relationships is critical, as they introduce additional risks. Require transparency from your vendors about their own supply chains to manage this risk effectively.
What Do You Do if You Have a Third-Party Data Breach?
If you become aware of a data breach, your response depends on whether information was stolen or unintentionally published. Key actions include:
Secure Your Operations
- Patch vulnerabilities in your systems.
- Secure locations connected to the incident and change access codes if necessary.
- Mobilize the breach response team to stop further data loss.
Take Down Information
- Remove any personal information from your website affected by the breach.
- Contact search engines to prevent archiving of exposed information.
- Search for disclosed data online and request removal from other websites.
- Interview individuals who found the breach and inform customer care employees about the incident.
Alert Necessary Parties
- Notify law enforcement, impacted organizations, and affected individuals.
- Determine legal requirements for breach notification in your jurisdiction.
- Have an incident response plan outlining roles and activities for a data leak or security breach.
Overcoming Resistance from Your Third-Party Vendor
If a vendor is reluctant to follow best practices but is essential to your operations, vendor risk management comes down to your organization’s risk tolerance and existing cybersecurity measures. Educate vendors about the importance of security standards and share training materials to encourage compliance.
Always prioritize security when engaging with third-party vendors to reduce the risk of data breaches.
Improve Your Cybersecurity with ZenGRC
Cybercriminals will continue to attack businesses and consumers. Keeping track of new cyberattacks and risks is essential. ZenGRC is a platform that monitors compliance issues and regulations, helping you manage third-party providers and the risks they bring.
A third-party risk management program like ZenGRC can streamline onboarding and vendor risk assessment, using risk analysis to evaluate supplier controls and conduct due diligence. Managing third-party risk is essential for all businesses. Take action before it’s too late and adopt a risk and compliance system that scales with your business, analyzes risks, and identifies potential hazards.