SecurityScorecard Research Shows 98% of Organizations Globally Have Relationships With At Least One Breached Third-Party
SecurityScorecard, the global leader in cybersecurity ratings, and The Cyentia Institute, an independent cybersecurity research firm, today published research that found 98 percent of organizations have vendor relationships with at least one third-party that has experienced a breach in the last two years. The study, Close Encounters of the Third (and Fourth) Party Kind,also found that 50 percent of organizations have indirect relationships with at least 200 breached fourth-party vendors in the last two years.
“An organizations’ attack surface spans beyond just the technology that they own or control, ” said Aleksandr Yampolskiy, co-founder and CEO of SecurityScorecard. “Organizations need visibility into the security ratings of their entire third and fourth party ecosystem so that they can know in an instant whether an organization deserves their trust and can take proactive steps to mitigate risk.”
The study, which analyzed data from over 235,000 (primary) organizations across the globe and more than 73,000 vendors and products used by them directly (third-parties) or used by their vendors (fourth-parties), offers an in-depth examination of how the interdependence of modern digital supply chains impacts organizational cyber risk exposure.
Key Report Findings:
- Security Suffers The More Third- and Fourth-Parties You Have
For every third-party vendor in their supply chain, organizations typically have indirect relationships with 60 to 90 times that number of fourth-party relationships. Research showed that compared to the primary organization, third-party vendors are five times more likely to exhibit poor security. Approximately 10% of third-party vendors receive an F rating among organizations that earn an A rating for their own security posture.
- Information Services Leads in Third-parties
The research revealed the Information Services sector maintained an average of 25 vendors-- 2.5 times the number of third party-relationships than the overall average of 10. The Finance sector was on the other end of the spectrum averaging 6.5 third-party relationships. The healthcare sector averaged 15.5 vendors per organization and the Insurance sector averaged 11 vendors. “Each of these third-party relations represents exposure to risk,” continued Baker. “In some cases due to compromised third-party code, or in others due to usage of an insecure hosting provider.”
- Exposing Data to International Third-parties Increases Regulatory and Security Requirements
While examining the regional dimension of third-party relationships, SecurityScorecard found that 59% of organizations have vendors from five or fewer countries, while roughly 14% work with vendors spanning 10 or more countries.
“SecurityScorecard’s data demonstrates why managing cyber risk across the digital supply chain is absolutely critical as threat actors work to exploit any vulnerabilities an organization may have. Identifying and continuously monitoring all partners and customers within the digital supply chain is key to staying ahead of any potential risk,” said Wade Baker, partner and co-founder at The Cyentia Institute. “By having full visibility into the security posture of their third and fourth parties, organizations can work with their vendors to address any cybersecurity gaps they may have in their infrastructure and, in turn, reduce their own level of cyber risk.”
Additional resources:
- Access the full report, “Close Encounters of the Third (and Fourth) Party Kind”
- Read our blog to better understand what can organizations do to minimize risk stemming from their business ecosystems
- Register for the informational webinar, presented by SecurityScorecard and the Cyentia Institute.
- Learn more about how Automatic Vendor Detection enables organizations to identify the products and vendors in their third- and fourth-party ecosystem to identify potential risk, automate their workflows, and drive targeted data-driven decisions.
About SecurityScorecard
Funded by world-class investors including Evolution Equity Partners, Silver Lake Waterman, Sequoia Capital, GV, Riverwood Capital, and others, SecurityScorecard is the global leader in cybersecurity ratings with more than 12 million companies continuously rated. Founded in 2013 by security and risk experts Dr. Aleksandr Yampolskiy and Sam Kassoumeh, SecurityScorecard's patented rating technology is used by over 30,000 organizations for enterprise risk management, third-party risk management, board reporting, due diligence, cyber insurance underwriting, and regulatory oversight. SecurityScorecard is the first cybersecurity ratings company to offer digital forensics and incident response services, providing a 360-degree approach to security prevention and response for its worldwide customer and partner base. SecurityScorecard continues to make the world a safer place by transforming the way companies understand, improve and communicate cybersecurity risk to their boards, employees and vendors. Every organization has the universal right to their trusted and transparent Instant SecurityScorecard rating. For more information, visit securityscorecard.com or connect with us on LinkedIn.
About The Cyentia Institute
The Cyentia Institute is a research and data science firm working to advance cybersecurity knowledge and practice. Cyentia pursues this goal through data-driven studies like this one and through a growing portfolio of analytic services. Learn more at www.cyentia.com.
To view this piece of content from cts.businesswire.com, please give your consent at the top of this page.
View source version on businesswire.com: https://www.businesswire.com/news/home/20230201005038/en/
Contact information
Derek Delano
SecurityScorecard
ddelano@securityscorecard.io
(646) 457-4513
About Business Wire
Subscribe to releases from Business Wire
Subscribe to all the latest releases from Business Wire by registering your e-mail address below. You can unsubscribe at any time.
Latest releases from Business Wire
GENESIS Pharma announces a new partnership with Otsuka Pharmaceutical Europe Ltd. for the commercialization of donidalorsen for hereditary angioedema in Central and Eastern Europe15.12.2025 10:00:00 CET | Press Release
ANNOUNCEMENT FOR EUROPEAN MEDICAL & PHARMACEUTICAL TRADE MEDIA AND EUROPEAN FINANCIAL MEDIA ONLY GENESIS Pharma, a regional biopharma company focused on the commercialization of innovative medicines in Central and Eastern Europe, announces an exclusive agreementwithOtsuka Pharmaceutical Europe Ltd. (OPEL), the European operation of global healthcare company Otsuka Pharmaceutical Co., Ltd., for donidalorsen. Under the terms of the agreement, GENESIS Pharma will exclusively distribute and commercializedonidalorsen in fourteen markets: Bulgaria, Croatia, Cyprus, Czech Republic, Estonia, Greece, Hungary, Latvia, Lithuania, Malta, Poland, Romania, Slovakia and Slovenia. In November 2025, the Committee for Medicinal Products for Human Use (CHMP) adopted a positive opinion, recommending the granting of a marketing authorisation for donidalorsen in the routine prevention of recurrent attacks of hereditary angioedema (HAE) in adults and adolescents aged 12 years and older. The CHMP opinion is c
BitGo yn Sicrhau Cymeradwyaeth OCC i Drosi i Fanc Ymddiriedolaeth Genedlaethol Siartredig Ffederal13.12.2025 02:13:00 CET | Pressmeddelande
Cyhoeddodd BitGo Holdings, Inc. (“BitGo”), y cwmni seilwaith asedau digidol, heddiw fod Swyddfa Rheolwr yr Arian Cyfred (“OCC”) wedi cymeradwyo ei gais i drosi BitGo Trust Company, Inc., cwmni ymddiriedolaeth siartredig De Dakota, i fanc cenedlaethol o'r enw BitGo Bank & Trust, National Association (N.A.). Gyda chymeradwyaeth OCC heddiw o'i drosi, mae is-gwmni Cwmni Ymddiriedolaeth BitGo bellach yn gweithredu fel BitGo Bank & Trust, National Association (N.A.). Bydd BitGo Bank & Trust, N.A. yn gweithredu o dan un gyfundrefn oruchwylio ffederal unffurf, gan ei alluogi i ddarparu'r eglurder, y llywodraethiant, a'r sicrwydd rheoleiddiol y mae sefydliadau'n eu disgwyl gan ymddiriedolwr a reoleiddir yn ffederal. Mae'r gymeradwyaeth hon yn atgyfnerthu safle BitGo fel sylfaen sefydliadol ar gyfer y system ariannol fodern, gan gyfuno goruchwyliaeth ar lefel banc â'r diogelwch, y cydymffurfiaeth, a'r graddadwyedd sy'n diffinio seilwaith BitGo. O dan siarter y banc cenedlaethol, ac yn amodol ar
FIA, Formula 1 Group and All 11 Race Teams Officially Sign the Ninth Concorde Agreement, Securing Strength and Stability for the Sport in Pivotal Five-Year Agreement12.12.2025 17:10:00 CET | Press Release
The Fédération Internationale de l'Automobile (FIA), the global governing body for motor sport and the federation for mobility organisations worldwide, and Formula 1 Group, the Commercial Rights Holder, have today announced the signing of the Concorde Governance Agreement, a crucial contract defining the regulatory framework and governance terms of the FIA Formula One World Championship until 2030. This follows the announcement in March that the 2026 Commercial Concorde Agreement had been signed by all the teams and Formula 1 Group. Together, these agreements constitute the ninth Concorde Agreement, representing a major step forward in the professionalisation and global development of the sport. First introduced in 1981, the Concorde Agreements are designed to promote sporting fairness, technological innovation and operational excellence, and align all key stakeholders around a shared vision for structured governance and continued growth of the sport. Each iteration of the Concorde Agr
Anabranch Capital Management, LP supports relisting of SmartCraft ASA to Nasdaq Stockholm12.12.2025 16:26:00 CET | Press Release
Reference is made to the stock exchange announcement by SmartCraft ASA ("SmartCraft" or the "Company") on 1 December 2025 regarding the contemplated relisting of SmartCraft from Euronext Oslo Børs to Nasdaq Stockholm (the "Relisting") and the announcement of a cross-border merger to effect the Relisting. Funds managed by Anabranch Capital Management, LP (“Anabranch”) intend to vote in favour of the merger plan resolved by the boards of SmartCraft and its Swedish wholly owned subsidiary, SmartCraft Group AB (publ), to effect the Relisting at the Company's extraordinary general meeting planned for January 2025 (the "EGM"). Anabranch intends to vote with all Anabranch shares held at the Record Date for the EGM in favour of the relisting effected by the merger plan. Funds managed by Anabranch currently hold approximately 15.9 million shares in SmartCraft. Disclaimer: The views expressed are those of the authors and Anabranch Capital Management, LP as of the date referenced and are subject
Mohammed Ben Sulayem Re-Elected as President of the FIA12.12.2025 15:49:00 CET | Press Release
The Fédération Internationale de l’Automobile (FIA), the global governing body for motor sport and the federation for mobility organisations worldwide, today confirms that Mohammed Ben Sulayem has been re-elected as President of the FIA, following the election of his Presidential List by the General Assembly in Tashkent, Republic of Uzbekistan. This press release features multimedia. View the full release here: https://www.businesswire.com/news/home/20251212213181/en/ President Mohammed Ben Sulayem now begins his second four-year term, having overseen a period of significant renewal and stabilisation for the organisation since his initial election in 2021. Over the past four years, the FIA has undergone a wide-ranging transformation, improving governance, operations and restoring the financial health of the federation. These changes have strengthened the FIA’s position as the world’s governing body for motorsport and the leading authority on safe, sustainable, and affordable mobility.
In our pressroom you can read all our latest releases, find our press contacts, images, documents and other relevant information about us.
Visit our pressroom
