32 Percent of Companies Don’t Evaluate Their Third Party Vendors

According to the results of a recent NAVEX Global survey of 321 professionals involved in third-party management, fully 32 percent of respondents don’t evaluate third parties at all before engaging with them, almost half of respondents have no dedicated budget for third party risk management, and 11 percent of respondents don’t even know how many […]

Written By: Jeff Goldman
Feb 19, 2016
eSecurity Planet content and product recommendations are editorially independent. We may make money when you click on links to our partners. Learn More

According to the results of a recent NAVEX Global survey of 321 professionals involved in third-party management, fully 32 percent of respondents don’t evaluate third parties at all before engaging with them, almost half of respondents have no dedicated budget for third party risk management, and 11 percent of respondents don’t even know how many third parties they manage.

That’s in spite of several recent high-profile data breaches resulting from security flaws at third-party vendors, including those at Target and Goodwill.

Survey respondents said their top three concerns about third parties include bribery and corruption (39 percent), fraud (23 percent), and conflicts of interest (19 percent).

“Though many organizations know which third party failures they should fear, they have not built sufficient programs and processes to identify and manage those risks,” NAVEX Global vice president for advisory services and report author Randy Stephens said in a statement.

“That may indicate a disconnect between performance of individual programs and accountability for the pain of a third party failure,” Stephens added. “Whoever is managing third parties and third party risk should understand the economic risk and impact of third party compliance on the company.”

When asked to identify top objectives for their third party risk management programs, 90 percent said their key aim was to “protect our organization from risk and damage,” followed by “comply with laws and regulations” (82 percent), and to “meet legal and regulatory requirements” (71 percent).

The leading internal issues that respondents believe are undermining their third party risk management programs’ effectives are difficulty monitoring third party relationships (51 percent), limited resources for the program (51 percent), and inconsistent reporting on on third party issues (43 percent).

The leading external challenges to third party risk management programs are getting third parties to certify compliance with a company’s policies (51 percent), training third parties on a company’s policies and compliance requirements (48 percent), getting third parties to enforce a company’s ethics and compliance policies in their organizations (41 percent), and getting third parties to enforce a company’s ethics and compliance structure with their own third parties (34 percent).

Separately, a recent BitSight Technologies study of 35,635 companies highlighted the risk from fourth parties, third party vendors’ own third party vendors. “The effects of a breach may be felt well beyond the initial attack,” the report states. “This is often a result of the complex business relationships that exist.”

“For example, let’s say Company 1 is a vendor for Company 2, and this vendor outsources their services to Company 3, who was the target of a breach,” the report adds. “This attack creates a knock-on effect, where vulnerabilities introduced through the compromised service provider now provides a backdoor to hackers.”

“Organizations who ignore these interconnections leave themselves vulnerable to other attacks or system disruptions at some point in the future,” the report notes.

Over 31 percent of the companies studied are linked to Adobe Systems, which suffered a data breach in 2013; almost 40 percent of media and entertainment companies use Amazon Web Services as their content delivery network; and more than 13 percent of the aerospace and defense companies studied use IIS 6, indicating that they use Windows Server 2003, which is no longer supported.

“Though understanding your entire security ecosystem may seem like a lofty undertaking, appropriate identification, prioritization, and validation, paired with continuous monitoring, can simplify the process and eliminate the potential for a devastating disruption,” BitSight co-founder and CTO Stephen Boyer said in a statement.

A recent eSecurity Planet offered five tips on reducing third-party security risks.

thumbnail Jeff Goldman

eSecurity Planet contributor Jeff Goldman has been a technology journalist for more than 20 years and an eSecurity Planet writer since 2009. He's also written extensively about wireless and broadband infrastructure and semiconductor engineering. He started his career at MTV, but soon decided that technology writing was a more promising path.

Recommended for you...

Surfshark vs NordVPN (2025): Which VPN Wins? Full Breakdown

NordVPN or Surfshark? Compare speed, security, price, streaming, unique features, and more in our detailed 2025 VPN review. Find your match.

Matt Gonzales
Aug 14, 2025
The 5 Best VPNs for Small Businesses on a Budget

Discover the 5 best VPNs for small businesses in 2025. Compare features, pricing, and find the right fit to protect your team and data.

Matt Gonzales
Jul 16, 2025
Penetration Testing Phases: Steps, Tools & Methodology

Penetration testing simulates cyberattacks to find risks. Explore the 7 key phases, tools, and methods to strengthen your security.

Ray Fernandez
Jun 10, 2025
Microsoft Defender vs Bitdefender: Compare Antivirus Software

Compare Microsoft Defender and Bitdefender antivirus software. We rate malware detection, pricing plans, privacy features, and more.

Jenna Phipps
May 27, 2025
eSecurity Planet Logo

eSecurity Planet is a leading resource for IT professionals at large enterprises who are actively researching cybersecurity vendors and latest trends. eSecurity Planet focuses on providing instruction for how to approach common security challenges, as well as informational deep-dives about advanced cybersecurity topics.

Property of TechnologyAdvice. © 2025 TechnologyAdvice. All Rights Reserved

Advertiser Disclosure: Some of the products that appear on this site are from companies from which TechnologyAdvice receives compensation. This compensation may impact how and where products appear on this site including, for example, the order in which they appear. TechnologyAdvice does not include all companies or all types of products available in the marketplace.